7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-3622
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

u'Channel name string which has been read from shared memory is potentially subjected to string manipulations but not validated for NULL termination can results into memory corruption' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8017, APQ8053, APQ8096AU, APQ8098, Bitra, IPQ6018, IPQ8074, Kamorta, MDM9150, MDM9205, MDM9206, MDM9607, MDM9640, MDM9645,

CVE-2020-12427
Software Genérico Web Cloud Windows
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.

CVE-2020-9026
Software Genérico General
N/A
UNKNOWN
EPSS
2.1%
2020 1 PoC

ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.

CVE-2020-36109
Software Genérico Web Networking
N/A
UNKNOWN
EPSS
12.9%
2020 2 PoCs

ASUS RT-AX86U router firmware below version under 9.0.0.4_386 has a buffer overflow in the blocking_request.cgi function of the httpd module that can cause code execution when an attacker constructs malicious data.

CVE-2020-25006
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

Heybbs v1.2 has a SQL injection vulnerability in login.php file via the username parameter which may allow a remote attacker to execute arbitrary code.

CVE-2020-14350
PostgreSQL Database
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially crafted script, during the installation or update of such extension. This affects PostgreSQL versions before 12.4, before 11.9, before 10.14, before 9.6.19, and before 9.5.23.

CVE-2020-18652
Software Genérico General
N/A
UNKNOWN
EPSS
2.2%
2020 1 PoC

Buffer Overflow vulnerability in WEBP_Support.cpp in exempi 2.5.0 and earlier allows remote attackers to cause a denial of service via opening of crafted webp file.

CVE-2020-28974
Software Genérico General
N/A
UNKNOWN
EPSS
0.1%
2020 4 PoCs

A slab-out-of-bounds read in fbcon in the Linux kernel before 5.9.7 could be used by local attackers to read privileged information or potentially crash the kernel, aka CID-3c4e0dff2095. This occurs because KD_FONT_OP_COPY in drivers/tty/vt/vt.c can be used for manipulations such as font height.

CVE-2020-10661
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

HashiCorp Vault and Vault Enterprise versions 0.11.0 through 1.3.3 may, under certain circumstances, have existing nested-path policies grant access to Namespaces created after-the-fact. Fixed in 1.3.4.

CVE-2020-23064
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Sin descripción disponible.

CVE-2020-13812
Software Genérico General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory.

CVE-2020-16257
Software Genérico Web
N/A
UNKNOWN
EPSS
6.3%
2020 1 PoC

Winston 1.5.4 devices are vulnerable to command injection via the API.

CVE-2020-11152
Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

Race condition in HAL layer while processing callback objects received from HIDL due to lack of synchronization between accessing objects in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

CVE-2020-16608
Software Genérico Web
N/A
UNKNOWN
EPSS
3.9%
2020 1 PoC

Notable 1.8.4 allows XSS via crafted Markdown text, with resultant remote code execution (because nodeIntegration in webPreferences is true).

CVE-2020-24388
Software Genérico General
N/A
UNKNOWN
EPSS
0.8%
2020 1 PoC

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a denial of service.

CVE-2020-20444
Software Genérico Web
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

Jact OpenClinic 0.8.20160412 allows the attacker to read server files after login to the the admin account by an infected 'file' GET parameter in '/shared/view_source.php' which "could" lead to RCE vulnerability .

CVE-2020-11655
Software Genérico Database
N/A
UNKNOWN
EPSS
4.9%
2020 4 PoCs

SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.

CVE-2020-13947
Apache ActiveMQ Web
N/A
UNKNOWN
EPSS
4.0%
2020 2 PoCs

An instance of a cross-site scripting vulnerability was identified to be present in the web based administration console on the message.jsp page of Apache ActiveMQ versions 5.15.12 through 5.16.0.

CVE-2020-6812
Thunderbird General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosing the user's name. To resolve this issue, Firefox added a special case that renames devices containing the substring 'AirPods' to simply 'AirPods'. This vulnerability affects Thunderbird < 68.6, Firefox < 74, Firefox < ESR68.6, and Firefox ESR < 68.6.

CVE-2020-12248
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled.