CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2020-0160

    Last Modified: 21 Nov 2024

    In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124771364

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0161

    Last Modified: 21 Nov 2024

    In parseChunk of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127973550

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0169

    Last Modified: 21 Nov 2024

    In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123700383

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0172

    Last Modified: 21 Nov 2024

    In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127312550

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0173

    Last Modified: 21 Nov 2024

    In Parse_lins of eas_mdls.c, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127313764

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0174

    Last Modified: 21 Nov 2024

    In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-127313537

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0175

    Last Modified: 21 Nov 2024

    In XMF_ReadNode of eas_xmf.c, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-126380818

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0189

    Last Modified: 21 Nov 2024

    In ihevcd_decode() of ihevcd_decode.c, there is possible resource exhaustion due to an infinite loop. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139939283

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0195

    Last Modified: 21 Nov 2024

    In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144686961

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0197

    Last Modified: 21 Nov 2024

    In InitDataParser::parsePssh of InitDataParser.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137370379

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0200

    Last Modified: 21 Nov 2024

    In ReadLittleEndian of raw_bit_reader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147231862

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0207

    Last Modified: 21 Nov 2024

    In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-135532289

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0211

    Last Modified: 21 Nov 2024

    In SumCompoundHorizontalTaps of convolve_neon.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147491773

    Published: 11 Jun 2020
    9.8
    Critical

    CVE-2020-0217

    Last Modified: 21 Nov 2024

    In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141331405

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0135

    Last Modified: 21 Nov 2024

    In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150949837

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0192

    Last Modified: 21 Nov 2024

    In ih264d_decode_slice_thread of ih264d_thread_parse_decode.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144687080

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0127

    Last Modified: 21 Nov 2024

    In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the phone process with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140054506

    Published: 11 Jun 2020
    7.5
    High

    CVE-2020-0128

    Last Modified: 21 Nov 2024

    In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-123940919

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0191

    Last Modified: 21 Nov 2024

    In ih264d_update_default_index_list() of ih264d_dpb_mgr.c, there is a possible out of bounds read due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140561484

    Published: 11 Jun 2020
    7
    High

    CVE-2020-0218

    Last Modified: 21 Nov 2024

    In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-136005905

    Published: 11 Jun 2020
    6.4
    Medium

    CVE-2020-0126

    Last Modified: 21 Nov 2024

    In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local code execution with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137878930

    Published: 11 Jun 2020
    8.8
    High

    CVE-2020-0131

    Last Modified: 21 Nov 2024

    In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely initialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-151159638

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0132

    Last Modified: 21 Nov 2024

    In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139473816

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0134

    Last Modified: 21 Nov 2024

    In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146052771

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0141

    Last Modified: 21 Nov 2024

    In OutputBuffersArray::realloc of CCodecBuffers.cpp, there is a possible heap disclosure due to a race condition. This could lead to remote information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142544793

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0151

    Last Modified: 21 Nov 2024

    In avb_vbmeta_image_verify of avb_vbmeta_image.c there is a possible out of bounds read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-133164384

    Published: 11 Jun 2020
    4.4
    Medium

    CVE-2020-0152

    Last Modified: 21 Nov 2024

    In avb_vbmeta_image_verify of avb_vbmeta_image.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145992159

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0167

    Last Modified: 21 Nov 2024

    In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-129475100

    Published: 11 Jun 2020
    8.8
    High

    CVE-2020-0168

    Last Modified: 21 Nov 2024

    In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv of impeg2_format_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137798382

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0179

    Last Modified: 21 Nov 2024

    In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is required for exploitation.Product: AndroidVersions: Android-10Android ID: A-130656917

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0180

    Last Modified: 21 Nov 2024

    In GetOpusHeaderBuffers() of OpusHeader.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142861738

    Published: 11 Jun 2020
    8.8
    High

    CVE-2020-0190

    Last Modified: 21 Nov 2024

    In ideint_weave_blk of ideint_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140324890

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0193

    Last Modified: 21 Nov 2024

    In ihevc_intra_pred_chroma_mode_3_to_9_av8 of ihevc_intra_pred_chroma_mode_3_to_9.s, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144595488

    Published: 11 Jun 2020
    8.8
    High

    CVE-2020-0194

    Last Modified: 21 Nov 2024

    In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143826590

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0209

    Last Modified: 21 Nov 2024

    In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145206842

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0210

    Last Modified: 21 Nov 2024

    In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145206763

    Published: 11 Jun 2020
    6.5
    Medium

    CVE-2020-0213

    Last Modified: 21 Nov 2024

    In hevcd_fmt_conv_420sp_to_420sp_av8 of ihevcd_fmt_conv_420sp_to_420sp.s, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-10 Android-11 Android ID: A-143464314

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0208

    Last Modified: 21 Nov 2024

    In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145207098

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0203

    Last Modified: 21 Nov 2024

    In freeIsolatedUidLocked of ProcessList.java, there is a possible UID reuse due to improper cleanup. This could lead to local escalation of privilege between constrained processes with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146313311

    Published: 11 Jun 2020
    6.7
    Medium

    CVE-2020-0124

    Last Modified: 21 Nov 2024

    In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140237592

    Published: 11 Jun 2020
    5.5
    Medium

    CVE-2020-0187

    Last Modified: 21 Nov 2024

    In engineSetMode of BaseBlockCipher.java, there is a possible incorrect cryptographic algorithm chosen due to an incomplete comparison. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-148517383

    Published: 11 Jun 2020
    7.8
    High

    CVE-2020-0166

    Last Modified: 21 Nov 2024

    In multiple functions of URI.java, there is a possible escalation of privilege due to missing validation in the parceling of URI information. This could lead to a local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124526860

    Published: 11 Jun 2020
    7.2
    High

    CVE-2020-6090

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the Web-Based Management (WBM) functionality of WAGO PFC 200 03.03.10(15). A specially crafted series of HTTP requests can cause code execution resulting in remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.

    Published: 11 Jun 2020
    9.8
    Critical

    CVE-2020-4101

    Last Modified: 21 Nov 2024

    "HCL Digital Experience is susceptible to Server Side Request Forgery."

    Published: 11 Jun 2020
    7.5
    High

    CVE-2020-12712

    Last Modified: 21 Nov 2024

    A vulnerability based on insecure user/password encryption in the JOE (job editor) component of SOS JobScheduler 1.12 and 1.13 allows attackers to decrypt the user/password that is optionally stored with a user's profile.

    Published: 11 Jun 2020
    5.4
    Medium

    CVE-2020-4380

    Last Modified: 21 Nov 2024

    IBM Workload Scheduler 9.3.0.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 179160.

    Published: 11 Jun 2020
    8.8
    High

    CVE-2020-5593

    Last Modified: 21 Nov 2024

    Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.

    Published: 11 Jun 2020
    6.1
    Medium

    CVE-2020-5592

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Zenphoto versions prior to 1.5.7 allows remote attackers to inject an arbitrary JavaScript via unspecified vectors.

    Published: 11 Jun 2020
    8.8
    High

    CVE-2020-13851

    Last Modified: 21 Nov 2024

    Artica Pandora FMS 7.44 allows remote command execution via the events feature.

    Published: 11 Jun 2020
    7.2
    High

    CVE-2020-13852

    Last Modified: 21 Nov 2024

    Artica Pandora FMS 7.44 allows arbitrary file upload (leading to remote command execution) via the File Manager feature.

    Published: 11 Jun 2020