CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-0477

    Last Modified: 21 Nov 2024

    In sendLinkConfigurationChangedBroadcast of ClientModeImpl.java, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure of the current network configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162246414

    Published: 15 Dec 2020
    4.4
    Medium

    CVE-2020-0476

    Last Modified: 21 Nov 2024

    In onNotificationRemoved of Assistant.java, there is a possible leak of sensitive information to logs. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162014574

    Published: 15 Dec 2020
    7.8
    High

    CVE-2020-0475

    Last Modified: 21 Nov 2024

    In createInputConsumer of WindowManagerService.java, there is a possible way to block and intercept input events due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-162324374

    Published: 15 Dec 2020
    7
    High

    CVE-2020-0474

    Last Modified: 21 Nov 2024

    In HalCamera::requestNewFrame of HalCamera.cpp, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169282240

    Published: 15 Dec 2020
    4.6
    Medium

    CVE-2020-0473

    Last Modified: 21 Nov 2024

    In updateIncomingFileConfirmNotification of BluetoothOppNotification.java, there is a possible permissions bypass. This could lead to local escalation of privilege allowing an attacker with physical possession of the device to transfer files to it over Bluetooth, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-160691486

    Published: 15 Dec 2020
    3.3
    Low

    CVE-2020-0368

    Last Modified: 21 Nov 2024

    In queryInternal of CallLogProvider.java, there is a possible permission bypass due to improper input validation. This could lead to local information disclosure of voicemail metadata with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-143230980

    Published: 15 Dec 2020
    5.5
    Medium

    CVE-2020-0280

    Last Modified: 21 Nov 2024

    In nci_proc_ee_management_rsp of nci_hrcv.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136565424

    Published: 15 Dec 2020
    5.5
    Medium

    CVE-2020-0244

    Last Modified: 21 Nov 2024

    In writeBurstBufferBytes of SPDIFEncoder.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no clear exfiltration path, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145262423

    Published: 15 Dec 2020
    6.1
    Medium

    CVE-2020-35396

    Last Modified: 21 Nov 2024

    EGavilan Barcodes generator 1.0 is affected by: Cross Site Scripting (XSS) via the index.php. An Attacker is able to inject the XSS payload in the web application each time a user visits the website.

    Published: 15 Dec 2020
    6.1
    Medium

    CVE-2020-35395

    Last Modified: 21 Nov 2024

    XSS in the Add Expense Component of EGavilan Media Expense Management System 1.0 allows an attacker to permanently store malicious JavaScript code via the 'description' field

    Published: 15 Dec 2020
    7.3
    High

    CVE-2020-28456

    Last Modified: 21 Nov 2024

    The package s-cart/core before 4.4 are vulnerable to Cross-site Scripting (XSS) via the admin panel.

    Published: 15 Dec 2020
    7.2
    High

    CVE-2020-28457

    Last Modified: 21 Nov 2024

    This affects the package s-cart/core before 4.4. The search functionality of the admin dashboard in core/src/Admin/Controllers/AdminOrderController.phpindex is vulnerable to XSS.

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8944

    Last Modified: 21 Nov 2024

    An arbitrary memory write vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to ecall_restore using the attribute output which fails to check the range of a pointer. An attacker can use this pointer to write to arbitrary memory addresses including those within the secure enclave We recommend upgrading past commit 382da2b8b09cbf928668a2445efb778f76bd9c8a

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8943

    Last Modified: 21 Nov 2024

    An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvfrom whose return size was not validated against the requested size. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading past commit 6e158d558abd3c29a0208e30c97c9a8c5bd4230f

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8942

    Last Modified: 21 Nov 2024

    An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_read whose return size was not validated against the requrested size. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading past commit b1d120a2c7d7446d2cc58d517e20a1b184b82200

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8941

    Last Modified: 21 Nov 2024

    An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_inet_pton using an attacker controlled klinux_addr_buffer parameter. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading past commit 8fed5e334131abaf9c5e17307642fbf6ce4a57ec

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8940

    Last Modified: 21 Nov 2024

    An arbitrary memory read vulnerability in Asylo versions up to 0.6.0 allows an untrusted attacker to make a call to enc_untrusted_recvmsg using an attacker controlled result parameter. The parameter size is unchecked allowing the attacker to read memory locations outside of the intended buffer size including memory addresses within the secure enclave. We recommend upgrading or past commit fa6485c5d16a7355eab047d4a44345a73bc9131e

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8939

    Last Modified: 21 Nov 2024

    An out of bounds read on the enc_untrusted_inet_ntop function allows an attack to extend the result size that is used by memcpy() to read memory from within the enclave heap. We recommend upgrading past commit 6ff3b77ffe110a33a2f93848a6333f33616f02c4

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8938

    Last Modified: 21 Nov 2024

    An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to FromkLinuxSockAddr with attacker controlled content and size of klinux_addr which allows an attacker to write memory values from within the enclave. We recommend upgrading past commit a37fb6a0e7daf30134dbbf357c9a518a1026aa02

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8937

    Last Modified: 21 Nov 2024

    An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to enc_untrusted_create_wait_queue that uses a pointer queue that relies on UntrustedLocalMemcpy, which fails to validate where the pointer is located. This allows an attacker to write memory values from within the enclave. We recommend upgrading past commit a37fb6a0e7daf30134dbbf357c9a518a1026aa02

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8936

    Last Modified: 21 Nov 2024

    An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allows an attacker to make a host call to UntrustedCall. UntrustedCall failed to validate the buffer range within sgx_params and allowed the host to return a pointer that was an address within the enclave memory. This allowed an attacker to read memory values from within the enclave.

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-8935

    Last Modified: 21 Nov 2024

    An arbitrary memory overwrite vulnerability in Asylo versions up to 0.6.0 allow an attacker to make an Ecall_restore function call to reallocate untrusted code and overwrite sections of the Enclave memory address. We recommend updating your library.

    Published: 15 Dec 2020
    6.1
    Medium

    CVE-2020-4849

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.19 Interim Fix 7 could allow a remote attacker to bypass security restrictions, caused by a reverse tabnabbing flaw. An attacker could exploit this vulnerability and redirect a vitcim to a phishing site. IBM X-Force ID: 190294.

    Published: 15 Dec 2020
    9.8
    Critical

    CVE-2020-4747

    Last Modified: 21 Nov 2024

    IBM Connect:Direct for UNIX 6.1.0, 6.0.0, 4.3.0, and 4.2.0 can allow a local or remote user to obtain an authenticated CLI session due to improper authentication methods. IBM X-Force ID: 188516.

    Published: 15 Dec 2020
    5.5
    Medium

    CVE-2020-28203

    Last Modified: 21 Nov 2024

    An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null pointer access/dereference while opening a crafted PDF file, leading the application to crash (denial of service).

    Published: 15 Dec 2020
    6.7
    Medium

    CVE-2020-27066

    Last Modified: 21 Nov 2024

    In xfrm6_tunnel_free_spi of net/ipv6/xfrm6_tunnel.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-168043318

    Published: 15 Dec 2020
    7.5
    High

    CVE-2020-28442

    Last Modified: 21 Nov 2024

    All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.

    Published: 15 Dec 2020
    3.5
    Low

    CVE-2021-4231

    Last Modified: 20 Nov 2025

    A vulnerability was found in Angular up to 11.0.4/11.1.0-next.2. It has been classified as problematic. Affected is the handling of comments. The manipulation leads to cross site scripting. It is possible to launch the attack remotely but it might require an authentication first. Upgrading to version 11.0.5 and 11.1.0-next.3 is able to address this issue. The name of the patch is ba8da742e3b243e8f43d4c63aa842b44e14f2b09. It is recommended to upgrade the affected component.

    Published: 15 Dec 2020
    8.8
    High

    CVE-2020-26974

    Last Modified: 21 Nov 2024

    When flex-basis was used on a table wrapper, a StyleGenericFlexBasis object could have been incorrectly cast to the wrong type. This resulted in a heap user-after-free, memory corruption, and a potentially exploitable crash. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

    Published: 15 Dec 2020
    8.8
    High

    CVE-2020-35112

    Last Modified: 21 Nov 2024

    If a user downloaded a file lacking an extension on Windows, and then "Open"-ed it from the downloads panel, if there was an executable file in the downloads directory with the same name but with an executable extension (such as .bat or .exe) that executable would have been launched instead. *Note: This issue only affected Windows operating systems. Other operating systems are unaffected.*. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

    Published: 15 Dec 2020
    3.2
    Low

    CVE-2020-14394

    Last Modified: 21 Nov 2024

    An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

    Published: 15 Dec 2020
    8.8
    High

    CVE-2020-26971

    Last Modified: 21 Nov 2024

    Certain blit values provided by the user were not properly constrained leading to a heap buffer overflow on some video drivers. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

    Published: 15 Dec 2020
    6.1
    Medium

    CVE-2020-26978

    Last Modified: 21 Nov 2024

    Using techniques that built on the slipstream research, a malicious webpage could have exposed both an internal network's hosts as well as services running on the user's local machine. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

    Published: 15 Dec 2020
    9.8
    Critical

    CVE-2020-27847

    Last Modified: 21 Nov 2024

    A vulnerability exists in the SAML connector of the github.com/dexidp/dex library used to process SAML Signature Validation. This flaw allows an attacker to bypass SAML authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability. This flaw affects dex versions before 2.27.0.

    Published: 15 Dec 2020
    8.8
    High

    CVE-2020-35113

    Last Modified: 21 Nov 2024

    Mozilla developers reported memory safety bugs present in Firefox 83 and Firefox ESR 78.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

    Published: 15 Dec 2020
    8.8
    High

    CVE-2020-26973

    Last Modified: 21 Nov 2024

    Certain input to the CSS Sanitizer confused it, resulting in incorrect components being removed. This could have been used as a sanitizer bypass. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

    Published: 15 Dec 2020
    4.3
    Medium

    CVE-2020-35111

    Last Modified: 21 Nov 2024

    When an extension with the proxy permission registered to receive <all_urls>, the proxy.onRequest callback was not triggered for view-source URLs. While web content cannot navigate to such URLs, a user opening View Source could have inadvertently leaked their IP address. This vulnerability affects Firefox < 84, Thunderbird < 78.6, and Firefox ESR < 78.6.

    Published: 15 Dec 2020
    5.3
    Medium

    CVE-2020-35460

    Last Modified: 5 May 2025

    common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, leading to the writing of files to arbitrary locations.

    Published: 14 Dec 2020
    7.8
    High

    CVE-2020-35457

    Last Modified: 21 Nov 2024

    GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entries. NOTE: the vendor's position is "Realistically this is not a security issue. The standard pattern is for callers to provide a static list of option entries in a fixed number of calls to g_option_group_add_entries()." The researcher states that this pattern is undocumented

    Published: 14 Dec 2020
    5.5
    Medium

    CVE-2020-0019

    Last Modified: 21 Nov 2024

    In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-171413798

    Published: 14 Dec 2020
    7.8
    High

    CVE-2020-0016

    Last Modified: 21 Nov 2024

    In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android SoCAndroid ID: A-171413483

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-0456

    Last Modified: 21 Nov 2024

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170378843

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-0455

    Last Modified: 21 Nov 2024

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170372514

    Published: 14 Dec 2020
    9.8
    Critical

    CVE-2020-0457

    Last Modified: 21 Nov 2024

    There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-170367562

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-0463

    Last Modified: 21 Nov 2024

    In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Android-8.1 Android-9Android ID: A-169342531

    Published: 14 Dec 2020
    5.5
    Medium

    CVE-2020-0469

    Last Modified: 21 Nov 2024

    In addEscrowToken of LockSettingsService.java, there is a possible loss of the synthetic password due to logic error. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-168692734

    Published: 14 Dec 2020
    5.5
    Medium

    CVE-2020-0467

    Last Modified: 21 Nov 2024

    In onUserStopped of Vpn.java, there is a possible resetting of user preferences due to a logic issue. This could lead to local information disclosure of secure network traffic over a non-VPN link with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.1 Android-9Android ID: A-168500792

    Published: 14 Dec 2020
    5.5
    Medium

    CVE-2020-0470

    Last Modified: 21 Nov 2024

    In extend_frame_highbd of restoration.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-10Android ID: A-166268541

    Published: 14 Dec 2020
    7.5
    High

    CVE-2020-0460

    Last Modified: 21 Nov 2024

    In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-163413737

    Published: 14 Dec 2020
    6.8
    Medium

    CVE-2020-0465

    Last Modified: 21 Nov 2024

    In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-162844689References: Upstream kernel

    Published: 14 Dec 2020