2938 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-7300
DLP ePO extension Web
4.6
MEDIUM
EPSS
0.1%
2020 CWE-863 1 PoC

Improper Authorization vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attackers to change the configuration when logged in with view only privileges via carefully constructed HTTP post messages.

CVE-2020-37194
Nsauditor Backup Key Recovery Recover Keys Crashed Hard Disk Drive General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by supplying an overly long registration key. Attackers can generate a 1000-character payload file and paste it into the registration key field to trigger an application crash.

CVE-2020-37188
Nsauditor SpotOutlook General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotOutlook 1.2.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can overwrite the buffer by pasting 1000 'A' characters into the 'Name' field, causing the application to become unresponsive.

CVE-2020-37208
Nsauditor SpotFTP FTP Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-787 1 PoC

SpotFTP 3.0.0.0 contains a buffer overflow vulnerability in the registration key input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash and denial of service.

CVE-2020-37038
Code::Blocks General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

Code Blocks 20.03 contains a denial of service vulnerability that allows attackers to crash the application by manipulating input in the FSymbols search field. Attackers can paste a large payload of 5000 repeated characters into the search field to trigger an application crash.

CVE-2020-29537
Software Genérico General
4.6
MEDIUM
EPSS
0.1%
2020 1 PoC

Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.

CVE-2020-37203
Nsauditor Office Product Key Finder General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the registration code input. Attackers can create a specially crafted text file and paste it into the 'Name and Key' field to trigger an application crash.

CVE-2020-7294
McAfee Web Gateway (MWG) General
4.6
MEDIUM
EPSS
0.1%
2020 CWE-287 1 PoC

Privilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected files via improper access controls in the REST interface.

CVE-2020-37204
Nsauditor RemShutdown General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

CVE-2020-37195
BlueAuditor General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

BlueAuditor 1.7.2.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37185
Nsauditor Backup Key Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash.

CVE-2020-35786
Software Genérico General
4.5
MEDIUM
EPSS
0.3%
2020 1 PoC

NETGEAR R7800 devices before 1.0.2.74 are affected by a buffer overflow by an authenticated user.

CVE-2020-1774
((OTRS)) Community Edition General
4.5
MEDIUM
EPSS
0.2%
2020 CWE-201 1 PoC

When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior versions, 6.0.27 and prior versions. OTRS: 7.0.16 and prior versions.

CVE-2020-11935
Linux kernel (aufs filesystem module) General
4.4
MEDIUM
EPSS
0.0%
2020 CWE-911 1 PoC

It was discovered that aufs improperly managed inode reference counts in the vfsub_dentry_open() method. A local attacker could use this vulnerability to cause a denial of service attack.

CVE-2020-13330
GitLab DevOps Web
4.4
MEDIUM
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.

CVE-2020-15250
junit4 General
4.4
MEDIUM
EPSS
0.1%
2020 CWE-200 1 PoC

In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability. On Unix like systems, the system's temporary directory is shared between all users on that system. Because of this, when files and directories are written into this directory they are, by default, readable by other users on that same system. This vulnerability does not allow other users to overwrite the contents of these directories or files. This is purely an information disclosure vulnerability. This vulnerability impacts you if the JUnit tests write sensitive in

CVE-2020-6107
F2fs-Tools General
4.4
MEDIUM
EPSS
0.3%
2020 CWE-253 1 PoC

An exploitable information disclosure vulnerability exists in the dev_read functionality of F2fs-Tools F2fs.Fsck 1.13. A specially crafted f2fs filesystem can cause an uninitialized read resulting in an information disclosure. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-36772
cagefs Cloud
4.4
MEDIUM
EPSS
0.0%
2020 CWE-73 2 PoCs

CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain file formats outside the CageFS environment.

CVE-2020-2930
MySQL Server Database
4.4
MEDIUM
EPSS
0.4%
2020 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2020-14873
MySQL Server Database
4.4
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).