3695 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2020-27993
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Hrsale 2.0.0 allows download?type=files&filename=../ directory traversal to read arbitrary files.

CVE-2020-11265
Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking

CVE-2020-5395
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

CVE-2020-8215
node-canvas General
N/A
UNKNOWN
EPSS
1.9%
2020 CWE-120 1 PoC

A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.

CVE-2020-28950
Kaspersky Anti-Ransomware Tool General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

The installer of Kaspersky Anti-Ransomware Tool (KART) prior to KART 4.0 Patch C was vulnerable to a DLL hijacking attack that allowed an attacker to elevate privileges during installation process.

CVE-2020-15578
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x) software. FactoryCamera does not properly restrict runtime permissions. The Samsung ID is SVE-2020-17270 (July 2020).

CVE-2020-6835
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

An issue was discovered in Bftpd before 5.4. There is a heap-based off-by-one error during file-transfer error checking.

CVE-2020-25687
dnsmasq General
N/A
UNKNOWN
EPSS
22.0%
2020 CWE-122 1 PoC

A flaw was found in dnsmasq before version 2.83. A heap-based buffer overflow was discovered in dnsmasq when DNSSEC is enabled and before it validates the received DNS entries. This flaw allows a remote attacker, who can create valid DNS replies, to cause an overflow in a heap-allocated memory. This flaw is caused by the lack of length checks in rfc1035.c:extract_name(), which could be abused to make the code execute memcpy() with a negative size in sort_rrset() and cause a crash in dnsmasq, resulting in a denial of service. The highest threat from this vulnerability is to system availability.

CVE-2020-35550
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), Q(10.0), and R(11.0) software. Attackers can bypass Factory Reset Protection (FRP) via StatusBar. The Samsung ID is SVE-2020-17888 (December 2020).

CVE-2020-26943
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

An issue was discovered in OpenStack blazar-dashboard before 1.3.1, 2.0.0, and 3.0.0. A user allowed to access the Blazar dashboard in Horizon may trigger code execution on the Horizon host as the user the Horizon service runs under (because the Python eval function is used). This may result in Horizon host unauthorized access and further compromise of the Horizon service. All setups using the Horizon dashboard with the blazar-dashboard plugin are affected.

CVE-2020-28861
Software Genérico General
N/A
UNKNOWN
EPSS
0.9%
2020 2 PoCs

OpenAsset Digital Asset Management (DAM) 12.0.19 and earlier failed to implement access controls on /Stream/ProjectsCSV endpoint, allowing unauthenticated attackers to gain access to potentially sensitive project information stored by the application.

CVE-2020-14944
Software Genérico General
N/A
UNKNOWN
EPSS
11.8%
2020 2 PoCs

Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can allow for manipulation and takeover of user accounts if successfully exploited. The following vulnerable functions are exposed: ChangePassword, SaveUserProfile, and GetUser.

CVE-2020-21896
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 1 PoC

A Use After Free vulnerability in svg_dev_text_span_as_paths_defs function in source/fitz/svg-device.c in Artifex Software MuPDF 1.16.0 allows remote attackers to cause a denial of service via opening of a crafted PDF file.

CVE-2020-36447
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

An issue was discovered in the v9 crate through 2020-12-18 for Rust. There is an unconditional implementation of Sync for SyncRef<T>.

CVE-2020-12749
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The S.LSI Wi-Fi drivers have a buffer overflow. The Samsung ID is SVE-2020-16906 (May 2020).

CVE-2020-27820
kernel General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-416 1 PoC

A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).

CVE-2020-25593
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.

CVE-2020-19642
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

An issue was discovered in INSMA Wifi Mini Spy 1080P HD Security IP Camera 1.9.7 B. A local attacker can execute arbitrary code via editing the 'recdata.db' file to call a specially crafted GoAhead ASP-file on the SD card.

CVE-2020-27788
upx General
N/A
UNKNOWN
EPSS
0.0%
2020 CWE-125 1 PoC

An out-of-bounds read access vulnerability was discovered in UPX in PackLinuxElf64::canPack() function of p_lx_elf.cpp file. An attacker with a crafted input file could trigger this issue that could cause a crash leading to a denial of service.

CVE-2020-6440
Chrome General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.