CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2020-0312

    Last Modified: 21 Nov 2024

    In Battery Saver, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153879099

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0308

    Last Modified: 21 Nov 2024

    In Window Manager, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153654357

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0297

    Last Modified: 21 Nov 2024

    In devicepolicy service, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-155183624

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0296

    Last Modified: 21 Nov 2024

    In ADB server and USB server, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153356209

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0293

    Last Modified: 21 Nov 2024

    In Java network APIs, there is possible access to sensitive network state due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation in Android versions: Android-11, Android ID: A-141455849

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0290

    Last Modified: 21 Nov 2024

    In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153996866

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0289

    Last Modified: 21 Nov 2024

    In PackageManager, there is a missing permission check. This could lead to local information disclosure across users with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153996872

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0288

    Last Modified: 21 Nov 2024

    In PackageManager, there is a missing permission check. This could lead to local information disclosure across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-153995991

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0366

    Last Modified: 21 Nov 2024

    In PackageInstaller, there is a possible permissions bypass due to a tapjacking vulnerability. This could lead to local escalation of privilege using an app set as the default Assist app with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-138443815

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0345

    Last Modified: 21 Nov 2024

    In DocumentsUI, there is a possible permission bypass due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144286721

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0341

    Last Modified: 21 Nov 2024

    In DisplayManager, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-144920149

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0277

    Last Modified: 21 Nov 2024

    In NetworkPolicyManagerService, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing a malicious app to modify the device's data plan with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-148627993

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0130

    Last Modified: 21 Nov 2024

    In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123230379

    Published: 17 Sept 2020
    9.8
    Critical

    CVE-2020-0333

    Last Modified: 21 Nov 2024

    In UrlQuerySanitizer, there is a possible improper input validation. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-73822755

    Published: 17 Sept 2020
    5
    Medium

    CVE-2020-0338

    Last Modified: 21 Nov 2024

    In checkKeyIntent of AccountManagerService.java, there is a possible permission bypass. This could lead to local information disclosure with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-123700107

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0337

    Last Modified: 21 Nov 2024

    In MediaProvider, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-124329382

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0275

    Last Modified: 21 Nov 2024

    In MediaProvider, there is a possible way to access ContentResolver and MediaStore entries the app shouldn't have access to due to a permissions bypass. This could lead to local escalation of privilege, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150507736

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0267

    Last Modified: 21 Nov 2024

    In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app instead of the one the user intended, with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-139128211

    Published: 17 Sept 2020
    6.7
    Medium

    CVE-2020-0330

    Last Modified: 21 Nov 2024

    In iorap, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege and code execution with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-150331085

    Published: 17 Sept 2020
    3.7
    Low

    CVE-2020-15184

    Last Modified: 21 Nov 2024

    In Helm before versions 2.16.11 and 3.3.2 there is a bug in which the `alias` field on a `Chart.yaml` is not properly sanitized. This could lead to the injection of unwanted information into a chart. This issue has been patched in Helm 3.3.2 and 2.16.11. A possible workaround is to manually review the `dependencies` field of any untrusted chart, verifying that the `alias` field is either not used, or (if used) does not contain newlines or path characters.

    Published: 17 Sept 2020
    8.4
    High

    CVE-2020-15183

    Last Modified: 21 Nov 2024

    SoyCMS 3.0.2 and earlier is affected by Reflected Cross-Site Scripting (XSS) which leads to Remote Code Execution (RCE) from a known vulnerability. This allows remote attackers to force the administrator to edit files once the adminsitrator loads a specially crafted webpage.

    Published: 17 Sept 2020
    6.1
    Medium

    CVE-2020-13260

    Last Modified: 21 Nov 2024

    A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated attacker to upload a JavaScript file, with a stored XSS payload, that will remain stored in the system as an OVPN file in Configuration-Services-Security-OpenVPN-Config or as the static key file in Configuration-Services-Security-OpenVPN-Static Keys. This payload will execute each time a user opens an affected web page. This could be exploited in conjunction with CVE-2020-13259.

    Published: 17 Sept 2020
    8.4
    High

    CVE-2020-15182

    Last Modified: 21 Nov 2024

    The SOY Inquiry component of SOY CMS is affected by Cross-site Request Forgery (CSRF) and Remote Code Execution (RCE). The vulnerability affects versions 2.0.0.3 and earlier of SOY Inquiry. This allows remote attackers to force the administrator to edit files once the administrator loads a specially crafted webpage. An administrator must be logged in for exploitation to be possible. This issue is fixed in SOY Inquiry version 2.0.0.4 and included in SOY CMS 3.0.2.328.

    Published: 17 Sept 2020
    —
    Unknown

    CVE-2020-0435

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-14615. Reason: This candidate is a duplicate of CVE-2018-14615. Notes: All CVE users should reference CVE-2018-14615 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0434

    Last Modified: 21 Nov 2024

    In Pixel's use of the Catpipe library, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-150730508

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0433

    Last Modified: 21 Nov 2024

    In blk_mq_queue_tag_busy_iter of blk-mq-tag.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-151939299

    Published: 17 Sept 2020
    6.7
    Medium

    CVE-2020-0431

    Last Modified: 21 Nov 2024

    In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-144161459

    Published: 17 Sept 2020
    6.7
    Medium

    CVE-2020-0429

    Last Modified: 21 Nov 2024

    In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-152735806

    Published: 17 Sept 2020
    6.4
    Medium

    CVE-2020-0428

    Last Modified: 21 Nov 2024

    In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-123999783

    Published: 17 Sept 2020
    8.1
    High

    CVE-2020-24750

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.

    Published: 17 Sept 2020
    6.7
    Medium

    CVE-2020-0403

    Last Modified: 21 Nov 2024

    In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-131252923

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0387

    Last Modified: 21 Nov 2024

    In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-156046804

    Published: 17 Sept 2020
    9.8
    Critical

    CVE-2020-24753

    Last Modified: 21 Nov 2024

    A memory corruption vulnerability in Objective Open CBOR Run-time (oocborrt) in versions before 2020-08-12 could allow an attacker to execute code via crafted Concise Binary Object Representation (CBOR) input to the cbor2json decoder. An uncaught error while decoding CBOR Major Type 3 text strings leads to the use of an attacker-controllable uninitialized stack value. This can be used to modify memory, causing a crash or potentially exploitable heap corruption.

    Published: 17 Sept 2020
    9
    Critical

    CVE-2020-13169

    Last Modified: 21 Nov 2024

    Stored XSS (Cross-Site Scripting) exists in the SolarWinds Orion Platform before before 2020.2.1 on multiple forms and pages. This vulnerability may lead to the Information Disclosure and Escalation of Privileges (takeover of administrator account).

    Published: 17 Sept 2020
    6.1
    Medium

    CVE-2020-25729

    Last Modified: 21 Nov 2024

    ZoneMinder before 1.34.21 has XSS via the connkey parameter to download.php or export.php.

    Published: 17 Sept 2020
    9.8
    Critical

    CVE-2020-25489

    Last Modified: 21 Nov 2024

    A heap overflow in Sqreen PyMiniRacer (aka Python Mini Racer) before 0.3.0 allows remote attackers to potentially exploit heap corruption.

    Published: 17 Sept 2020
    7.3
    High

    CVE-2020-25490

    Last Modified: 21 Nov 2024

    Lack of cryptographic signature verification in the Sqreen PHP agent daemon before 1.16.0 makes it easier for remote attackers to inject rules for execution inside the virtual machine.

    Published: 17 Sept 2020
    7.2
    High

    CVE-2020-24046

    Last Modified: 21 Nov 2024

    A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. This restricted shell can be bypassed after changing the properties of the user admin in the operating system file /etc/passwd. This file cannot be accessed though the restricted shell, but it can be modified by abusing the Backup/Import Backup functionality of the web interface. An authenticated attacker would be able to obtain the file /var/tmp/admin.passwd after executing a Backup operation. This file can be manually modified to change the GUID of the user to 0 (root) and change the restricted shell to a normal shell /bin/sh. After the modification is done, the file can be recompressed to a .tar.bz file and imported again via the Import Backup functionality. The properties of the admin user will be overwritten and a root shell will be granted to the user upon the next successful login.

    Published: 17 Sept 2020
    7.2
    High

    CVE-2020-24045

    Last Modified: 21 Nov 2024

    A sandbox escape issue was discovered in TitanHQ SpamTitan Gateway 7.07. It limits the admin user to a restricted shell, allowing execution of a small number of tools of the operating system. The restricted shell can be bypassed by presenting a fake vmware-tools ISO image to the guest virtual machine running SpamTitan Gateway. This ISO image should contain a valid Perl script at the vmware-freebsd-tools/vmware-tools-distrib/vmware-install.pl path. The fake ISO image will be mounted and the script wmware-install.pl will be executed with super-user privileges as soon as the hidden option to install VMware Tools is selected in the main menu of the restricted shell (option number 5). The contents of the script can be whatever the attacker wants, including a backdoor or similar.

    Published: 17 Sept 2020
    7.5
    High

    CVE-2020-25727

    Last Modified: 21 Nov 2024

    The Reset Password add-on before 1.2.0 for Alfresco suffers from CMIS-SQL Injection, which allows a malicious user to inject a query within the email input field.

    Published: 17 Sept 2020
    8.8
    High

    CVE-2020-25728

    Last Modified: 21 Nov 2024

    The Reset Password add-on before 1.2.0 for Alfresco has a broken algorithm (involving an increment) that allows a malicious user to change any user's account password include the admin account.

    Published: 17 Sept 2020
    6.5
    Medium

    CVE-2020-11700

    Last Modified: 21 Nov 2024

    An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter fname, used on the page certs-x.php, would allow an attacker to retrieve the contents of arbitrary files. The user has to be authenticated before interacting with this page.

    Published: 17 Sept 2020
    8.8
    High

    CVE-2020-11699

    Last Modified: 21 Nov 2024

    An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page.

    Published: 17 Sept 2020
    9.8
    Critical

    CVE-2020-11698

    Last Modified: 21 Nov 2024

    An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.

    Published: 17 Sept 2020
    8.8
    High

    CVE-2020-11804

    Last Modified: 21 Nov 2024

    An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request.

    Published: 17 Sept 2020
    8.8
    High

    CVE-2020-11803

    Last Modified: 21 Nov 2024

    An issue was discovered in Titan SpamTitan 7.07. Improper sanitization of the parameter jaction when interacting with the page mailqueue.php could lead to PHP code evaluation server-side, because the user-provided input is passed directly to the php eval() function. The user has to be authenticated on the web platform before interacting with the page.

    Published: 17 Sept 2020
    9.8
    Critical

    CVE-2020-0342

    Last Modified: 21 Nov 2024

    There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812576

    Published: 17 Sept 2020
    9.8
    Critical

    CVE-2020-0278

    Last Modified: 21 Nov 2024

    There is a possible out of bounds write due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-160812574

    Published: 17 Sept 2020
    7.8
    High

    CVE-2020-0391

    Last Modified: 21 Nov 2024

    In applyPolicy of PackageManagerService.java, there is possible arbitrary command execution as System due to an unenforced protected-broadcast. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-158570769

    Published: 17 Sept 2020
    5.5
    Medium

    CVE-2020-0390

    Last Modified: 21 Nov 2024

    In the app zygote SE Policy, there is a possible permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11Android ID: A-157598026

    Published: 17 Sept 2020