
Look up vulnerabilities by software, product or CVE number.
| CVE | Published | CVSS | ShadowTrackr CVSS | Summary |
|---|---|---|---|---|
CVE: CVE-2020-37069 | Published 2026-02-03 | CVSS: 8.7 | ShadowTrackr CVSS: 6.6 | Summary: Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code. |
CVE: CVE-2020-37067 | Published 2026-02-03 | CVSS: 7.1 | ShadowTrackr CVSS: 4.9 | Summary: Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service. |
CVE: CVE-2020-37068 | Published 2026-02-03 | CVSS: 8.7 | ShadowTrackr CVSS: 6.6 | Summary: Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code. |
CVE: CVE-2020-37066 | Published 2026-02-03 | CVSS: 8.4 | ShadowTrackr CVSS: 5.7 | Summary: GoldWave 5.70 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting malicious input in the File Open URL dialog. Attackers can generate a specially crafted text file with Unicode-encoded shellcode to trigger a stack-based overflow and execute commands when the file is opened. |
CVE: CVE-2020-37065 | Published 2026-02-03 | CVSS: 8.4 | ShadowTrackr CVSS: 5.7 | Summary: StreamRipper32 version 2.6 contains a buffer overflow vulnerability in the Station/Song Section that allows attackers to overwrite memory by manipulating the SongPattern input. Attackers can craft a malicious payload exceeding 256 bytes to potentially execute arbitrary code and compromise the application. |
CVE: CVE-2020-37064 | Published 2026-02-01 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: EPSON EasyMP Network Projection 2.81 contains an unquoted service path vulnerability in the EMP_NSWLSV service that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\EPSON Projector\EasyMP Network Projection V2\ to inject malicious code that would execute with LocalSystem privileges. |
CVE: CVE-2020-37062 | Published 2026-02-01 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: DHCP Turbo 4.61298 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code by exploiting the service binary path. Attackers can place malicious executables in the service path to gain elevated privileges when the service starts. |
CVE: CVE-2020-37063 | Published 2026-02-01 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: TFTP Turbo 4.6.1273 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious executables that will be launched with LocalSystem permissions. |
CVE: CVE-2020-37061 | Published 2026-02-01 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: BOOTP Turbo 2.0.1214 contains an unquoted service path vulnerability that allows local attackers to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted executable path to inject malicious code that will be executed when the service starts with LocalSystem permissions. |
CVE: CVE-2020-37060 | Published 2026-01-30 | CVSS: 8.5 | ShadowTrackr CVSS: 5.9 | Summary: Atomic Alarm Clock 6.3 contains a local privilege escalation vulnerability in its service configuration that allows attackers to execute arbitrary code with SYSTEM privileges. Attackers can exploit the unquoted service path by placing a malicious executable named 'Program.exe' to gain persistent system-level access. |
CVE: CVE-2020-3706 | Published 2021-12-20 | CVSS: - | ShadowTrackr CVSS: 0.0 | Summary: |