CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2019-20530

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), P(9.0), and Q(10.0) software. Arbitrary code execution is possible on the lock screen. The Samsung ID is SVE-2019-15266 (December 2019).

    Published: 24 Mar 2020
    4.6
    Medium

    CVE-2020-10855

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppTray. The Samsung ID is SVE-2019-16192 (January 2020).

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-10854

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Kernel stack addresses are leaked to userspace. The Samsung ID is SVE-2019-16161 (January 2020).

    Published: 24 Mar 2020
    5.3
    Medium

    CVE-2020-10853

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery leaks cached data. The Samsung IDs are SVE-2019-16010, SVE-2019-16011, SVE-2019-16012 (January 2020).

    Published: 24 Mar 2020
    7.8
    High

    CVE-2020-10852

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a stack overflow in display driver. The Samsung ID is SVE-2019-15877 (January 2020).

    Published: 24 Mar 2020
    7.8
    High

    CVE-2020-10851

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is a stack overflow in the kperfmon driver. The Samsung ID is SVE-2019-15876 (January 2020).

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-10850

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The secure bootloade has a buffer overflow of the USB buffer, leading to arbitrary code execution. The Samsung ID is SVE-2019-15872 (January 2020).

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-10849

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID is SVE-2019-14575 (January 2020).

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-10848

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos 9810 chipsets) software. Arbitrary memory mapping exists in TEE. The Samsung ID is SVE-2019-16665 (February 2020).

    Published: 24 Mar 2020
    6.8
    Medium

    CVE-2020-10847

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SVE-2019-16614 (February 2020).

    Published: 24 Mar 2020
    5.5
    Medium

    CVE-2020-10846

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devices, leading to potentially unwanted binaries being downloaded. The Samsung ID is SVE-2019-16554 (February 2020).

    Published: 24 Mar 2020
    6.4
    Medium

    CVE-2020-10845

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a race condition leading to a use-after-free in MTP. The Samsung ID is SVE-2019-16520 (February 2020).

    Published: 24 Mar 2020
    6.5
    Medium

    CVE-2020-10844

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.x), and Q(10.0) software. There is an out-of-bounds read vulnerability in media.audio_policy. The Samsung ID is SVE-2019-16333 (February 2020).

    Published: 24 Mar 2020
    7
    High

    CVE-2020-10843

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets) software. There are race conditions in the hdcp2 driver. The Samsung ID is SVE-2019-16296 (February 2020).

    Published: 24 Mar 2020
    7.8
    High

    CVE-2020-10842

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets) software. There is a heap out-of-bounds write in the tsmux driver. The Samsung ID is SVE-2019-16295 (February 2020).

    Published: 24 Mar 2020
    7.8
    High

    CVE-2020-10841

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) software. There is an arbitrary kfree in the vipx and vertex drivers. The Samsung ID is SVE-2019-16294 (February 2020).

    Published: 24 Mar 2020
    7.1
    High

    CVE-2020-10840

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) software. There is a kernel pointer leak in the vipx driver. The Samsung ID is SVE-2019-16293 (February 2020).

    Published: 24 Mar 2020
    6.8
    Medium

    CVE-2020-10839

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card. The Samsung ID is SVE-2019-16193 (February 2020).

    Published: 24 Mar 2020
    7.8
    High

    CVE-2020-10838

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. PROCA allows a use-after-free and arbitrary code execution. The Samsung ID is SVE-2019-16132 (February 2020).

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-10837

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and arbitrary code execution. The Samsung ID is SVE-2019-15984 (February 2020).

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-10836

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The Widevine Trustlet allows read and write operations on arbitrary memory locations. The Samsung ID is SVE-2019-15873 (February 2020).

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-10835

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with any (before February 2020 for Exynos modem chipsets) software. There is a buffer overflow in baseband CP message decoding. The Samsung IDs are SVE-2019-15816 and SVE-2019-15817 (February 2020).

    Published: 24 Mar 2020
    5.3
    Medium

    CVE-2020-10834

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view notifications on the lock screen via Routines. The Samsung ID is SVE-2019-15074 (February 2020).

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-10833

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows attackers to access the quick panel and notifications. The Samsung ID is SVE-2019-16532 (March 2020).

    Published: 24 Mar 2020
    7.8
    High

    CVE-2020-10832

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. Kernel Wi-Fi drivers allow out-of-bounds Read or Write operations (e.g., a buffer overflow). The Samsung IDs are SVE-2019-16125, SVE-2019-16134, SVE-2019-16158, SVE-2019-16159, SVE-2019-16319, SVE-2019-16320, SVE-2019-16337, SVE-2019-16464, SVE-2019-16465, SVE-2019-16467 (March 2020).

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-10831

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can trigger an update to arbitrary touch-screen firmware. The Samsung ID is SVE-2019-16013 (March 2020).

    Published: 24 Mar 2020
    2.4
    Low

    CVE-2020-10830

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can view notifications by entering many PINs in Lockdown mode. The Samsung ID is SVE-2019-16590 (March 2020).

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-7003

    Last Modified: 21 Nov 2024

    In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, sensitive information is transmitted over some web applications in clear text.

    Published: 24 Mar 2020
    7.8
    High

    CVE-2020-10829

    Last Modified: 21 Nov 2024

    An issue was discovered on Samsung mobile devices with O(8.0), P(9.0), and Q(10.0) (Broadcom chipsets) software. A kernel driver heap overflow leads to arbitrary code execution. The Samsung ID is SVE-2019-15880 (March 2020).

    Published: 24 Mar 2020
    7.5
    High

    CVE-2019-18242

    Last Modified: 21 Nov 2024

    In Moxa ioLogik 2500 series firmware, Version 3.0 or lower, and IOxpress configuration utility, Version 2.3.0 or lower, frequent and multiple requests for short-term use may cause the web server to fail.

    Published: 24 Mar 2020
    9.1
    Critical

    CVE-2020-6972

    Last Modified: 21 Nov 2024

    In Notifier Web Server (NWS) Version 3.50 and earlier, the Honeywell Fire Web Server’s authentication may be bypassed by a capture-replay attack from a web browser.

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-10938

    Last Modified: 21 Nov 2024

    GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c.

    Published: 24 Mar 2020
    5.3
    Medium

    CVE-2020-4309

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0CD could disclose sensitive information to an unauthenticated user which could be used to aid in further attacks against the system. IBM X-Force ID: 177080.

    Published: 24 Mar 2020
    8.8
    High

    CVE-2020-4253

    Last Modified: 21 Nov 2024

    IBM Content Navigator 3.0CD does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 175559.

    Published: 24 Mar 2020
    6.1
    Medium

    CVE-2019-4681

    Last Modified: 21 Nov 2024

    IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.17 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 171734.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2019-4553

    Last Modified: 21 Nov 2024

    IBM API Connect V5.0.0.0 through 5.0.8.7iFix3 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 165958.

    Published: 24 Mar 2020
    7.2
    High

    CVE-2020-10934

    Last Modified: 21 Nov 2024

    Acyba AcyMailing before 6.9.2 mishandles file uploads by admins.

    Published: 24 Mar 2020
    6.1
    Medium

    CVE-2020-10570

    Last Modified: 21 Nov 2024

    The Telegram application through 5.12 for Android, when Show Popup is enabled, might allow physically proximate attackers to bypass intended restrictions on message reading and message replying. This might be interpreted as a bypass of the passcode feature.

    Published: 24 Mar 2020
    8.8
    High

    CVE-2020-11111

    Last Modified: 25 Aug 2026

    FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).

    Published: 24 Mar 2020
    6.4
    Medium

    CVE-2020-10689

    Last Modified: 21 Nov 2024

    A flaw was found in the Eclipse Che up to version 7.8.x, where it did not properly restrict access to workspace pods. An authenticated user can exploit this flaw to bypass JWT proxy and gain access to the workspace pods of another user. Successful exploitation requires knowledge of the service name and namespace of the target pod.

    Published: 24 Mar 2020
    7.5
    High

    CVE-2020-10931

    Last Modified: 21 Nov 2024

    Memcached 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (daemon crash) via a crafted binary protocol header to try_read_command_binary in memcached.c.

    Published: 24 Mar 2020
    5.9
    Medium

    CVE-2020-10941

    Last Modified: 21 Nov 2024

    Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.

    Published: 24 Mar 2020
    9.8
    Critical

    CVE-2020-7610

    Last Modified: 21 Nov 2024

    All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

    Published: 24 Mar 2020
    5
    Medium

    CVE-2020-5252

    Last Modified: 21 Nov 2024

    The command-line "safety" package for Python has a potential security issue. There are two Python characteristics that allow malicious code to “poison-pill” command-line Safety package detection routines by disguising, or obfuscating, other malicious or non-secure packages. This vulnerability is considered to be of low severity because the attack makes use of an existing Python condition, not the Safety tool itself. This can happen if: You are running Safety in a Python environment that you don’t trust. You are running Safety from the same Python environment where you have your dependencies installed. Dependency packages are being installed arbitrarily or without proper verification. Users can mitigate this issue by doing any of the following: Perform a static analysis by installing Docker and running the Safety Docker image: $ docker run --rm -it pyupio/safety check -r requirements.txt Run Safety against a static dependencies list, such as the requirements.txt file, in a separate, clean Python environment. Run Safety from a Continuous Integration pipeline. Use PyUp.io, which runs Safety in a controlled environment and checks Python for dependencies without any need to install them. Use PyUp's Online Requirements Checker.

    Published: 23 Mar 2020
    9.8
    Critical

    CVE-2020-1944

    Last Modified: 21 Nov 2024

    There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and Transfer-Encoding and Content length headers. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

    Published: 23 Mar 2020
    7.5
    High

    CVE-2020-10875

    Last Modified: 21 Nov 2024

    Motorola FX9500 devices allow remote attackers to conduct absolute path traversal attacks, as demonstrated by PL/SQL Server Pages files such as /include/viewtagdb.psp.

    Published: 23 Mar 2020
    9.8
    Critical

    CVE-2020-10879

    Last Modified: 21 Nov 2024

    rConfig before 3.9.5 allows command injection by sending a crafted GET request to lib/crud/search.crud.php since the nodeId parameter is passed directly to the exec function without being escaped.

    Published: 23 Mar 2020
    9.8
    Critical

    CVE-2019-17559

    Last Modified: 21 Nov 2024

    There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and scheme parsing. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

    Published: 23 Mar 2020
    9.8
    Critical

    CVE-2019-17565

    Last Modified: 21 Nov 2024

    There is a vulnerability in Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.8, and 8.0.0 to 8.0.5 with a smuggling attack and chunked encoding. Upgrade to versions 7.1.9 and 8.0.6 or later versions.

    Published: 23 Mar 2020
    7.5
    High

    CVE-2020-10874

    Last Modified: 21 Nov 2024

    Motorola FX9500 devices allow remote attackers to read database files.

    Published: 23 Mar 2020