578 vulnerabilidades · Windows Orden: CVSS EPSS Año ID
CVE-2020-4030
FreeRDP Windows
3.5
LOW
EPSS
0.0%
2020 CWE-125 1 PoC

In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.

CVE-2020-11096
FreeRDP Windows
3.5
LOW
EPSS
0.3%
2020 CWE-125 1 PoC

In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2.

CVE-2020-11095
FreeRDP Windows
3.5
LOW
EPSS
0.2%
2020 CWE-125 1 PoC

In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.

CVE-2020-4033
FreeRDP Windows
3.1
LOW
EPSS
0.2%
2020 CWE-125 1 PoC

In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2.

CVE-2020-4032
FreeRDP Windows
3.1
LOW
EPSS
0.4%
2020 CWE-681 1 PoC

In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.

CVE-2020-11044
FreeRDP Windows
2.2
LOW
EPSS
0.1%
2020 CWE-415 1 PoC

In FreeRDP greater than 1.2 and before 2.0.0, a double free in update_read_cache_bitmap_v3_order crashes the client application if corrupted data from a manipulated server is parsed. This has been patched in 2.0.0.

CVE-2020-11058
FreeRDP Windows
2.2
LOW
EPSS
0.1%
2020 CWE-119 1 PoC

In FreeRDP after 1.1 and before 2.0.0, a stream out-of-bounds seek in rdp_read_font_capability_set could lead to a later out-of-bounds read. As a result, a manipulated client or server might force a disconnect due to an invalid data read. This has been fixed in 2.0.0.

CVE-2020-11048
FreeRDP Windows
2.2
LOW
EPSS
0.1%
2020 CWE-125 1 PoC

In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bounds read. It only allows to abort a session. No data extraction is possible. This has been fixed in 2.0.0.

CVE-2020-11045
FreeRDP Windows
2.2
LOW
EPSS
0.2%
2020 CWE-125 1 PoC

In FreeRDP after 1.0 and before 2.0.0, there is an out-of-bound read in in update_read_bitmap_data that allows client memory to be read to an image buffer. The result displayed on screen as colour.

CVE-2020-14771
MySQL Server Database Windows
2.2
LOW
EPSS
0.2%
2020 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).

CVE-2020-27020
Kaspersky Password Manager for Windows, Kaspersky Password Manager for Android, Kaspersky Password Manager for iOS Windows
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

Password generator feature in Kaspersky Password Manager was not completely cryptographically strong and potentially allowed an attacker to predict generated passwords in some cases. An attacker would need to know some additional information (for example, time of password generation).

CVE-2020-0976
Microsoft SharePoint Enterprise Server Windows
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

A spoofing vulnerability exists when Microsoft SharePoint Server does not properly sanitize a specially crafted web request to an affected SharePoint server, aka 'Microsoft SharePoint Spoofing Vulnerability'. This CVE ID is unique from CVE-2020-0972, CVE-2020-0975, CVE-2020-0977.

CVE-2020-28039
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
6.0%
2020 1 PoC

is_protected_meta in wp-includes/meta.php in WordPress before 5.5.2 allows arbitrary file deletion because it does not properly determine whether a meta key is considered protected.

CVE-2020-9442
Software Genérico Networking Windows
N/A
UNKNOWN
EPSS
2.0%
2020 1 PoC

OpenVPN Connect 3.1.0.361 on Windows has Insecure Permissions for %PROGRAMDATA%\OpenVPN Connect\drivers\tap\amd64\win10, which allows local users to gain privileges by copying a malicious drvstore.dll there.

CVE-2020-21884
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
0.7%
2020 3 PoCs

Unibox SMB 2.4 and UniBox Enterprise Series 2.4 and UniBox Campus Series 2.4 contain a cross-site request forgery (CSRF) vulnerability in /tools/network-trace, /list_users, /list_byod?usertype=raduser, /dhcp_leases, /go?rid=202 in which a specially crafted HTTP request may reconfigure the device.

CVE-2020-15364
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
1.6%
2020 1 PoC

The Nexos theme through 1.7 for WordPress allows top-map/?search_location= reflected XSS.

CVE-2020-12832
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
72.3%
2020 0 PoCs

WordPress Plugin Simple File List before 4.2.8 is prone to a vulnerability that lets attackers delete arbitrary files because the application fails to properly verify user-supplied input.

CVE-2020-12905
AMD Radeon Software Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

Out of Bounds Read in AMD Graphics Driver for Windows 10 in Escape 0x3004403 may lead to arbitrary information disclosure.

CVE-2020-11732
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
41.0%
2020 0 PoCs

The Media Library Assistant plugin before 2.82 for Wordpress suffers from a Local File Inclusion vulnerability in mla_gallery link=download.

CVE-2020-6567
Chrome Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.