2938 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37210
Nsauditor SpotIE General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-37215
MSN Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Registration Code' field to trigger an application crash.

CVE-2020-2740
Access Manager Web Database
4.6
MEDIUM
EPSS
0.3%
2020 1 PoC

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Ora

CVE-2020-14853
MySQL Cluster Database
4.6
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of M

CVE-2020-37139
Odin Secure FTP Expert General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the application by manipulating site information fields. Attackers can generate a buffer overflow by pasting 108 bytes of repeated characters into connection fields, causing the application to crash.

CVE-2020-36617
sftpserver General
4.6
MEDIUM
EPSS
0.4%
2020 CWE-908 1 PoC

A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path of the file parse.c. The manipulation leads to uninitialized pointer. The real existence of this vulnerability is still doubted at the moment. The name of the patch is bf4032f34832ee11d79aa60a226cc018e7ec5eed. It is recommended to apply a patch to fix this issue. The identifier VDB-216205 was assigned to this vulnerability. NOTE: In some deployment models this would be a vulnerability. README specifically warns about avoiding such deployment models

CVE-2020-37205
Nsauditor RemShutdown General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

RemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' registration field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an application crash.

CVE-2020-37193
ZIP Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when selecting a ZIP file.

CVE-2020-7317
ePolicy Orchistrator (ePO) Web
4.6
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via parameter values for "syncPointList" not being correctly sanitsed.

CVE-2020-37202
Nsauditor NetworkSleuth General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

NetworkSleuth 3.0.0.0 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

CVE-2020-37199
Nsauditor NBMonitor General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-2514
Application Express Web Database
4.6
MEDIUM
EPSS
0.4%
2020 1 PoC

Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 19.2. Easily exploitable vulnerability allows low privileged attacker having End User Role privilege with network access via HTTPS to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data and unauthorized ability to cause a partial denial of

CVE-2020-2977
Application Express Web Database
4.6
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Orac

CVE-2020-37187
Nsauditor SpotDialup General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotDialup 1.6.7 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37143
ProficySCADA for iOS General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the password input field. Attackers can overwrite the password field with 257 bytes of repeated characters to trigger an application crash and prevent successful authentication.

CVE-2020-37179
Nsauditor APKF Product Key Finder General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash.

CVE-2020-37197
Nsauditor Dnss Domain Name Search Software General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Dnss Domain Name Search Software contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an application crash.

CVE-2020-37178
KeePass Password Safe General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-94 2 PoCs

KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially causing application instability or crash.

CVE-2020-37134
UltraVNC Viewer General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

UltraVNC Viewer 1.2.4.0 contains a denial of service vulnerability that allows attackers to crash the application by manipulating VNC Server input. Attackers can generate a malformed 256-byte payload and paste it into the VNC Server connection dialog to trigger an application crash.

CVE-2020-37189
TaskCanvas General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

TaskCanvas 1.4.0 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration field to trigger an application crash.