CVE Feed

    Dashboard / CVE

    3
    Low

    CVE-2020-15187

    Last Modified: 29 May 2025

    In Helm before versions 2.16.11 and 3.3.2, a Helm plugin can contain duplicates of the same entry, with the last one always used. If a plugin is compromised, this lowers the level of access that an attacker needs to modify a plugin's install hooks, causing a local execution attack. To perform this attack, an attacker must have write access to the git repository or plugin archive (.tgz) while being downloaded (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 2.16.11 and Helm 3.3.2. As a possible workaround make sure to install plugins using a secure connection protocol like SSL.

    Published: 17 Sept 2020
    3.4
    Low

    CVE-2020-15186

    Last Modified: 21 Nov 2024

    In Helm before versions 2.16.11 and 3.3.2 plugin names are not sanitized properly. As a result, a malicious plugin author could use characters in a plugin name that would result in unexpected behavior, such as duplicating the name of another plugin or spoofing the output to `helm --help`. This issue has been patched in Helm 3.3.2. A possible workaround is to not install untrusted Helm plugins. Examine the `name` field in the `plugin.yaml` file for a plugin, looking for characters outside of the [a-zA-Z0-9._-] range.

    Published: 17 Sept 2020
    2.2
    Low

    CVE-2020-15185

    Last Modified: 21 Nov 2024

    In Helm before versions 2.16.11 and 3.3.2, a Helm repository can contain duplicates of the same chart, with the last one always used. If a repository is compromised, this lowers the level of access that an attacker needs to inject a bad chart into a repository. To perform this attack, an attacker must have write access to the index file (which can occur during a MITM attack on a non-SSL connection). This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the index file in the Helm repository cache before installing software.

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0375

    Last Modified: 21 Nov 2024

    In Telephony, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege and the setting of supported EUICC countries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156253476

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0374

    Last Modified: 21 Nov 2024

    In NFC, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156251602

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0266

    Last Modified: 21 Nov 2024

    In factory reset protection, there is a possible FRP bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-111086459

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0363

    Last Modified: 21 Nov 2024

    In libmedia, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-132274514

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0362

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123237930

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0353

    Last Modified: 21 Nov 2024

    In libmp4extractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124777526

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0351

    Last Modified: 21 Nov 2024

    In libstagefright, there is possible CPU exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124777537

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0332

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible dead loop due to an uncaught exception. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124783982

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0320

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-129282427

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0301

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124940460

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0287

    Last Modified: 21 Nov 2024

    In libmkvextractor, there is a possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-141860394

    Published: 17 Sept 2020
    4.7
    Medium

    CVE-2020-0373

    Last Modified: 21 Nov 2024

    In SoundTriggerHwService, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146894086

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0370

    Last Modified: 21 Nov 2024

    In libAACdec, there is a possible out of bounds read due to missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-112051700

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0364

    Last Modified: 21 Nov 2024

    In libDRCdec, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137282770

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0361

    Last Modified: 21 Nov 2024

    In libDRCdec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-151927433

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0359

    Last Modified: 21 Nov 2024

    In GLESRenderEngine, there is a possible out of bounds read due to a buffer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150303018

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0355

    Last Modified: 21 Nov 2024

    In libFraunhoferAAC, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-141883493

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0344

    Last Modified: 21 Nov 2024

    In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-140729887

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0340

    Last Modified: 21 Nov 2024

    In libcodec2_soft_mp3dec, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144901522

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0329

    Last Modified: 21 Nov 2024

    In the OMX encoder, there is a possible out of bounds read due to invalid input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-63522940

    Published: 17 Sept 2020
    4.4
    Medium

    CVE-2020-0328

    Last Modified: 21 Nov 2024

    In the camera, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150156131

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0324

    Last Modified: 21 Nov 2024

    In libsonivox, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-136660304

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0314

    Last Modified: 21 Nov 2024

    In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934920

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0279

    Last Modified: 4 Nov 2025

    In the AAC parser, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-131430997

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0274

    Last Modified: 21 Nov 2024

    In the OMX parser, there is a possible information disclosure due to a returned raw pointer. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-120781925

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-0270

    Last Modified: 21 Nov 2024

    In tremolo, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145790628

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0125

    Last Modified: 21 Nov 2024

    In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137282168

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0406

    Last Modified: 21 Nov 2024

    In libmpeg2dec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if another exploit allowed this to be triggered with different parameters, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-137794014

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0360

    Last Modified: 21 Nov 2024

    In Notification Access Confirmation, there is a possible permissions bypass due to uninformed consent. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-145129456

    Published: 17 Sept 2020
    6.4
    Medium

    CVE-2020-0358

    Last Modified: 21 Nov 2024

    In SurfaceFlinger, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150227563

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0357

    Last Modified: 21 Nov 2024

    In SurfaceFlinger, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150225569

    Published: 17 Sept 2020
    6.7
    Medium

    CVE-2020-0356

    Last Modified: 21 Nov 2024

    In the Audio HAL, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-143787559

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0346

    Last Modified: 21 Nov 2024

    In Mediaserver, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege if integer sanitization were not enabled (which it is by default), with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147002762

    Published: 17 Sept 2020
    6.7
    Medium

    CVE-2020-0336

    Last Modified: 21 Nov 2024

    In SurfaceFlinger, there is possible memory corruption due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153467444

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0306

    Last Modified: 21 Nov 2024

    In LLVM, there is a possible ineffective stack cookie placement due to stack frame double reservation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139666480

    Published: 17 Sept 2020
    8.8
    High

    CVE-2020-0321

    Last Modified: 21 Nov 2024

    In the mp3 extractor, there is a possible out of bounds write due to uninitialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155171907

    Published: 17 Sept 2020
    8.8
    High

    CVE-2020-0303

    Last Modified: 21 Nov 2024

    In the Media extractor, there is a possible use after free due to improper locking. This could lead to remote code execution in the media extractor with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148223229

    Published: 17 Sept 2020
    8.8
    High

    CVE-2020-0264

    Last Modified: 21 Nov 2024

    In libstagefright, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-116718596

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0426

    Last Modified: 21 Nov 2024

    In SyncManager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154921790

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0425

    Last Modified: 21 Nov 2024

    There is a possible way to view notifications even when the "Lockdown" feature is on. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124000380

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0323

    Last Modified: 21 Nov 2024

    In libavb, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-146516087

    Published: 17 Sept 2020
    4.4
    Medium

    CVE-2020-0322

    Last Modified: 21 Nov 2024

    In apexd, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-147002540

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0369

    Last Modified: 21 Nov 2024

    In libavb, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-130231426

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0372

    Last Modified: 21 Nov 2024

    In ActivityManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119673147

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0352

    Last Modified: 21 Nov 2024

    In MediaProvider, there is a possible permissions bypass due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-132074310

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0343

    Last Modified: 21 Nov 2024

    In NetworkStatsService, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119672472

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0317

    Last Modified: 21 Nov 2024

    In UsageStatsManager, there is a possible access to protected data due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-119671929

    Published: 17 Sept 2020