7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-10967
Software Genérico General
5.3
MEDIUM
EPSS
3.4%
2020 1 PoC

In Dovecot before 2.3.10.1, remote unauthenticated attackers can crash the lmtp or submission process by sending mail with an empty localpart.

CVE-2020-36421
Software Genérico General
5.3
MEDIUM
EPSS
0.5%
2020 1 PoC

An issue was discovered in Arm Mbed TLS before 2.23.0. Because of a side channel in modular exponentiation, an RSA private key used in a secure enclave could be disclosed.

CVE-2020-12526
TwinCAT OPC UA Server General
5.3
MEDIUM
EPSS
0.4%
2020 CWE-20 1 PoC

TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the OPC UA server is no longer responsive to any client. This is without effect to the real-time functionality of IPCs.

CVE-2020-7693
sockjs DevOps
5.3
MEDIUM
EPSS
16.0%
2020 2 PoCs

Incorrect handling of Upgrade header with the value websocket leads in crashing of containers hosting sockjs apps. This affects the package sockjs before 0.3.20.

CVE-2020-2564
Siebel UI Framework Web Database
5.3
MEDIUM
EPSS
1.4%
2020 1 PoC

Vulnerability in the Siebel UI Framework product of Oracle Siebel CRM (component: EAI). Supported versions that are affected are 19.10 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Siebel UI Framework. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Siebel UI Framework accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2020-12494
TwinCat Driver for Intel 8254x (Tcl8254x.sys) General
5.3
MEDIUM
EPSS
0.3%
2020 CWE-459 1 PoC

Beckhoff's TwinCAT RT network driver for Intel 8254x and 8255x is providing EtherCAT functionality. The driver implements real-time features. Except for Ethernet frames sent from real-time functionality, all other Ethernet frames sent through the driver are not padded if their payload is less than the minimum Ethernet frame size. Instead, arbitrary memory content is transmitted within in the padding bytes of the frame. Most likely this memory contains slices from previously transmitted or received frames. By this method, memory content is disclosed, however, an attacker can hardly control whic

CVE-2020-15853
supybot-fedora General
5.3
MEDIUM
EPSS
0.3%
2020 CWE-400 1 PoC

supybot-fedora implements the command 'refresh', that refreshes the cache of all users from FAS. This takes quite a while to run, and zodbot stops responding to requests during this time.

CVE-2020-2775
PeopleSoft Enterprise PT PeopleTools Web Database
5.3
MEDIUM
EPSS
1.2%
2020 1 PoC

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Portal). Supported versions that are affected are 8.56, 8.57 and 8.58. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PeopleTools. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise PeopleTools accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CVE-2020-28413
Software Genérico Web Database
5.3
MEDIUM
EPSS
1.7%
2020 3 PoCs

In MantisBT 2.24.3, SQL Injection can occur in the parameter "access" of the mc_project_get_users function through the API SOAP.

CVE-2020-14694
VM VirtualBox Database
5.3
MEDIUM
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM Virtu

CVE-2020-1730
libssh Networking
5.3
MEDIUM
EPSS
0.1%
2020 CWE-476 2 PoCs

A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability.

CVE-2020-36563
github.com/RobotsAndPencils/go-saml General
5.3
MEDIUM
EPSS
0.1%
2020 1 PoC

XML Digital Signatures generated and validated using this package use SHA-1, which may allow an attacker to craft inputs which cause hash collisions depending on their control over the input.

CVE-2020-7306
Data Loss Prevention(DLP) General
5.2
MEDIUM
EPSS
0.0%
2020 CWE-522 1 PoC

Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text

CVE-2020-11791
Software Genérico Web
5.2
MEDIUM
EPSS
0.4%
2020 1 PoC

NETGEAR JGS516PE devices before 2.6.0.43 are affected by reflected XSS.

CVE-2020-27223
Eclipse Jetty General
5.2
MEDIUM
EPSS
33.8%
2020 CWE-407 6 PoCs

In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept headers with a large number of “quality” (i.e. q) parameters, the server may enter a denial of service (DoS) state due to high CPU usage processing those quality values, resulting in minutes of CPU time exhausted processing those quality values.

CVE-2020-7307
Data Loss Prevention(DLP) General
5.2
MEDIUM
EPSS
0.0%
2020 CWE-522 1 PoC

Unprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials.

CVE-2020-36956
Openfire Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-79 1 PoC

Openfire 4.6.0 contains a stored cross-site scripting vulnerability in the nodejs plugin that allows attackers to inject malicious scripts through the 'path' parameter. Attackers can craft a payload with script tags to execute arbitrary JavaScript in the context of administrative users viewing the nodejs configuration page.

CVE-2020-1751
glibc General
5.1
MEDIUM
EPSS
0.2%
2020 CWE-787 1 PoC

An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.

CVE-2020-37079
Wing FTP Server Web
5.1
MEDIUM
EPSS
0.0%
2020 CWE-352 1 PoC

Wing FTP Server versions prior to 6.2.7 contain a cross-site request forgery (CSRF) vulnerability in the web administration interface that allows attackers to delete admin users. Attackers can craft a malicious HTML page with a hidden form to submit a request that deletes the administrative user account without proper authorization.

CVE-2020-10724
dpdk General
5.1
MEDIUM
EPSS
0.1%
2020 CWE-190 2 PoCs

A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.