3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-11668
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 3 PoCs

In the Linux kernel before 5.6.1, drivers/media/usb/gspca/xirlink_cit.c (aka the Xirlink camera USB driver) mishandles invalid descriptors, aka CID-a246b4d54770.

CVE-2020-6564
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents of a permission dialog via a crafted HTML page.

CVE-2020-6478
Chrome General
N/A
UNKNOWN
EPSS
0.9%
2020 1 PoC

Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVE-2020-5665
MELSEC iQ-F series FX5U(C) CPU unit General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

Improper check or handling of exceptional conditions in MELSEC iQ-F series FX5U(C) CPU unit firmware version 1.060 and earlier allows an attacker to cause a denial-of-service (DoS) condition on program execution and communication by sending a specially crafted ARP packet.

CVE-2020-8544
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

OX App Suite through 7.10.3 allows SSRF.

CVE-2020-12967
SEV/SEV-ES General
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

CVE-2020-16154
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

CVE-2020-13833
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).

CVE-2020-10855
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppTray. The Samsung ID is SVE-2019-16192 (January 2020).

CVE-2020-14375
dpdk General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-367 1 PoC

A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. Virtio ring descriptors, and the data they describe are in a region of memory accessible by from both the virtual machine and the host. An attacker in a VM can change the contents of the memory after vhost_crypto has validated it. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

CVE-2020-7604
pulverizr General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

pulverizr through 0.7.0 allows execution of arbitrary commands. Within "lib/job.js", the variable "filename" can be controlled by the attacker. This function uses the variable "filename" to construct the argument of the exec call without any sanitization. In order to successfully exploit this vulnerability, an attacker will need to create a new file with the same name as the attack command.

CVE-2020-27461
Software Genérico General
N/A
UNKNOWN
EPSS
5.7%
2020 1 PoC

A remote code execution vulnerability in SEOPanel 4.6.0 has been fixed for 4.7.0. This vulnerability allowed for remote code execution through an authenticated file upload via the Settings Panel>Import website function.

CVE-2020-29651
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 2 PoCs

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

CVE-2020-25752
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

An issue was discovered on Enphase Envoy R3.x and D4.x devices. There are hardcoded web-panel login passwords for the installer and Enphase accounts. The passwords for these accounts are hardcoded values derived from the MD5 hash of the username and serial number mixed with some static strings. The serial number can be retrieved by an unauthenticated user at /info.xml. These passwords can be easily calculated by an attacker; users are unable to change these passwords.

CVE-2020-27361
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
89.2%
2020 0 PoCs

An issue exists within Akkadian Provisioning Manager 4.50.02 which allows attackers to view sensitive information within the /pme subdirectories.

CVE-2020-27524
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This may lead to memory content leaks and potentially crash the services.

CVE-2020-15797
DCA Vantage Analyzer General
N/A
UNKNOWN
EPSS
0.3%
2020 CWE-269 1 PoC

A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Improper Access Control could allow an unauthenticated attacker to escape from the restricted environment (“kiosk mode”) and access the underlying operating system. Successful exploitation requires direct physical access to the system.

CVE-2020-12713
Software Genérico General
N/A
UNKNOWN
EPSS
2.0%
2020 2 PoCs

An issue was discovered in CipherMail Community Gateway and Professional/Enterprise Gateway 1.0.1 through 4.7.1-0 and CipherMail Webmail Messenger 1.1.1 through 3.1.1-0. Attackers with administrative access to the web interface have multiple options to escalate their privileges to the Unix root account.

CVE-2020-7112
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.