CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2020-11297

    Last Modified: 21 Nov 2024

    Denial of service in WLAN module due to improper check of subtypes in logic where excessive frames are dropped in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 22 Feb 2021
    7.5
    High

    CVE-2020-11296

    Last Modified: 21 Nov 2024

    Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    7.5
    High

    CVE-2020-11287

    Last Modified: 21 Nov 2024

    Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    9.8
    Critical

    CVE-2020-11283

    Last Modified: 21 Nov 2024

    A buffer overflow can occur when playing an MKV clip due to lack of input validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 22 Feb 2021
    6.8
    Medium

    CVE-2020-11286

    Last Modified: 21 Nov 2024

    An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard request categories like device, interface & endpoint are made together. in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 22 Feb 2021
    7.8
    High

    CVE-2020-11282

    Last Modified: 21 Nov 2024

    Improper access control when using mmap with the kgsl driver with a special offset value that can be provided to map the memstore of the GPU to user space in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 22 Feb 2021
    7.5
    High

    CVE-2020-11280

    Last Modified: 21 Nov 2024

    Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parameter IE due to improper error handling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    7.5
    High

    CVE-2020-11281

    Last Modified: 21 Nov 2024

    Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to information disclosure. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    7.5
    High

    CVE-2020-11278

    Last Modified: 21 Nov 2024

    Possible denial of service while handling host WMI command due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    9.1
    Critical

    CVE-2020-11276

    Last Modified: 21 Nov 2024

    Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper validation of P2P IE and NOA attribute lengths in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    7.4
    High

    CVE-2020-11277

    Last Modified: 21 Nov 2024

    Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during async session in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 22 Feb 2021
    9.1
    Critical

    CVE-2020-11275

    Last Modified: 21 Nov 2024

    Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beacon in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    7.8
    High

    CVE-2020-11271

    Last Modified: 21 Nov 2024

    Possible out of bounds while accessing global control elements due to race condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    9.8
    Critical

    CVE-2020-11272

    Last Modified: 21 Nov 2024

    Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a stale version later can lead to use after free condition in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 22 Feb 2021
    7.5
    High

    CVE-2020-11270

    Last Modified: 21 Nov 2024

    Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status in the FTM parameter IE in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    8.8
    High

    CVE-2020-11269

    Last Modified: 21 Nov 2024

    Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    7.8
    High

    CVE-2020-11253

    Last Modified: 21 Nov 2024

    Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 22 Feb 2021
    7.8
    High

    CVE-2020-11223

    Last Modified: 21 Nov 2024

    Out of bound in camera driver due to lack of check of validation of array index before copying into array in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 22 Feb 2021
    7.8
    High

    CVE-2020-11204

    Last Modified: 21 Nov 2024

    Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary compliance for parameters that are read from shared MSG RAM in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    7.1
    High

    CVE-2020-11203

    Last Modified: 21 Nov 2024

    Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables

    Published: 22 Feb 2021
    7.8
    High

    CVE-2020-11195

    Last Modified: 21 Nov 2024

    Out of bound write and read in TA while processing command from NS side due to improper length check on command and response buffers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music

    Published: 22 Feb 2021
    6.7
    Medium

    CVE-2020-11198

    Last Modified: 21 Nov 2024

    Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improper usage of memset in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    7.8
    High

    CVE-2020-11194

    Last Modified: 21 Nov 2024

    Possible out of bound access in TA while processing a command from NS side due to improper length check of response buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    8.8
    High

    CVE-2020-11177

    Last Modified: 21 Nov 2024

    User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and device lock in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

    Published: 22 Feb 2021
    7.8
    High

    CVE-2020-11187

    Last Modified: 21 Nov 2024

    Possible memory corruption in BSI module due to improper validation of parameter count in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile

    Published: 22 Feb 2021
    9.8
    Critical

    CVE-2020-11170

    Last Modified: 21 Nov 2024

    Out of bound memory access while playing music playbacks with crafted vorbis content due to improper checks in header extraction in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

    Published: 22 Feb 2021
    9.8
    Critical

    CVE-2020-11163

    Last Modified: 21 Nov 2024

    Possible buffer overflow while updating ikev2 parameters due to lack of check of input validation for certain parameters received from the ePDG server in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 22 Feb 2021
    6.7
    Medium

    CVE-2020-11147

    Last Modified: 21 Nov 2024

    Use after free issue in audio modules while removing and freeing objects during list iteration due to incorrect usage of macro in Snapdragon Compute, Snapdragon Industrial IOT, Snapdragon Mobile

    Published: 22 Feb 2021
    6.1
    Medium

    CVE-2020-35571

    Last Modified: 21 Nov 2024

    An issue was discovered in MantisBT through 2.24.3. In the helper_ensure_confirmed call in manage_custom_field_update.php, the custom field name is not sanitized. This may be problematic depending on CSP settings.

    Published: 22 Feb 2021
    7.5
    High

    CVE-2020-35556

    Last Modified: 21 Nov 2024

    An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.

    Published: 22 Feb 2021
    6.1
    Medium

    CVE-2020-35664

    Last Modified: 21 Nov 2024

    An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console.

    Published: 22 Feb 2021
    9.8
    Critical

    CVE-2021-24115

    Last Modified: 21 Nov 2024

    In Botan before 2.17.3, constant-time computations are not used for certain decoding and encoding operations (base32, base58, base64, and hex).

    Published: 22 Feb 2021
    7.2
    High

    CVE-2021-3149

    Last Modified: 21 Nov 2024

    On Netshield NANO 25 10.2.18 devices, /usr/local/webmin/System/manual_ping.cgi allows OS command injection (after authentication by the attacker) because the system C library function is used unsafely.

    Published: 22 Feb 2021
    9.8
    Critical

    CVE-2021-26120

    Last Modified: 21 Nov 2024

    Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.

    Published: 22 Feb 2021
    7.5
    High

    CVE-2021-26119

    Last Modified: 21 Nov 2024

    Smarty before 3.1.39 allows a Sandbox Escape because $smarty.template_object can be accessed in sandbox mode.

    Published: 22 Feb 2021
    5.4
    Medium

    CVE-2021-21309

    Last Modified: 21 Nov 2024

    Redis is an open-source, in-memory database that persists on disk. In affected versions of Redis an integer overflow bug in 32-bit Redis version 4.0 or newer could be exploited to corrupt the heap and potentially result with remote code execution. Redis 4.0 or newer uses a configurable limit for the maximum supported bulk input size. By default, it is 512MB which is a safe value for all platforms. If the limit is significantly increased, receiving a large request from a client may trigger several integer overflow scenarios, which would result with buffer overflow and heap corruption. We believe this could in certain conditions be exploited for remote code execution. By default, authenticated Redis users have access to all configuration parameters and can therefore use the “CONFIG SET proto-max-bulk-len” to change the safe default, making the system vulnerable. **This problem only affects 32-bit Redis (on a 32-bit system, or as a 32-bit executable running on a 64-bit system).** The problem is fixed in version 6.2, and the fix is back ported to 6.0.11 and 5.0.11. Make sure you use one of these versions if you are running 32-bit Redis. An additional workaround to mitigate the problem without patching the redis-server executable is to prevent clients from directly executing `CONFIG SET`: Using Redis 6.0 or newer, ACL configuration can be used to block the command. Using older versions, the `rename-command` configuration directive can be used to rename the command to a random string unknown to users, rendering it inaccessible. Please note that this workaround may have an additional impact on users or operational systems that expect `CONFIG SET` to behave in certain ways.

    Published: 22 Feb 2021
    7.1
    High

    CVE-2021-3481

    Last Modified: 21 Nov 2024

    A flaw was found in Qt. An out-of-bounds read vulnerability was found in QRadialFetchSimd in qt/qtbase/src/gui/painting/qdrawhelper_p.h in Qt/Qtbase. While rendering and displaying a crafted Scalable Vector Graphics (SVG) file this flaw may lead to an unauthorized memory access. The highest threat from this vulnerability is to data confidentiality and the application availability.

    Published: 22 Feb 2021
    7.8
    High

    CVE-2021-37322

    Last Modified: 21 Nov 2024

    GCC c++filt v2.26 was discovered to contain a use-after-free vulnerability via the component cplus-dem.c.

    Published: 22 Feb 2021
    5.3
    Medium

    CVE-2021-42779

    Last Modified: 3 Nov 2025

    A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.

    Published: 22 Feb 2021
    7.5
    High

    CVE-2021-27516

    Last Modified: 21 Nov 2024

    URI.js (aka urijs) before 1.19.6 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

    Published: 21 Feb 2021
    8.8
    High

    CVE-2021-27513

    Last Modified: 21 Nov 2024

    The module admin_ITSM in EyesOfNetwork 5.3-10 allows remote authenticated users to upload arbitrary .xml.php files because it relies on "le filtre userside."

    Published: 21 Feb 2021
    9.8
    Critical

    CVE-2021-27514

    Last Modified: 21 Nov 2024

    EyesOfNetwork 5.3-10 uses an integer of between 8 and 10 digits for the session ID, which might be leveraged for brute-force authentication bypass (such as in CVE-2021-27513 exploitation).

    Published: 21 Feb 2021
    6.1
    Medium

    CVE-2021-26716

    Last Modified: 21 Nov 2024

    Modules/input/Views/schedule.php in Emoncms through 10.2.7 allows XSS via the node parameter.

    Published: 21 Feb 2021
    5.3
    Medium

    CVE-2021-27515

    Last Modified: 21 Nov 2024

    url-parse before 1.5.0 mishandles certain uses of backslash such as http:\/ and interprets the URI as a relative path.

    Published: 21 Feb 2021
    5.4
    Medium

    CVE-2021-26544

    Last Modified: 13 Feb 2025

    Livy server version 0.7.0-incubating (only) is vulnerable to a cross site scripting issue in the session name. A malicious user could use this flaw to access logs and results of other users' sessions and run jobs with their privileges. This issue is fixed in Livy 0.7.1-incubating.

    Published: 20 Feb 2021
    7.5
    High

    CVE-2021-22883

    Last Modified: 30 Apr 2025

    Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If a file descriptor limit is configured on the system, then the server is unable to accept new connections and prevent the process also from opening, e.g. a file. If no file descriptor limit is configured, then this lead to an excessive memory usage and cause the system to run out of memory.

    Published: 20 Feb 2021
    8.8
    High

    CVE-2020-28248

    Last Modified: 21 Nov 2024

    An integer overflow in the PngImg::InitStorage_() function of png-img before 3.1.0 leads to an under-allocation of heap memory and subsequently an exploitable heap-based buffer overflow when loading a crafted PNG file.

    Published: 19 Feb 2021
    8.8
    High

    CVE-2020-27997

    Last Modified: 21 Nov 2024

    An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to elevation of privileges (e.g., /admin/customer/create to create an admin account).

    Published: 19 Feb 2021
    8.8
    High

    CVE-2020-24617

    Last Modified: 21 Nov 2024

    Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaigns/clicked/ajax because variable column names are not properly escaped.

    Published: 19 Feb 2021
    5.9
    Medium

    CVE-2020-24393

    Last Modified: 21 Nov 2024

    TweetStream 2.6.1 uses the library eventmachine in an insecure way that does not have TLS hostname validation. This allows an attacker to perform a man-in-the-middle attack.

    Published: 19 Feb 2021