Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In January 2020
A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP port 15672 and 55672
CVSS Score
7.5
EPSS Score
0.021
Published
2020-01-31
c-lightning before 0.7.1 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "It can be used for testing, but it should not be used for real funds."
CVSS Score
7.5
EPSS Score
0.003
Published
2020-01-31
Lightning Network Daemon (lnd) before 0.7 allows attackers to trigger loss of funds because of Incorrect Access Control.
CVSS Score
7.5
EPSS Score
0.006
Published
2020-01-31
Eclair through 0.3 allows attackers to trigger loss of funds because of Incorrect Access Control. NOTE: README.md states "it is beta-quality software and don't put too much money in it."
CVSS Score
7.5
EPSS Score
0.005
Published
2020-01-31
Parallel::ForkManager module before 1.0.0 for Perl does not properly handle temporary files.
CVSS Score
7.5
EPSS Score
0.004
Published
2020-01-31
_is_safe in the File::Temp module for Perl does not properly handle symlinks.
CVSS Score
7.5
EPSS Score
0.008
Published
2020-01-31
The Batch::BatchRun module 1.03 for Perl does not properly handle temporary files.
CVSS Score
7.5
EPSS Score
0.004
Published
2020-01-31
Stack-based buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0.7858 allows remote attackers to execute arbitrary code via a crafted MPEG-2 Transport Stream (M2TS) file.
CVSS Score
7.8
EPSS Score
0.038
Published
2020-01-31
Buffer overflow in Media Player Classic - Home Cinema (MPC-HC) before 1.7.0 allows remote attackers to execute arbitrary code via a crafted RealMedia .rm file
CVSS Score
7.8
EPSS Score
0.038
Published
2020-01-31
Cross-site scripting (XSS) vulnerability in infoware MapSuite MapAPI 1.0.x before 1.0.36 and 1.1.x before 1.1.49 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
CVSS Score
6.1
EPSS Score
0.004
Published
2020-01-31


Contact Us

Shodan ® - All rights reserved