2938 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37132
UltraVNC Launcher General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

UltraVNC Launcher 1.2.4.0 contains a denial of service vulnerability in its password configuration properties that allows local attackers to crash the application. Attackers can paste an overly long 300-character string into the password field to trigger an application crash and prevent normal launcher functionality.

CVE-2020-7320
Endpoint Security for Windows Windows
6.7
MEDIUM
EPSS
0.1%
2020 CWE-693 1 PoC

Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the detection capability allowing otherwise detected malware to run via stopping certain Microsoft services.

CVE-2020-15145
windows-setup Web Windows
6.7
MEDIUM
EPSS
0.0%
2020 CWE-276 2 PoCs

In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit the following scenarios. 1. A local regular user may modify the existing `C:\ProgramData\ComposerSetup\bin\composer.bat` in order to get elevated command execution when composer is run by an administrator. 2. A local regular user may create a specially crafted dll in the `C:\ProgramData\ComposerSetup\bin` folder in order to get Local System privileges. See: https://itm4n.github.io/windows-server-netman-dll-hijacking. 3. If the directory of the php.

CVE-2020-37181
Torrent FLV Converter Windows
6.7
MEDIUM
EPSS
0.1%
2020 CWE-121 1 PoC

Torrent FLV Converter 1.51 Build 117 contains a stack overflow vulnerability that allows attackers to overwrite Structured Exception Handler (SEH) through a malicious registration code input. Attackers can craft a payload with specific offsets and partial SEH overwrite techniques to potentially execute arbitrary code on vulnerable Windows 32-bit systems.

CVE-2020-15135
save-server Web
6.7
MEDIUM
EPSS
0.1%
2020 CWE-352 3 PoCs

save-server (npm package) before version 1.05 is affected by a CSRF vulnerability, as there is no CSRF mitigation (Tokens etc.). The fix introduced in version version 1.05 unintentionally breaks uploading so version v1.0.7 is the fixed version. This is patched by implementing Double submit. The CSRF attack would require you to navigate to a malicious site while you have an active session with Save-Server (Session key stored in cookies). The malicious user would then be able to perform some actions, including uploading/deleting files and adding redirects. If you are logged in as root, this atta

CVE-2020-7305
DLP ePO extension General
6.7
MEDIUM
EPSS
0.2%
2020 CWE-269 1 PoC

Privilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials.

CVE-2020-37136
ZOC Terminal Networking
6.7
MEDIUM
EPSS
0.0%
2020 CWE-121 1 PoC

ZOC Terminal 7.25.5 contains a denial of service vulnerability in the private key file input field that allows attackers to crash the application. Attackers can overwrite the private key file input with a 2000-byte buffer, causing the application to become unresponsive when attempting to create SSH key files.

CVE-2020-14386
kernel General
6.7
MEDIUM
EPSS
0.6%
2020 CWE-787 4 PoCs

A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.

CVE-2020-37131
Product Key Explorer General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Nsauditor Product Key Explorer 4.2.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by inputting a specially crafted registration key. Attackers can generate a payload of 1000 bytes of repeated characters and paste it into the 'Key' input field to trigger the application crash.

CVE-2020-11231
Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile General
6.7
MEDIUM
EPSS
0.0%
2020 1 PoC

Two threads call one or both functions concurrently leading to corruption of pointers and reference counters which in turn can lead to heap corruption in Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

CVE-2020-36949
TapinRadio Web
6.7
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

TapinRadio 2.13.7 contains a denial of service vulnerability in the application proxy settings that allows attackers to crash the program by overflowing input fields. Attackers can paste a large buffer of 20,000 characters into the username and address fields to cause the application to become unresponsive and require reinstallation.

CVE-2020-37213
TextCrawler Pro General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

TextCrawler Pro 3.1.1 contains a denial of service vulnerability that allows attackers to crash the application by sending an oversized buffer in the license key field. Attackers can generate a 6000-byte payload and paste it into the activation field to trigger an application crash.

CVE-2020-7273
McAfee Endpoint Security (ENS) Windows
6.7
MEDIUM
EPSS
0.1%
2020 CWE-269 1 PoC

Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to delete or rename programs in the autorun key via manipulation of some parameters.

CVE-2020-3403
Cisco IOS XE Software Networking
6.7
MEDIUM
EPSS
0.1%
2020 CWE-78 1 PoC

A vulnerability in the CLI of Cisco IOS XE Software could allow an authenticated, local attacker to inject a command to the underlying operating system that will execute with root privileges upon the next reboot of the device. The authenticated user must have privileged EXEC permissions on the device. The vulnerability is due to insufficient protection of values passed to a script that executes during device startup. An attacker could exploit this vulnerability by writing values to a specific file. A successful exploit could allow the attacker to execute commands with root privileges each time

CVE-2020-37164
AbsoluteTelnet General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license entry field to trigger an application crash.

CVE-2020-4230
DB2 for Linux- UNIX and Windows Windows
6.7
MEDIUM
EPSS
0.1%
2020 1 PoC

IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 11.1 and 11.5 is vulnerable to an escalation of privilege when an authenticated local attacker with special permissions executes specially crafted Db2 commands. IBM X-Force ID: 175212.

CVE-2020-37107
Core FTP LE General
6.7
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the account field with a large buffer. Attackers can create a text file with 20,000 repeated characters and paste it into the account field to cause the application to become unresponsive and require reinstallation.

CVE-2020-37121
Code::Blocks General
6.7
MEDIUM
EPSS
0.1%
2020 CWE-121 1 PoC

CODE::BLOCKS 16.01 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler with crafted Unicode characters. Attackers can create a malicious M3U playlist file with 536 bytes of buffer and shellcode to trigger remote code execution.

CVE-2020-35164
Dell BSAFE Crypto-C Micro Edition General
6.7
MEDIUM
EPSS
0.7%
2020 CWE-385 2 PoCs

Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.

CVE-2020-36198
Malware Remover General
6.7
MEDIUM
EPSS
0.9%
2020 CWE-77 1 PoC

A command injection vulnerability has been reported to affect certain versions of Malware Remover. If exploited, this vulnerability allows remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Malware Remover versions prior to 4.6.1.0. This issue does not affect: QNAP Systems Inc. Malware Remover 3.x.