CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-18693

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. There is a buffer overflow in the fps sysfs entry. The Samsung ID is SVE-2016-7510 (January 2017).

    Published: 7 Apr 2020
    5.3
    Medium

    CVE-2017-18694

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with software through 2016-10-25 (Exynos5 chipsets). Attackers can read kernel addresses in the log because an incorrect format specifier is used. The Samsung ID is SVE-2016-7551 (January 2017).

    Published: 7 Apr 2020
    6.5
    Medium

    CVE-2017-18695

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), M(6.0), and N(7.0) software. Attackers (who control a certain subdomain) can discover a user's credentials, during an email account login, via an EAS autodiscover packet. The Samsung ID is SVE-2016-7654 (January 2017).

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2017-18696

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0) and N(7.0) (Exynos7420, Exynos8890, or MSM8996 chipsets) software. RKP allows memory corruption. The Samsung ID is SVE-2016-7897 (January 2017).

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2016-11025

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a memcpy heap-based buffer overflow in the OTP service. The Samsung ID is SVE-2016-7114 (December 2016).

    Published: 7 Apr 2020
    7.5
    High

    CVE-2016-11026

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. BootReceiver allows attackers to trigger a system crash because of incorrect exception handling. The Samsung ID is SVE-2016-7118 (December 2016).

    Published: 7 Apr 2020
    2.4
    Low

    CVE-2016-11027

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0) software. In the Shade Locked state, a physically proximate attacker can read notifications on the lock screen. The Samsung ID is SVE-2016-7132 (December 2016).

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2016-11028

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with software through 2016-09-13 (Exynos AP chipsets). There is a stack-based buffer overflow in the OTP TrustZone trustlet. The Samsung IDs are SVE-2016-7173 and SVE-2016-7174 (December 2016).

    Published: 7 Apr 2020
    7.5
    High

    CVE-2016-11029

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.0/5.1), M(6.0), and N(7.0) software. Attackers can read the password of the Mobile Hotspot in the log because of an unprotected intent. The Samsung ID is SVE-2016-7301 (December 2016).

    Published: 7 Apr 2020
    8.1
    High

    CVE-2016-11030

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (with Hrm sensor support) software. The sysfs of the MAX86902 sensor driver does not prevent concurrent access, leading to a race condition and resultant heap-based buffer overflow. The Samsung ID is SVE-2016-7341 (December 2016).

    Published: 7 Apr 2020
    7.5
    High

    CVE-2016-11031

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) software. AntService allows a system_server crash and reboot. The Samsung ID is SVE-2016-7044 (November 2016).

    Published: 7 Apr 2020
    5.3
    Medium

    CVE-2016-11032

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0) software. An attacker can disable all Sound functionality by broadcasting an unprotected intent. The Samsung IDs are SVE-2016-7179 and SVE-2016-7182 (November 2016).

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2016-11033

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0) software. There is a heap-based buffer overflow in tlc_server. The Samsung IDs are SVE-2016-7220 and SVE-2016-7225 (November 2016).

    Published: 7 Apr 2020
    6.5
    Medium

    CVE-2016-11034

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. The decode function in Qjpeg in Qt 5.7 allows attackers to trigger a system crash via a malformed image. The Samsung ID is SVE-2016-6560 (October 2016).

    Published: 7 Apr 2020
    5.5
    Medium

    CVE-2016-11035

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with software through 2016-05-27 (Exynos AP chipsets). A local graphics user can cause a Kernel Crash via the fb0(DECON) frame buffer interface. The Samsung ID is SVE-2016-7011 (October 2016).

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2016-11036

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-6008 (August 2016).

    Published: 7 Apr 2020
    5.3
    Medium

    CVE-2020-7618

    Last Modified: 21 Nov 2024

    sds through 3.2.0 is vulnerable to Prototype Pollution.The library could be tricked into adding or modifying properties of the 'Object.prototype' by abusing the 'set' function located in 'js/set.js'.

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2020-7614

    Last Modified: 21 Nov 2024

    npm-programmatic through 0.0.12 is vulnerable to Command Injection.The packages and option properties are concatenated together without any validation and are used by the 'exec' function directly.

    Published: 7 Apr 2020
    8.1
    High

    CVE-2020-7613

    Last Modified: 21 Nov 2024

    clamscan through 1.2.0 is vulnerable to Command Injection. It is possible to inject arbitrary commands as part of the `_is_clamav_binary` function located within `Index.js`. It should be noted that this vulnerability requires a pre-requisite that a folder should be created with the same command that will be chained to execute. This lowers the risk of this issue.

    Published: 7 Apr 2020
    —
    Unknown

    CVE-2016-11037

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-6604. Reason: This candidate is a reservation duplicate of CVE-2016-6604. Notes: All CVE users should reference CVE-2016-6604 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Apr 2020
    9.8
    Critical

    CVE-2016-11038

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with software through 2016-04-05 (incorporating the Samsung Professional Audio SDK). The Jack audio service doesn't implement access control for shared memory, leading to arbitrary code execution or privilege escalation. The Samsung ID is SVE-2016-5953 (July 2016).

    Published: 7 Apr 2020
    5.3
    Medium

    CVE-2020-7616

    Last Modified: 21 Nov 2024

    express-mock-middleware through 0.0.6 is vulnerable to Prototype Pollution. Exported functions by the package can be tricked into adding or modifying properties of the `Object.prototype`. Exploitation of this vulnerability requires creation of a new directory where an attack code can be placed which will then be exported by `express-mock-middleware`. As such, this is considered to be a low risk.

    Published: 7 Apr 2020
    7.8
    High

    CVE-2020-7615

    Last Modified: 21 Nov 2024

    fsa through 0.5.1 is vulnerable to Command Injection. The first argument of 'execGitCommand()', located within 'lib/rep.js#63' can be controlled by users without any sanitization to inject arbitrary commands.

    Published: 7 Apr 2020
    7.5
    High

    CVE-2016-11039

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with KK(4.4), L(5.0/5.1), and M(6.0) (AP + CP MDM9x35, or Qualcomm Onechip) software. There is a NULL pointer dereference issue in the IPC socket code. The Samsung ID is SVE-2016-5980 (July 2016).

    Published: 7 Apr 2020
    4.6
    Medium

    CVE-2016-11040

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) (with USB OTG MyFile2014_L_ESS support) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2015-5068 (June 2016).

    Published: 7 Apr 2020
    7.5
    High

    CVE-2020-5734

    Last Modified: 21 Nov 2024

    Classic buffer overflow in SolarWinds Dameware allows a remote, unauthenticated attacker to cause a denial of service by sending a large 'SigPubkeyLen' during ECDH key exchange.

    Published: 7 Apr 2020
    4.6
    Medium

    CVE-2016-11041

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with KK(4.4) software. Attackers can bypass the lockscreen by sending an AT command over USB. The Samsung ID is SVE-2015-5301 (June 2016).

    Published: 7 Apr 2020
    7.5
    High

    CVE-2016-11042

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) software. There is a SIM Lock bypass. The Samsung ID is SVE-2016-5381 (June 2016).

    Published: 7 Apr 2020
    7.5
    High

    CVE-2016-11043

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with M(6.0) software. The S/MIME implementation in EAS uses DES (where 3DES is intended). The Samsung ID is SVE-2016-5871 (June 2016).

    Published: 7 Apr 2020
    7.8
    High

    CVE-2016-11044

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) and M(6.0) (with Fingerprint support) software. The check of an application's signature can be bypassed during installation. The Samsung ID is SVE-2016-5923 (June 2016).

    Published: 7 Apr 2020
    7.8
    High

    CVE-2016-11045

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. The Gallery library allow memory corruption via a malformed image. The Samsung ID is SVE-2016-5317 (May 2016).

    Published: 7 Apr 2020
    7.5
    High

    CVE-2016-11046

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with JBP(4.3), KK(4.4), and L(5.0/5.1) software. Because of a misused whitelist, attackers can reach the radio layer (aka RIL or RILD) to place calls or send SMS messages. The Samsung ID is SVE-2016-5733 (May 2016).

    Published: 7 Apr 2020
    7.8
    High

    CVE-2016-11047

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with JBP(4.2) and KK(4.4) (Marvell chipsets) software. The ACIPC-MSOCKET driver allows local privilege escalation via a stack-based buffer overflow. The Samsung ID is SVE-2016-5393 (April 2016).

    Published: 7 Apr 2020
    4.6
    Medium

    CVE-2016-11048

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) (Spreadtrum or Marvell chipsets) software. There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2016-5421 (March 2016).

    Published: 7 Apr 2020
    9.1
    Critical

    CVE-2016-11049

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with software through 2016-01-16 (Shannon333/308/310 chipsets). The IMEI may be retrieved and modified because of an error in managing key information. The Samsung ID is SVE-2016-5435 (March 2016).

    Published: 7 Apr 2020
    4.3
    Medium

    CVE-2016-11050

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with S3(KK), Note2(KK), S4(L), Note3(L), and S5(L) software. An attacker can rewrite the IMEI by flashing crafted firmware. The Samsung ID is SVE-2016-5562 (March 2016).

    Published: 7 Apr 2020
    —
    Unknown

    CVE-2016-11051

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-0569. Reason: This candidate is a duplicate of CVE-2015-0569. Notes: All CVE users should reference CVE-2015-0569 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 7 Apr 2020
    7.8
    High

    CVE-2016-11052

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with L(5.0/5.1) software. je_free in libQjpeg.so in Qjpeg in Qt 5.5 allows memory corruption via a malformed JPEG file. The Samsung ID is SVE-2015-5110 (January 2016).

    Published: 7 Apr 2020
    4.6
    Medium

    CVE-2016-11053

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with software through 2015-11-11 (supporting FRP/RL). There is a Factory Reset Protection (FRP) bypass. The Samsung ID is SVE-2015-5131 (January 2016).

    Published: 7 Apr 2020
    5.4
    Medium

    CVE-2020-2176

    Last Modified: 21 Nov 2024

    Multiple form validation endpoints in Jenkins useMango Runner Plugin 1.4 and earlier do not escape values received from the useMango service, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to control the values returned from the useMango service.

    Published: 7 Apr 2020
    5.4
    Medium

    CVE-2020-2175

    Last Modified: 21 Nov 2024

    Jenkins FitNesse Plugin 1.31 and earlier does not correctly escape report contents before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control the XML input files processed by the plugin.

    Published: 7 Apr 2020
    5.4
    Medium

    CVE-2020-2173

    Last Modified: 21 Nov 2024

    Jenkins Gatling Plugin 1.2.7 and earlier prevents Content-Security-Policy headers from being set for Gatling reports served by the plugin, resulting in an XSS vulnerability exploitable by users able to change report content.

    Published: 7 Apr 2020
    6.1
    Medium

    CVE-2020-2174

    Last Modified: 21 Nov 2024

    Jenkins AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output, resulting in a reflected cross-site scripting vulnerability.

    Published: 7 Apr 2020
    6.5
    Medium

    CVE-2020-2172

    Last Modified: 21 Nov 2024

    Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

    Published: 7 Apr 2020
    6.1
    Medium

    CVE-2020-6171

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the index page of the CLink Office 2.0 management console allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

    Published: 7 Apr 2020
    7.5
    High

    CVE-2020-12059

    Last Modified: 21 Nov 2024

    An issue was discovered in Ceph through 13.2.9. A POST request with an invalid tagging XML can crash the RGW process by triggering a NULL pointer exception.

    Published: 7 Apr 2020
    6.3
    Medium

    CVE-2020-8096

    Last Modified: 21 Nov 2024

    Untrusted Search Path vulnerability in Bitdefender High-Level Antimalware SDK for Windows allows an attacker to load third party code from a DLL library in the search path. This issue affects: Bitdefender High-Level Antimalware SDK for Windows versions prior to 3.0.1.204 .

    Published: 7 Apr 2020
    8.1
    High

    CVE-2020-11620

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6423

    Last Modified: 21 Nov 2024

    Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Apr 2020
    8.8
    High

    CVE-2020-6434

    Last Modified: 21 Nov 2024

    Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 7 Apr 2020