7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37039
Frigate 2 General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

Frigate 2.02 contains a denial of service vulnerability that allows attackers to crash the application by sending oversized input to the command line interface. Attackers can generate a payload of 8000 repeated characters and paste it into the application's command line field to trigger an application crash.

CVE-2020-7279
McAfee Host Intrusion Prevention System (Host IPS) for Windows Windows
4.6
MEDIUM
EPSS
0.2%
2020 CWE-426 1 PoC

DLL Search Order Hijacking Vulnerability in the installer component of McAfee Host Intrusion Prevention System (Host IPS) for Windows prior to 8.0.0 Patch 15 Update allows attackers with local access to execute arbitrary code via execution from a compromised folder.

CVE-2020-37139
Odin Secure FTP Expert General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-770 1 PoC

Odin Secure FTP Expert 7.6.3 contains a local denial of service vulnerability that allows attackers to crash the application by manipulating site information fields. Attackers can generate a buffer overflow by pasting 108 bytes of repeated characters into connection fields, causing the application to crash.

CVE-2020-37204
Nsauditor RemShutdown General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

RemShutdown 2.9.0.0 contains a denial of service vulnerability in its registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the registration key field to trigger an application crash.

CVE-2020-14853
MySQL Cluster Database
4.6
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: NDBCluster Plugin). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of M

CVE-2020-2740
Access Manager Web Database
4.6
MEDIUM
EPSS
0.3%
2020 1 PoC

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 11.1.2.3.0 and 12.2.1.3.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Access Manager accessible data as well as unauthorized read access to a subset of Ora

CVE-2020-37215
MSN Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

MSN Password Recovery version 1.30 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized input in the registration code field. Attackers can generate a 9000-byte buffer of repeated characters and paste it into the 'User Name and Registration Code' field to trigger an application crash.

CVE-2020-37210
Nsauditor SpotIE General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

SpotIE 2.9.5 contains a denial of service vulnerability in the registration key input that allows attackers to crash the application. Attackers can generate a 1000-character buffer payload and paste it into the 'Key' field to trigger an application crash.

CVE-2020-37191
Top Password Software Dialup Password Recovery General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

Top Password Software Dialup Password Recovery 1.30 contains a denial of service vulnerability that allows attackers to crash the application by overflowing input fields. Attackers can trigger the vulnerability by inserting a large 5000-character payload into the User Name and Registration Code input fields.

CVE-2020-37140
Everest General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-787 1 PoC

Everest, later referred to as AIDA64, 5.50.2100 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating file open functionality. Attackers can generate a 450-byte buffer of repeated characters and paste it into the file open dialog to trigger an application crash.

CVE-2020-37201
Nsauditor NetShareWatcher General
4.6
MEDIUM
EPSS
0.0%
2020 CWE-120 1 PoC

NetShareWatcher 1.5.8.0 contains a buffer overflow vulnerability in the registration name input that allows attackers to crash the application. Attackers can generate a 1000-character payload and paste it into the 'Name' field to trigger an application crash.

CVE-2020-1774
((OTRS)) Community Edition General
4.5
MEDIUM
EPSS
0.2%
2020 CWE-201 1 PoC

When user downloads PGP or S/MIME keys/certificates, exported file has same name for private and public keys. Therefore it's possible to mix them and to send private key to the third-party instead of public key. This issue affects ((OTRS)) Community Edition: 5.0.42 and prior versions, 6.0.27 and prior versions. OTRS: 7.0.16 and prior versions.

CVE-2020-35786
Software Genérico General
4.5
MEDIUM
EPSS
0.3%
2020 1 PoC

NETGEAR R7800 devices before 1.0.2.74 are affected by a buffer overflow by an authenticated user.

CVE-2020-13330
GitLab DevOps Web
4.4
MEDIUM
EPSS
0.1%
2020 1 PoC

An issue has been discovered in GitLab affecting versions prior to 12.10.13. GitLab was vulnerable to a stored XSS in import the Bitbucket project feature.

CVE-2020-2926
MySQL Server Database
4.4
MEDIUM
EPSS
0.2%
2020 1 PoC

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).

CVE-2020-36772
cagefs Cloud
4.4
MEDIUM
EPSS
0.0%
2020 CWE-73 2 PoCs

CloudLinux CageFS 7.0.8-2 or below insufficiently restricts file paths supplied to the sendmail proxy command. This allows local users to read and write arbitrary files of certain file formats outside the CageFS environment.

CVE-2020-14342
cifs-utils General
4.4
MEDIUM
EPSS
0.1%
2020 CWE-77 1 PoC

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as via sudo rules, could use this flaw to escalate their privileges.

CVE-2020-6106
F2fs-Tools General
4.4
MEDIUM
EPSS
0.3%
2020 CWE-131 1 PoC

An exploitable information disclosure vulnerability exists in the init_node_manager functionality of F2fs-Tools F2fs.Fsck 1.12 and 1.13. A specially crafted filesystem can be used to disclose information. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2020-15095
cli General
4.4
MEDIUM
EPSS
0.1%
2020 CWE-532 1 PoC

Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "<protocol>://[<user>[:<password>]@]<hostname>[:<port>][:][/]<path>". The password value is not redacted and is printed to stdout and also to any generated log files.

CVE-2020-14715
VM VirtualBox Database
4.4
MEDIUM
EPSS
0.1%
2020 1 PoC

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 5.2.44, prior to 6.0.24 and prior to 6.1.12. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC