CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2020-5737

    Last Modified: 21 Nov 2024

    Stored XSS in Tenable.Sc before 5.14.0 could allow an authenticated remote attacker to craft a request to execute arbitrary script code in a user's browser session. Updated input validation techniques have been implemented to correct this issue.

    Published: 17 Apr 2020
    4.4
    Medium

    CVE-2020-0077

    Last Modified: 21 Nov 2024

    In authorize_enroll of the FPC IRIS TrustZone app, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-146055840

    Published: 17 Apr 2020
    4.4
    Medium

    CVE-2020-0075

    Last Modified: 21 Nov 2024

    In set_shared_key of the FPC IRIS TrustZone app, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-146057864

    Published: 17 Apr 2020
    6.7
    Medium

    CVE-2020-0076

    Last Modified: 21 Nov 2024

    In get_auth_result of the FPC IRIS TrustZone app, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-146056878

    Published: 17 Apr 2020
    5.5
    Medium

    CVE-2019-2056

    Last Modified: 21 Nov 2024

    There is a possible disclosure of RAM using a shared crypto key due to improperly used crypto. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140879284

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2020-0073

    Last Modified: 21 Nov 2024

    In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-147309942

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2020-0072

    Last Modified: 21 Nov 2024

    In rw_t2t_handle_tlv_detect_rsp of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-147310271

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2020-0071

    Last Modified: 21 Nov 2024

    In rw_t2t_extract_default_locks_info of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-147310721

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2020-0070

    Last Modified: 21 Nov 2024

    In rw_t2t_update_lock_attributes of rw_t2t_ndef.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution over NFC with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-148159613

    Published: 17 Apr 2020
    7.8
    High

    CVE-2020-0079

    Last Modified: 21 Nov 2024

    In decrypt_1_2 of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-144506242

    Published: 17 Apr 2020
    7.8
    High

    CVE-2020-0078

    Last Modified: 21 Nov 2024

    In releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10Android ID: A-144766455

    Published: 17 Apr 2020
    7.8
    High

    CVE-2020-0082

    Last Modified: 21 Nov 2024

    In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead to local escalation of privilege to system_server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140417434

    Published: 17 Apr 2020
    7.8
    High

    CVE-2020-0081

    Last Modified: 21 Nov 2024

    In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144028297

    Published: 17 Apr 2020
    7.8
    High

    CVE-2020-0080

    Last Modified: 21 Nov 2024

    In onOpActiveChanged and related methods of AppOpsControllerImpl.java, there is a possible way to display an app overlaying other apps without the notification icon that it's overlaying. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144092031

    Published: 17 Apr 2020
    4.4
    Medium

    CVE-2020-0068

    Last Modified: 21 Nov 2024

    In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: Android. Versions: Android kernel. Android ID: A-139354541

    Published: 17 Apr 2020
    7.8
    High

    CVE-2020-7079

    Last Modified: 21 Nov 2024

    An improper signature validation vulnerability in Autodesk Dynamo BIM versions 2.5.1 and 2.5.0 may lead to code execution through maliciously crafted DLL files.

    Published: 17 Apr 2020
    7.8
    High

    CVE-2020-7085

    Last Modified: 21 Nov 2024

    A heap overflow vulnerability in the Autodesk FBX-SDK versions 2019.2 and earlier may lead to arbitrary code execution on a system running it.

    Published: 17 Apr 2020
    5.5
    Medium

    CVE-2020-7084

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application.

    Published: 17 Apr 2020
    6.5
    Medium

    CVE-2020-7083

    Last Modified: 21 Nov 2024

    An intager overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to denial of service of the application.

    Published: 17 Apr 2020
    8.8
    High

    CVE-2020-7082

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to code execution on a system running it.

    Published: 17 Apr 2020
    8.8
    High

    CVE-2020-7081

    Last Modified: 21 Nov 2024

    A type confusion vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitary code read/write on the system running it.

    Published: 17 Apr 2020
    7.8
    High

    CVE-2020-7080

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the Autodesk FBX-SDK versions 2019.0 and earlier may lead to arbitrary code execution on a system running it.

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2019-6203

    Last Modified: 21 Nov 2024

    A logic issue was addressed with improved state management. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2. An attacker in a privileged network position may be able to intercept network traffic.

    Published: 17 Apr 2020
    —
    Unknown

    CVE-2020-10178

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-11637. Reason: This candidate is a reservation duplicate of CVE-2020-11637. Notes: All CVE users should reference CVE-2020-11637 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Apr 2020
    6.5
    Medium

    CVE-2020-11880

    Last Modified: 21 Nov 2024

    An issue was discovered in KDE KMail before 19.12.3. By using the proprietary (non-RFC6068) "mailto?attach=..." parameter, a website (or other source of mailto links) can make KMail attach local files to a composed email message without showing a warning to the user, as demonstrated by an attach=.bash_history value.

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2020-11878

    Last Modified: 21 Nov 2024

    The Jitsi Meet (aka docker-jitsi-meet) stack on Docker before stable-4384-1 uses default passwords (such as passw0rd) for system accounts.

    Published: 17 Apr 2020
    7.5
    High

    CVE-2020-11876

    Last Modified: 21 Nov 2024

    airhost.exe in Zoom Client for Meetings 4.6.11 uses the SHA-256 hash of 0123425234234fsdfsdr3242 for initialization of an OpenSSL EVP AES-256 CBC context. NOTE: the vendor states that this initialization only occurs within unreachable code

    Published: 17 Apr 2020
    7.5
    High

    CVE-2020-11877

    Last Modified: 21 Nov 2024

    airhost.exe in Zoom Client for Meetings 4.6.11 uses 3423423432325249 as the Initialization Vector (IV) for AES-256 CBC encryption. NOTE: the vendor states that this IV is used only within unreachable code

    Published: 17 Apr 2020
    8.8
    High

    CVE-2020-9523

    Last Modified: 21 Nov 2024

    Insufficiently protected credentials vulnerability on Micro Focus enterprise developer and enterprise server, affecting all version prior to 4.0 Patch Update 16, and version 5.0 Patch Update 6. The vulnerability could allow an attacker to transmit hashed credentials for the user account running the Micro Focus Directory Server (MFDS) to an arbitrary site, compromising that account's security.

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2019-12002

    Last Modified: 21 Nov 2024

    A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.

    Published: 17 Apr 2020
    6.4
    Medium

    CVE-2019-12001

    Last Modified: 21 Nov 2024

    A remote session reuse vulnerability leading to access restriction bypass was discovered in HPE MSA 2040 SAN Storage; HPE MSA 1040 SAN Storage; HPE MSA 1050 SAN Storage; HPE MSA 2042 SAN Storage; HPE MSA 2050 SAN Storage; HPE MSA 2052 SAN Storage version(s): GL225P001 and earlier; GL225P001 and earlier; VE270R001-01 and earlier; GL225P001 and earlier; VL270R001-01 and earlier; VL270R001-01 and earlier.

    Published: 17 Apr 2020
    6.8
    Medium

    CVE-2019-20785

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 8.0 and 8.1 software for the DTAG carrier. RILD in the radio layer uses an uninitialized variable. The LG ID is LVE-SMP-180013 (January 2019).

    Published: 17 Apr 2020
    5.5
    Medium

    CVE-2019-20784

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (MTK chipsets) software. Interaction of GPS with 911 emergency calls is mishandled. The LG ID is LVE-SMP-180012 (January 2019).

    Published: 17 Apr 2020
    9.1
    Critical

    CVE-2019-20783

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 (North America CDMA) software. The LTE protocol implementation allows a bypass of AKA (Authentication and Key Agreement). The LG ID is LVE-SMP-180014 (February 2019).

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2019-20782

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. LG Advanced Flash (LAF) has a buffer overflow. The LG ID is LVE-SMP-190001 (March 2019).

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2019-20780

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. Certain security settings, related to whether packages are verified and accepted only from known sources, are mishandled. The LG ID is LVE-SMP-190002 (April 2019).

    Published: 17 Apr 2020
    5.5
    Medium

    CVE-2019-20779

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A TrustZone trusted application can crash via crafted input. The LG ID is LVE-SMP-190003 (May 2019).

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2019-20778

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Backup subsystem does not properly restrict operations or validate their input. The LG ID is LVE-SMP-190004 (June 2019).

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2019-20777

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. WapService mishandles OTA Provisioning on V40 and G7 devices. The LG ID is LVE-SMP-190006 (July 2019).

    Published: 17 Apr 2020
    5.5
    Medium

    CVE-2019-20776

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, and 8.1 software. A TZ trusted application can crash via crafted input. The LG ID is LVE-SMP-190005 (July 2019).

    Published: 17 Apr 2020
    5.5
    Medium

    CVE-2019-20775

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 9.0 (Qualcomm SDM450, SDM845, SM6150, and SM8150 chipsets) software. Weak encryption leads to local information disclosure. The LG ID is LVE-SMP-190010 (August 2019).

    Published: 17 Apr 2020
    5.5
    Medium

    CVE-2019-20774

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. A system service allows local retrieval of the user's password. The LG ID is LVE-SMP-190009 (August 2019).

    Published: 17 Apr 2020
    7.8
    High

    CVE-2019-20773

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. Unprivileged applications can execute shell commands via the connectivity service. The LG ID is LVE-SMP-190008 (August 2019).

    Published: 17 Apr 2020
    9.8
    Critical

    CVE-2019-20772

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 7.0, 7.1, 7.2, 8.0, 8.1, and 9.0 software. The Account subsystem allows authorization bypass. The LG ID is LVE-SMP-190007 (August 2019).

    Published: 17 Apr 2020
    7.8
    High

    CVE-2019-20770

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 9.0 software. The HAL service has a buffer overflow that leads to arbitrary code execution. The LG ID is LVE-SMP-190013 (September 2019).

    Published: 17 Apr 2020
    7.8
    High

    CVE-2019-20769

    Last Modified: 21 Nov 2024

    An issue was discovered in LG PC Suite for LG G3 and earlier (aka LG PC Suite v5.3.27 and earlier). DLL Hijacking can occur via a Trojan horse DLL in the current working directory. The LG ID is LVE-MOT-190001 (November 2019).

    Published: 17 Apr 2020
    7.8
    High

    CVE-2020-11875

    Last Modified: 21 Nov 2024

    An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9.0, and 10.0 (MTK chipsets) software. The MTK kernel does not properly implement exception handling, allowing an attacker to gain privileges. The LG ID is LVE-SMP-200001 (February 2020).

    Published: 17 Apr 2020
    7.5
    High

    CVE-2020-4277

    Last Modified: 21 Nov 2024

    IBM TRIRIGA Application Platform 3.5.3 and 3.6.1 discloses sensitive information in error messages that could aid an attacker formulate future attacks. IBM X-Force ID: 175993.

    Published: 17 Apr 2020
    5.4
    Medium

    CVE-2019-4749

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 173308.

    Published: 17 Apr 2020
    6.1
    Medium

    CVE-2019-4644

    Last Modified: 21 Nov 2024

    IBM Maximo Asset Management 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170880.

    Published: 17 Apr 2020