7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-14378
dpdk General
N/A
UNKNOWN
EPSS
0.1%
2020 CWE-191 1 PoC

An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to get stuck in a 4,294,967,295-count iteration loop. Depending on how `vhost_crypto` is being used this could prevent other VMs or network tasks from being serviced by the busy DPDK lcore for an extended period.

CVE-2020-35895
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in the stack crate before 0.3.1 for Rust. ArrayVec has an out-of-bounds write via element insertion.

CVE-2020-3811
netqmail General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability.

CVE-2020-14447
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

An issue was discovered in Mattermost Server before 5.23.0. Large webhook requests allow attackers to cause a denial of service (infinite loop), aka MMSA-2020-0021.

CVE-2020-5750
TCExam Web
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.

CVE-2020-15860
Software Genérico General
N/A
UNKNOWN
EPSS
3.5%
2020 2 PoCs

Parallels Remote Application Server (RAS) 17.1.1 has a Business Logic Error causing remote code execution. It allows an authenticated user to execute any application in the backend operating system through the web application, despite the affected application not being published. In addition, it was discovered that it is possible to access any host in the internal domain, even if it has no published applications or the mentioned host is no longer associated with that server farm.

CVE-2020-7913
Software Genérico Web
N/A
UNKNOWN
EPSS
0.0%
2020 2 PoCs

JetBrains YouTrack 2019.2 before 2019.2.59309 was vulnerable to XSS via an issue description.

CVE-2020-29156
Software Genérico Web Windows
N/A
UNKNOWN
EPSS
13.1%
2020 1 PoC

The WooCommerce plugin before 4.7.0 for WordPress allows remote attackers to view the status of arbitrary orders via the order_id parameter in a fetch_order_status action.

CVE-2020-5966
NVIDIA GPU Display Driver Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

NVIDIA Windows GPU Display Driver, all versions, contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape, in which a NULL pointer is dereferenced, leading to denial of service or potential escalation of privileges.

CVE-2020-13786
Software Genérico Web
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

D-Link DIR-865L Ax 1.20B01 Beta devices allow CSRF.

CVE-2020-26104
Software Genérico General
N/A
UNKNOWN
EPSS
1.0%
2020 1 PoC

In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).

CVE-2020-12838
Software Genérico Web
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

ismartgate PRO 1.5.9 is vulnerable to privilege escalation by appending PHP code to /cron/mailAdmin.php.

CVE-2020-27170
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 4 PoCs

An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.

CVE-2020-11130
Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

u'Possible buffer overflow in WIFI hal process due to copying data without checking the buffer length' in Snapdragon Auto, Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile in QCM4290, QCS4290, QM215, QSM8350, SA6145P, SA6155, SA6155P, SA8155, SA8155P, SC8180X, SC8180XP, SDX55, SDX55M, SM4250, SM4250P, SM6115, SM6115P, SM6125, SM6250, SM6350, SM7125, SM7225, SM7250, SM7250P, SM8150, SM8150P, SM8250, SM8350, SM8350P, SXR2130, SXR2130P

CVE-2020-24367
Software Genérico Windows
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user.

CVE-2020-24175
Software Genérico General
N/A
UNKNOWN
EPSS
1.7%
2020 1 PoC

Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows attackers to execute arbitrary code via a crafted archive file, related to filename handling.

CVE-2020-24342
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.

CVE-2020-11265
Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Information disclosure issue due to lack of validation of pointer arguments passed to TZ BSP in Snapdragon Wired Infrastructure and Networking

CVE-2020-20950
Software Genérico Database
N/A
UNKNOWN
EPSS
0.6%
2020 2 PoCs

Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in remote information disclosure.

CVE-2020-10472
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

Reflected XSS in admin/manage-templates.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to inject arbitrary web script or HTML via the GET parameter sort.