3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-7628
install-package General
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization.

CVE-2020-16116
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.

CVE-2020-6609
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.

CVE-2020-9027
Software Genérico General
N/A
UNKNOWN
EPSS
3.2%
2020 1 PoC

ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected.

CVE-2020-26603
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Sticker Center allows directory traversal for an unprivileged process to read arbitrary files. The Samsung ID is SVE-2020-18433 (October 2020).

CVE-2020-28384
Solid Edge SE2020 General
N/A
UNKNOWN
EPSS
1.3%
2020 CWE-121 1 PoC

A vulnerability has been identified in Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could lead to a stack based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.

CVE-2020-11205
Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

u'Possible integer overflow to heap overflow while processing command due to lack of check of packet length received' in Snapdragon Auto, Snapdragon Compute, Snapdragon Mobile in QSM8350, SA6145P, SA6150P, SA6155, SA6155P, SA8150P, SA8155P, SA8195P, SDX55M, SM8250, SM8350, SM8350P, SXR2130, SXR2130P

CVE-2020-25204
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The God Kings application 0.60.1 for Android exposes a broadcast receiver to other apps called com.innogames.core.frontend.notifications.receivers.LocalNotificationBroadcastReceiver. The purpose of this broadcast receiver is to show an in-game push notification to the player. However, the application does not enforce any authorization schema on the broadcast receiver, allowing any application to send fully customizable in-game push notifications.

CVE-2020-9451
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have write permissions. The logs are generated in a predictable pattern, allowing an unprivileged user to create a hardlink from a (not yet created) log file to anti_ransomware_service.exe. On reboot, this forces the anti_ransomware_service to try to write its log into its own process, crashing in a SHARING VIOLATION. This crash occurs on every reboot.

CVE-2020-35593
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

BMC PATROL Agent through 20.08.00 allows local privilege escalation via vectors involving pconfig +RESTART -host.

CVE-2020-16294
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 2 PoCs

A buffer overflow vulnerability in epsc_print_page() in devices/gdevepsc.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-22038
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in the ff_v4l2_m2m_create_context function in v4l2_m2m.c.

CVE-2020-29436
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Sonatype Nexus Repository Manager 3.x before 3.29.0 allows a user with admin privileges to configure the system to gain access to content outside of NXRM via an XXE vulnerability. Fixed in version 3.29.0.

CVE-2020-23856
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.

CVE-2020-8604
Trend Micro InterScan Web Security Virtual Appliance General
N/A
UNKNOWN
EPSS
82.9%
2020 2 PoCs

A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.

CVE-2020-10256
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in beta versions of the 1Password command-line tool prior to 0.5.5 and in beta versions of the 1Password SCIM bridge prior to 0.7.3. An insecure random number generator was used to generate various keys. An attacker with access to the user's encrypted data may be able to perform brute-force calculations of encryption keys and thus succeed at decryption.

CVE-2020-27423
Software Genérico General
N/A
UNKNOWN
EPSS
15.0%
2020 1 PoC

Anuko Time Tracker v1.19.23.5311 lacks rate limit on the password reset module which allows attacker to perform Denial of Service attack on any legitimate user's mailbox

CVE-2020-9973
macOS General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in macOS Catalina 10.15.7, Security Update 2020-005 High Sierra, Security Update 2020-005 Mojave, iOS 14.0 and iPadOS 14.0. Processing a maliciously crafted USD file may lead to unexpected application termination or arbitrary code execution.

CVE-2020-27630
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

In Silicon Labs uC/TCP-IP 3.6.0, TCP ISNs are improperly random.

CVE-2020-20277
Software Genérico General
N/A
UNKNOWN
EPSS
39.3%
2020 3 PoCs

There are multiple unauthenticated directory traversal vulnerabilities in different FTP commands in uftpd FTP server versions 2.7 to 2.10 due to improper implementation of a chroot jail in common.c's compose_abspath function that can be abused to read or write to arbitrary files on the filesystem, leak process memory, or potentially lead to remote code execution.