2938 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-2875
MySQL Connectors Database
4.7
MEDIUM
EPSS
0.7%
2020 1 PoC

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.14 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access t

CVE-2020-2886
CRM Technical Foundation Web Database
4.7
MEDIUM
EPSS
1.0%
2020 1 PoC

Vulnerability in the Oracle CRM Technical Foundation product of Oracle E-Business Suite (component: Preferences). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update

CVE-2020-7318
ePolicy Orchistrator (ePO) Web ⚡ nuclei
4.6
MEDIUM
EPSS
12.5%
2020 CWE-79 1 PoC

Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized.

CVE-2020-37190
Top Password Firefox Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting 5000 characters into the User Name or Registration Code input fields.

CVE-2020-37201
Nsauditor NetShareWatcher General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37175
P2PWIFICAM2 for iOS General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

P2PWIFICAM2 for iOS 10.4.1 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the Camera ID input field. Attackers can paste a 257-character buffer into the Camera ID field to trigger an application crash on iOS devices.

CVE-2020-37211
Nsauditor SpotIM General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotIM 2.2 contains a denial of service vulnerability that allows attackers to crash the application by inputting a large buffer in the registration name field. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37206
Nsauditor ShareAlarmPro Advanced Network Access Control General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

ShareAlarmPro contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload to trigger an application crash when pasted into the registration key field.

CVE-2020-1771
((OTRS)) Community Edition Web
4.6
MEDIUM
EPSS
0.6%
2020 CWE-79 2 PoCs

Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.

CVE-2020-37196
Nsauditor Dnss Domain Name Search Software General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by providing an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

CVE-2020-2664
Solaris Operating System Database
4.6
MEDIUM
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Solar

CVE-2020-37039
Frigate 2 General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

Frigate 2.02 contains a denial of service vulnerability that allows attackers to crash the application by sending oversized input to the command line interface. Attackers can generate a payload of 8000 repeated characters and paste it into the application's command line field to trigger an application crash.

CVE-2020-7279
McAfee Host Intrusion Prevention System (Host IPS) for Windows Windows
4.6
MEDIUM
EPSS
0.2%
2020 CWE-426 1 PoC

DLL Search Order Hijacking Vulnerability in the installer component of McAfee Host Intrusion Prevention System (Host IPS) for Windows prior to 8.0.0 Patch 15 Update allows attackers with local access to execute arbitrary code via execution from a compromised folder.

CVE-2020-37207
Nsauditor SpotDialup General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotDialup 1.6.7 contains a denial of service vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-37180
Nsauditor GTalk Password Finder General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-37200
Nsauditor NetShareWatcher General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration key input that allows attackers to crash the application by supplying oversized input. Attackers can generate a 1000-character payload and paste it into the registration key field to trigger an application crash.

CVE-2020-37212
Nsauditor SpotMSN General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37209
Nsauditor SpotFTP FTP Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37140
Everest General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-787 1 PoC

Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can generate a 450-byte buffer of repeated characters and paste it into the file open dialog to trigger an application crash.

CVE-2020-37191
Top Password Software Dialup Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting a large 5000-character payload into the User Name and Registration Code input fields.