CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-0276

    Last Modified: 21 Nov 2024

    In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253586

    Published: 18 Sept 2020
    4.4
    Medium

    CVE-2020-0272

    Last Modified: 21 Nov 2024

    In libhwbinder, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-130166487

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0269

    Last Modified: 21 Nov 2024

    In Android Auto Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151645626

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0265

    Last Modified: 21 Nov 2024

    In Telephony, there are possible leaks of sensitive data due to missing permission checks. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150155839

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0263

    Last Modified: 21 Nov 2024

    In the Accessibility service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154913130

    Published: 18 Sept 2020
    7.8
    High

    CVE-2020-0405

    Last Modified: 21 Nov 2024

    In NetworkStackNotifier, there is a possible permissions bypass due to an unsafe implicit PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-157475111

    Published: 18 Sept 2020
    6.7
    Medium

    CVE-2020-0350

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139424089

    Published: 18 Sept 2020
    6.7
    Medium

    CVE-2020-0347

    Last Modified: 21 Nov 2024

    In iptables, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136658008

    Published: 18 Sept 2020
    6.7
    Medium

    CVE-2020-0335

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-122361504

    Published: 18 Sept 2020
    6.7
    Medium

    CVE-2020-0334

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147995915

    Published: 18 Sept 2020
    6.7
    Medium

    CVE-2020-0326

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds write due to uninitialized data. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146453119

    Published: 18 Sept 2020
    7.8
    High

    CVE-2020-0319

    Last Modified: 21 Nov 2024

    In NFC, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges and a Firmware compromise needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137868765

    Published: 18 Sept 2020
    6.7
    Medium

    CVE-2020-0309

    Last Modified: 21 Nov 2024

    In the Bluetooth server, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with System privileges and a Firmware compromise needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147227320

    Published: 18 Sept 2020
    7.8
    High

    CVE-2020-0299

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible spoofing of bluetooth device metadata due to a missing permission check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145130119

    Published: 18 Sept 2020
    7.8
    High

    CVE-2020-0298

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible control over Bluetooth enabled state due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145129266

    Published: 18 Sept 2020
    7.8
    High

    CVE-2020-0273

    Last Modified: 21 Nov 2024

    In hwservicemanager, there is a possible out of bounds write due to freeing a wild pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155646800

    Published: 18 Sept 2020
    7.3
    High

    CVE-2020-0271

    Last Modified: 21 Nov 2024

    In the Settings app, there is an insecure default value. This could lead to local escalation of privilege and tapjacking with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144507081

    Published: 18 Sept 2020
    6.4
    Medium

    CVE-2020-0268

    Last Modified: 21 Nov 2024

    In NFC, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148294643

    Published: 18 Sept 2020
    7.8
    High

    CVE-2020-0262

    Last Modified: 21 Nov 2024

    In WiFi tethering, there is a possible attacker controlled intent due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156353008

    Published: 18 Sept 2020
    5.8
    Medium

    CVE-2020-7358

    Last Modified: 21 Nov 2024

    In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during an installation and any arbitrary code executable using the same file name.

    Published: 18 Sept 2020
    7.8
    High

    CVE-2020-0089

    Last Modified: 21 Nov 2024

    In the audio server, there is a missing permission check. This could lead to local escalation of privilege regarding audio settings with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137015603

    Published: 18 Sept 2020
    9.8
    Critical

    CVE-2020-0354

    Last Modified: 21 Nov 2024

    In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-143604331

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-0318

    Last Modified: 21 Nov 2024

    In the System UI, there is a possible system crash due to an uncaught exception. This could lead to local permanent denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-33646131

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-5975

    Last Modified: 21 Nov 2024

    NVIDIA GeForce NOW, versions prior to 2.0.23 on Windows and macOS, contains a vulnerability in the desktop application software that includes sensitive information as part of a URL, which may lead to information disclosure.

    Published: 18 Sept 2020
    8.6
    High

    CVE-2020-15958

    Last Modified: 21 Nov 2024

    An issue was discovered in 1CRM System through 8.6.7. An insecure direct object reference to internally stored files allows a remote attacker to access various sensitive information via an unauthenticated request with a predictable URL.

    Published: 18 Sept 2020
    6.1
    Medium

    CVE-2020-9745

    Last Modified: 21 Nov 2024

    Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Published: 18 Sept 2020
    6.1
    Medium

    CVE-2020-9744

    Last Modified: 21 Nov 2024

    Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Published: 18 Sept 2020
    6.1
    Medium

    CVE-2020-9739

    Last Modified: 21 Nov 2024

    Adobe Media Encoder version 14.3.2 (and earlier versions) has an out-of-bounds read vulnerability that could be exploited to read past the end of an allocated buffer, possibly resulting in a crash or disclosure of sensitive information from other memory locations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

    Published: 18 Sept 2020
    6.5
    Medium

    CVE-2020-15773

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise before 2020.2.4. Because of unrestricted cross-origin requests to read-only data in the Export API, an attacker can access data as a user (for the duration of the browser session) after previously explicitly authenticating with the API.

    Published: 18 Sept 2020
    5.3
    Medium

    CVE-2020-15767

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise before 2020.2.5. The cookie used to convey the CSRF prevention token is not annotated with the “secure” attribute, which allows an attacker with the ability to MITM plain HTTP requests to obtain it, if the user mistakenly uses a HTTP instead of HTTPS address to access the server. This cookie value could then be used to perform CSRF.

    Published: 18 Sept 2020
    5.5
    Medium

    CVE-2020-15770

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise 2018.5. An attacker can potentially make repeated attempts to guess a local user's password, due to lack of lock-out after excessive failed logins.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-15771

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise 2018.2 and Gradle Enterprise Build Cache Node 4.1. Cross-site transmission of cookie containing CSRF token allows remote attacker to bypass CSRF mitigation.

    Published: 18 Sept 2020
    4.9
    Medium

    CVE-2020-15772

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. When configuring Gradle Enterprise to integrate with a SAML identity provider, an XML metadata file can be uploaded by an administrator. The server side processing of this file dereferences XML External Entities (XXE), allowing a remote attacker with administrative access to perform server side request forgery.

    Published: 18 Sept 2020
    6.8
    Medium

    CVE-2020-15774

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise 2018.5 - 2020.2.4. An attacker with physical access to the browser of a user who has recently logged in to Gradle Enterprise and since closed their browser could reopen their browser to access Gradle Enterprise as that user.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-15775

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise 2017.1 - 2020.2.4. The /usage page of Gradle Enterprise conveys high level build information such as project names and build counts over time. This page is incorrectly viewable anonymously.

    Published: 18 Sept 2020
    8.8
    High

    CVE-2020-15776

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise 2018.2 - 2020.2.4. The CSRF prevention token is stored in a request cookie that is not annotated as HttpOnly. An attacker with the ability to execute arbitrary code in a user's browser could impose an arbitrary value for this token, allowing them to perform cross-site request forgery.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-15768

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise 2017.3 - 2020.2.4 and Gradle Enterprise Build Cache Node 1.0 - 9.2. Unrestricted HTTP header reflection in Gradle Enterprise allows remote attackers to obtain authentication cookies, if they are able to discover a separate XSS vulnerability. This potentially allows an attacker to impersonate another user. Gradle Enterprise affected application request paths:/info/headers, /cache-info/headers, /admin-info/headers, /distribution-broker-info/headers. Gradle Enterprise Build Cache Node affected application request paths:/cache-node-info/headers.

    Published: 18 Sept 2020
    6.1
    Medium

    CVE-2020-15769

    Last Modified: 21 Nov 2024

    An issue was discovered in Gradle Enterprise 2020.2 - 2020.2.4. An XSS issue exists via the request URL.

    Published: 18 Sept 2020
    6.5
    Medium

    CVE-2020-5628

    Last Modified: 21 Nov 2024

    UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website via the vulnerable App. As a result, if the access destination is a malicious website, the user may fall victim to the social engineering attack.

    Published: 18 Sept 2020
    6.5
    Medium

    CVE-2020-5629

    Last Modified: 21 Nov 2024

    UNIQLO App for Android versions 7.3.3 and earlier allows remote attackers to lead a user to access an arbitrary website via a malicious App created by the third party. As a result, if the access destination is a malicious website, the user may fall victim to the social engineering attack.

    Published: 18 Sept 2020
    4.3
    Medium

    CVE-2020-5605

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in WHR-G54S firmware 1.43 and earlier allows an attacker to access sensitive information such as setting values via unspecified vectors.

    Published: 18 Sept 2020
    6.1
    Medium

    CVE-2020-5606

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in WHR-G54S firmware 1.43 and earlier allows remote attackers to inject arbitrary script via a specially crafted page.

    Published: 18 Sept 2020
    9.8
    Critical

    CVE-2020-25756

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability exists in the mg_get_http_header function in Cesanta Mongoose 6.18 due to a lack of bounds checking. A crafted HTTP header can exploit this bug. NOTE: a committer has stated "this will not happen in practice.

    Published: 18 Sept 2020
    8.8
    High

    CVE-2020-25751

    Last Modified: 21 Nov 2024

    The paGO Commerce plugin 2.5.9.0 for Joomla! allows SQL Injection via the administrator/index.php?option=com_pago&view=comments filter_published parameter.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-25750

    Last Modified: 21 Nov 2024

    An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no longer supported by the maintainer

    Published: 18 Sept 2020
    8.1
    High

    CVE-2020-25744

    Last Modified: 21 Nov 2024

    SaferVPN before 5.0.3.3 on Windows could allow low-privileged users to create or overwrite arbitrary files, which could cause a denial of service (DoS) condition, because a symlink from %LOCALAPPDATA%\SaferVPN\Log is followed.

    Published: 18 Sept 2020
    6.1
    Medium

    CVE-2020-25735

    Last Modified: 21 Nov 2024

    webTareas through 2.1 allows XSS in clients/editclient.php, extensions/addextension.php, administration/add_announcement.php, administration/departments.php, administration/locations.php, expenses/claim_type.php, projects/editproject.php, and general/newnotifications.php.

    Published: 18 Sept 2020
    5.3
    Medium

    CVE-2020-25734

    Last Modified: 21 Nov 2024

    webTareas through 2.1 allows files/Default/ Directory Listing.

    Published: 18 Sept 2020
    7.5
    High

    CVE-2020-25733

    Last Modified: 21 Nov 2024

    webTareas through 2.1 allows upload of the dangerous .exe and .shtml file types.

    Published: 18 Sept 2020
    8.1
    High

    CVE-2020-26117

    Last Modified: 21 Nov 2024

    In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could impersonate any server after a client had added an exception.

    Published: 18 Sept 2020