7695 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2020-37102
Web Companion General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Adaware Web Companion 4.9.2159 contains an unquoted service path vulnerability in the WCAssistantService that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted binary path to inject malicious executables that will be run with LocalSystem privileges during service startup.

CVE-2020-37100
Sync Breeze Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Sync Breeze Enterprise 12.4.18 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path by placing malicious executables in specific file system locations to hijack the service startup process.

CVE-2020-37037
AVAST SecureLine General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Avast SecureLine 5.5.522.0 contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem account permissions during service startup.

CVE-2020-36974
Realtek Andrea RT Filters General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Realtek Andrea RT Filters 1.0.64.7 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in 'C:\Program Files\IDT\WDM\AESTSr64.exe' to inject malicious code that would execute during service startup or system reboot.

CVE-2020-36984
EPSON General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON 1.124 contains an unquoted service path vulnerability in the SENADB service that allows local attackers to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON_P2B\Printer Software\Status Monitor\ to inject malicious executables that will run with LocalSystem permissions.

CVE-2020-14879
BI Publisher (formerly XML Publisher) Web Database
8.5
HIGH
EPSS
0.3%
2020 1 PoC

Vulnerability in the BI Publisher product of Oracle Fusion Middleware (component: E-Business Suite - XDO). Supported versions that are affected are 5.5.0.0.0, 11.1.1.9.0, 12.2.1.3.0 and 12.2.1.4.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise BI Publisher. While the vulnerability is in BI Publisher, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all BI Publisher accessible data as well as unauthorized update, inse

CVE-2020-36979
Coex Service Application Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup.

CVE-2020-6109
Zoom General
8.5
HIGH
EPSS
0.7%
2020 CWE-22 1 PoC

An exploitable path traversal vulnerability exists in the Zoom client, version 4.6.10 processes messages including animated GIFs. A specially crafted chat message can cause an arbitrary file write, which could potentially be abused to achieve arbitrary code execution. An attacker needs to send a specially crafted message to a target user or a group to exploit this vulnerability.

CVE-2020-2863
Advanced Outbound Telephony Web Database
8.5
HIGH
EPSS
0.5%
2020 1 PoC

Vulnerability in the Oracle Advanced Outbound Telephony product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Advanced Outbound Telephony. While the vulnerability is in Oracle Advanced Outbound Telephony, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Advanced Outbound Telephony accessib

CVE-2020-37098
Disk Sorter Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Disk Sorter Enterprise 12.4.16 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions.

CVE-2020-36976
Global Registration Service General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with elevated LocalSystem privileges during service startup.

CVE-2020-37045
NetBackup General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Veritas NetBackup 7.0 contains an unquoted service path vulnerability in the NetBackup INET Daemon service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files\Veritas\NetBackup\bin\bpinetd.exe to inject malicious code that would execute with elevated LocalSystem privileges.

CVE-2020-37062
DHCP Turbo General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can place malicious executables in the service path to gain elevated privileges when the service starts.

CVE-2020-37061
BOOTP Turbo General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the service starts with LocalSystem permissions.

CVE-2020-36975
Status Monitor 3 General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

EPSON Status Monitor 3 version 8.0 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can leverage the unquoted path in 'C:\Program Files\Common Files\EPSON\EPW!3SSRP\E_S60RPB.EXE' to inject malicious executables and escalate privileges.

CVE-2020-37099
Disk Savvy Enterprise General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Disk Savvy Enterprise 12.3.18 contains an unquoted service path vulnerability in its service configuration that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Disk Savvy Enterprise\bin\disksvs.exe' to inject malicious executables and escalate privileges.

CVE-2020-37058
Andrea ST Filters Service Windows
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

Andrea ST Filters Service 1.0.64.7 contains an unquoted service path vulnerability in its Windows service configuration. Local attackers can exploit the unquoted path to inject malicious code that will execute with elevated LocalSystem privileges during service startup.

CVE-2020-36913
enlogic:show Digital Signage System Web
8.5
HIGH
EPSS
0.1%
2020 CWE-384 1 PoC

All-Dynamics Software enlogic:show 2.0.2 contains a session fixation vulnerability that allows attackers to set a predefined PHP session identifier during the login process. Attackers can forge HTTP GET requests to welcome.php with a manipulated session token to bypass authentication and potentially execute cross-site request forgery attacks.

CVE-2020-37017
CodeMeter General
8.5
HIGH
EPSS
0.0%
2020 CWE-428 1 PoC

CodeMeter 6.60 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in the CodeMeter Runtime Server service to inject malicious code that would execute with LocalSystem permissions.

CVE-2020-36916
TDM Digital Signage PC Player General
8.5
HIGH
EPSS
0.0%
2020 CWE-732 2 PoCs

TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access.