2938 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37109
aSc TimeTables General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

aSc TimeTables 2020.11.4 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Subject title field with a large buffer. Attackers can generate a 1000-character buffer and paste it into the Subject title to trigger an application crash and potential instability.

CVE-2020-37171
TapinRadio Web
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

TapinRadio 2.12.3 contains a denial of service vulnerability in the application proxy username configuration that allows local attackers to crash the application. Attackers can overwrite the username field with 10,000 bytes of arbitrary data to trigger an application crash and prevent normal program functionality.

CVE-2020-6070
F2fs-tools General
6.7
MEDIUM
EPSS
0.6%
2020 1 PoC

An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-36943
asc Timetables General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

aSc TimeTables 2021.6.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting subject title fields with excessive data. Attackers can generate a 10,000-character buffer and paste it into the subject title to trigger application instability and potential crash.

CVE-2020-36694
Software Genérico General
6.7
MEDIUM
EPSS
0.0%
2020 2 PoCs

An issue was discovered in netfilter in the Linux kernel before 5.10. There can be a use-after-free in the packet processing context, because the per-CPU sequence count is mishandled during concurrent iptables rules replacement. This could be exploited with the CAP_NET_ADMIN capability in an unprivileged namespace. NOTE: cc00bca was reverted in 5.12.

CVE-2020-37192
MSN Password Recovery General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-611 1 PoC

MSN Password Recovery 1.30 contains an XML external entity injection vulnerability that allows attackers to read local system files through crafted XML input. Attackers can exploit the 'Favorites' tab by injecting a malicious XML file that references external entities to retrieve sensitive system configuration information.

CVE-2020-37133
UltraVNC Launcher General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in the Repeater Host configuration field that allows attackers to crash the application. Attackers can paste an overly long string of 300 characters into the Repeater Host property to trigger an application crash.

CVE-2020-37132
UltraVNC Launcher General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.

CVE-2020-7320
Endpoint Security for Windows Windows
6.7
MEDIUM
EPSS
0.1%
2020 CWE-693 1 PoC

Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise detected malware to run via stopping certain Microsoft services.

CVE-2020-36949
TapinRadio Web
6.7
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

TapinRadio 2.13.7 contains a denial of service vulnerability in the application proxy settings that allows attackers to crash the program by overflowing input fields. Attackers can paste a large buffer of 20,000 characters into the username and address fields to cause the application to become unresponsive and require reinstallation.

CVE-2020-7273
McAfee Endpoint Security (ENS) Windows
6.7
MEDIUM
EPSS
0.1%
2020 CWE-269 1 PoC

Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to delete or rename programs in the autorun key via manipulation of some parameters.

CVE-2020-3403
Cisco IOS XE Software Networking
6.7
MEDIUM
EPSS
0.1%
2020 CWE-78 1 PoC

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating system that will execute with root privileges upon the next reboot of the device. The authenticated user must have privileged EXEC permissions on the device. The vulnerability is due to insufficient protection of values passed to a script that executes during device startup. An attacker could exploit this vulnerability by writing values to a specific file. A successful exploit could allow the attacker to execute commands with root privileges each time

CVE-2020-4230
DB2 for Linux- UNIX and Windows Windows
6.7
MEDIUM
EPSS
0.1%
2020 1 PoC

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212.

CVE-2020-37121
Code::Blocks General
6.7
MEDIUM
EPSS
0.1%
2020 CWE-121 1 PoC

CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious M3U playlist file with 536 bytes of buffer and shellcode to trigger remote code execution.

CVE-2020-35164
Dell BSAFE Crypto-C Micro Edition General
6.7
MEDIUM
EPSS
0.7%
2020 CWE-385 2 PoCs

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

CVE-2020-37155
Core FTP Lite General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 2 PoCs

Core FTP Lite 1.3 contains a buffer overflow vulnerability in the username input field that allows attackers to crash the application by supplying oversized input. Attackers can generate a 7000-byte payload of repeated 'A' characters to trigger an application crash without requiring additional interaction.

CVE-2020-37130
Nsauditor General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Nsauditor 3.2.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can create a malicious payload of 1000 bytes of repeated characters to trigger an application crash when pasted into the registration name field.

CVE-2020-37177
BOOTP Turbo General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

BOOTP Turbo 2.0 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the Structured Exception Handler (SEH). Attackers can generate a malicious payload of 2196 bytes with specific byte patterns to trigger an application crash and corrupt the SEH chain.

CVE-2020-7305
DLP ePO extension General
6.7
MEDIUM
EPSS
0.2%
2020 CWE-269 1 PoC

Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials.

CVE-2020-37136
ZOC Terminal Networking
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers to crash the application. Attackers can overwrite the private key file input with a 2000-byte buffer, causing the application to become unresponsive when attempting to create SSH key files.