7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-16295
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 2 PoCs

A null pointer dereference vulnerability in clj_media_size() in devices/gdevclj.c of Artifex Software GhostScript v9.50 allows a remote attacker to cause a denial of service via a crafted PDF file. This is fixed in v9.51.

CVE-2020-12248
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

In Foxit Reader and PhantomPDF before 10.0.1, and PhantomPDF before 9.7.3, attackers can execute arbitrary code via a heap-based buffer overflow because dirty image-resource data is mishandled.

CVE-2020-11655
Software Genérico Database
N/A
UNKNOWN
EPSS
4.9%
2020 4 PoCs

SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled.

CVE-2020-27645
Software Genérico General
N/A
UNKNOWN
EPSS
0.7%
2020 1 PoC

The Inventory module of the 1E Client 5.0.0.745 doesn't handle an unquoted path when executing %PROGRAMFILES%\1E\Client\Tachyon.Performance.Metrics.exe. This may allow remote authenticated users and local users to gain elevated privileges.

CVE-2020-3611
Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

u'XBL SEC clears only ZI region when loading Qualcomm-signed segments can lead to improper access issue' in Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in APQ8098, Kamorta, MSM8998, QCS404, QCS605, SDA660, SDA845, SDM630, SDM636, SDM660, SDM670, SDM710, SDM845, SDM850, SXR1130

CVE-2020-5760
Grandstream HT800 Series General
N/A
UNKNOWN
EPSS
5.0%
2020 CWE-78 2 PoCs

Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP message.

CVE-2020-26142
Software Genérico General
N/A
UNKNOWN
EPSS
1.5%
2020 1 PoC

An issue was discovered in the kernel in OpenBSD 6.6. The WEP, WPA, WPA2, and WPA3 implementations treat fragmented frames as full frames. An adversary can abuse this to inject arbitrary network packets, independent of the network configuration.

CVE-2020-11760
Software Genérico General
N/A
UNKNOWN
EPSS
0.6%
2020 1 PoC

An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.

CVE-2020-0097
Android General
N/A
UNKNOWN
EPSS
0.0%
2020 5 PoCs

In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This could lead to local escalation of privilege with User privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-145981139

CVE-2020-26887
Software Genérico General
N/A
UNKNOWN
EPSS
0.3%
2020 2 PoCs

FRITZ!OS before 7.21 on FRITZ!Box devices allows a bypass of a DNS Rebinding protection mechanism.

CVE-2020-29443
Software Genérico Web
N/A
UNKNOWN
EPSS
0.1%
2020 1 PoC

ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.

CVE-2020-11123
Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking General
N/A
UNKNOWN
EPSS
0.0%
2020 1 PoC

u'information disclosure in gatekeeper trustzone implementation as the throttling mechanism to prevent brute force attempts at getting user`s lock-screen password can be bypassed by performing the standard gatekeeper operations.' in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking in APQ8009, APQ8009W, APQ8017, APQ8037, APQ8053, APQ8064AU, APQ8096, APQ8096AU, APQ8096SG, APQ8098, MDM8207, MDM9150, MDM92

CVE-2020-26555
Software Genérico General
N/A
UNKNOWN
EPSS
0.2%
2020 2 PoCs

Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN.

CVE-2020-13223
Software Genérico General
N/A
UNKNOWN
EPSS
0.4%
2020 1 PoC

HashiCorp Vault and Vault Enterprise logged proxy environment variables that potentially included sensitive credentials. Fixed in 1.3.6 and 1.4.2.

CVE-2020-8133
Nextcloud Server Cloud
N/A
UNKNOWN
EPSS
0.2%
2020 CWE-657 1 PoC

A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

CVE-2020-12674
Software Genérico General
N/A
UNKNOWN
EPSS
25.8%
2020 1 PoC

In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.

CVE-2020-6584
Software Genérico General
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

Nagios Log Server 2.1.3 has Incorrect Access Control.

CVE-2020-12393
Firefox ESR Web Windows
N/A
UNKNOWN
EPSS
0.5%
2020 1 PoC

The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a terminal, it could have resulted in command injection and arbitrary command execution. *Note: this issue only affects Firefox on Windows operating systems.*. This vulnerability affects Firefox ESR < 68.8, Firefox < 76, and Thunderbird < 68.8.0.

CVE-2020-7485
TriStation TS1131 (v4.0.0 to v4.9.0, v4.10.0) General
N/A
UNKNOWN
EPSS
0.3%
2020 1 PoC

**VERSION NOT SUPPORTED WHEN ASSIGNED** A legacy support account in the TriStation software version v4.9.0 and earlier could cause improper access to the TriStation host machine. This was addressed in TriStation version v4.9.1 and v4.10.1 released on May 30, 2013.1