7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37190
Top Password Firefox Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Top Password Firefox Password Recovery 2.8 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting 5000 characters into the User Name or Registration Code input fields.

CVE-2020-37189
TaskCanvas General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

TaskCanvas 1.4.0 contains a denial of service vulnerability in the registration code input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration field to trigger an application crash.

CVE-2020-37212
Nsauditor SpotMSN General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotMSN 2.4.6 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37209
Nsauditor SpotFTP FTP Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotFTP 3.0.0.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-37185
Nsauditor Backup Key Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Backup Key Recovery 2.2.5 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash.

CVE-2020-37195
BlueAuditor General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

BlueAuditor 1.7.2.0 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-2664
Solaris Operating System Database
4.6
MEDIUM
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystem). The supported version that is affected is 11. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Solaris, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Solar

CVE-2020-37143
ProficySCADA for iOS General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the password input field. Attackers can overwrite the password field with 257 bytes of repeated characters to trigger an application crash and prevent successful authentication.

CVE-2020-37187
Nsauditor SpotDialup General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotDialup 1.6.7 contains a denial of service vulnerability in the registration name input field that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-2977
Application Express Web Database
4.6
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the Oracle Application Express component of Oracle Database Server. Supported versions that are affected are 5.1-19.2. Easily exploitable vulnerability allows low privileged attacker having Valid User Account privilege with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data as well as unauthorized read access to a subset of Orac

CVE-2020-37038
Code::Blocks General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

Code Blocks 20.03 contains a denial of service vulnerability that allows attackers to crash the application by manipulating input in the FSymbols search field. Attackers can paste a large payload of 5000 repeated characters into the search field to trigger an application crash.

CVE-2020-2514
Application Express Web Database
4.6
MEDIUM
EPSS
0.4%
2020 1 PoC

Vulnerability in the Oracle Application Express component of Oracle Database Server. The supported version that is affected is Prior to 19.2. Easily exploitable vulnerability allows low privileged attacker having End User Role privilege with network access via HTTPS to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Application Express accessible data and unauthorized ability to cause a partial denial of

CVE-2020-37199
Nsauditor NBMonitor General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

NBMonitor 1.6.6.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-37202
Nsauditor NetworkSleuth General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

NetworkSleuth 3.0.0.0 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

CVE-2020-7317
ePolicy Orchistrator (ePO) Web
4.6
MEDIUM
EPSS
0.1%
2020 CWE-79 1 PoC

Cross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via parameter values for "syncPointList" not being correctly sanitsed.

CVE-2020-37193
ZIP Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

ZIP Password Recovery 2.30 contains a denial of service vulnerability that allows attackers to crash the application by providing maliciously crafted input. Attackers can create a specially prepared text file with specific characters to trigger an application crash when selecting a ZIP file.

CVE-2020-37205
Nsauditor RemShutdown General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

RemShutdown 2.9.0.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' registration field. Attackers can generate a 1000-character buffer payload and paste it into the registration name field to trigger an application crash.

CVE-2020-37204
Nsauditor RemShutdown General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

CVE-2020-36617
sftpserver General
4.6
MEDIUM
EPSS
0.4%
2020 CWE-908 1 PoC

A vulnerability was found in ewxrjk sftpserver. It has been declared as problematic. Affected by this vulnerability is the function sftp_parse_path of the file parse.c. The manipulation leads to uninitialized pointer. The real existence of this vulnerability is still doubted at the moment. The name of the patch is bf4032f34832ee11d79aa60a226cc018e7ec5eed. It is recommended to apply a patch to fix this issue. The identifier VDB-216205 was assigned to this vulnerability. NOTE: In some deployment models this would be a vulnerability. README specifically warns about avoiding such deployment models

CVE-2020-37039
Frigate 2 General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

Frigate 2.02 contains a denial of service vulnerability that allows attackers to crash the application by sending oversized input to the command line interface. Attackers can generate a payload of 8000 repeated characters and paste it into the application's command line field to trigger an application crash.