6.5
    Medium

    CVE-2020-0890

    Last Modified: 23 Feb 2026

    <p>A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate specific malicious data from a user on a guest operating system.</p> <p>To exploit the vulnerability, an attacker who already has a privileged account on a guest operating system, running as a virtual machine, could run a specially crafted application.</p> <p>The security update addresses the vulnerability by resolving the conditions where Hyper-V would fail to handle these requests.</p>

    Published:11 Sept 2020
    7.8
    High

    CVE-2020-0887

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0788, CVE-2020-0877.

    Published:12 Mar 2020
    10
    Critical

    CVE-2020-0796

    Last Modified: 14 Mar 2020

    A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests, aka 'Windows SMBv3 Client/Server Remote Code Execution Vulnerability'.

    Source:eerykitty
    Published:12 Mar 2020
    Unknown

    CVE-2020-00796

    https://github.com/bsec404/cve-2020-00796

    7.8
    High

    CVE-2020-0787

    Last Modified: 29 Oct 2025

    An elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic links, aka 'Windows Background Intelligent Transfer Service Elevation of Privilege Vulnerability'.

    Published:12 Mar 2020
    7.8
    High

    CVE-2020-0753

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0754.

    Published:11 Feb 2020
    5.5
    Medium

    CVE-2020-0728

    Last Modified: 21 Nov 2024

    An information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules Installer Service Information Disclosure Vulnerability'.

    Published:11 Feb 2020
    8.8
    High

    CVE-2020-0688

    Last Modified: 5 Mar 2020

    A remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory, aka 'Microsoft Exchange Memory Corruption Vulnerability'.

    Source:Metasploit
    Published:11 Feb 2020
    7.8
    High

    CVE-2020-0683

    Last Modified: 17 Feb 2020

    An elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0686.

    Source:nu11secur1ty
    Published:11 Feb 2020
    7.5
    High

    CVE-2020-0674

    Last Modified: 17 Nov 2020

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.

    Source:maxpl0it
    Published:11 Feb 2020
    7.8
    High

    CVE-2020-0668

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0669, CVE-2020-0670, CVE-2020-0671, CVE-2020-0672.

    Published:11 Feb 2020
    8.1
    High

    CVE-2020-0665

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the trusting forest request delegation of a TGT for an identity from the trusted forest, aka 'Active Directory Elevation of Privilege Vulnerability'.

    Published:11 Feb 2020
    9.8
    Critical

    CVE-2020-0646

    Last Modified: 31 Mar 2020

    A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework Remote Code Execution Injection Vulnerability'.

    Source:Metasploit
    Published:14 Jan 2020
    7.8
    High

    CVE-2020-0624

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0642.

    Published:14 Jan 2020
    9.8
    Critical

    CVE-2020-0618

    Last Modified: 17 Sept 2020

    A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.

    Source:West Shepherd
    Published:11 Feb 2020
    9.8
    Critical

    CVE-2020-0610

    Last Modified: 18 Jun 2020

    A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0609.

    Source:ollypwn
    Published:14 Jan 2020
    9.8
    Critical

    CVE-2020-0609

    Last Modified: 18 Jun 2020

    A remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Windows Remote Desktop Gateway (RD Gateway) Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0610.

    Source:ollypwn
    Published:14 Jan 2020
    8.1
    High

    CVE-2020-0601

    Last Modified: 16 Jan 2020

    A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source, aka 'Windows CryptoAPI Spoofing Vulnerability'.

    Source:Oliver Lyak
    Published:14 Jan 2020
    4.7
    Medium

    CVE-2020-0568

    Last Modified: 21 Nov 2024

    Race condition in the Intel(R) Driver and Support Assistant before version 20.1.5 may allow an authenticated user to potentially enable denial of service via local access.

    Published:15 Apr 2020
    7.8
    High

    CVE-2020-0557

    Last Modified: 21 Nov 2024

    Insecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated user to potentially enable escalation of privilege via local access.

    Published:15 Apr 2020
    5.6
    Medium

    CVE-2020-0551

    Last Modified: 21 Nov 2024

    Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. The list of affected products is provided in intel-sa-00334: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00334.html

    Published:10 Mar 2020
    9.8
    Critical

    CVE-2020-0471

    Last Modified: 21 Nov 2024

    In reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due to improper input validation. This could lead to remote escalation of privilege between two Bluetooth devices by a proximal attacker, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-8.0, Android-8.1, Android-9, Android-10, Android-11; Android ID: A-169327567.

    Published:11 Jan 2021
    7.5
    High

    CVE-2020-0463

    Last Modified: 21 Nov 2024

    In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure from the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-8.0 Android-8.1 Android-9Android ID: A-169342531

    Published:14 Dec 2020
    7.8
    High

    CVE-2020-0458

    Last Modified: 21 Nov 2024

    In SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-8.0 Android-8.1Android ID: A-160265164

    Published:14 Dec 2020
    5.5
    Medium

    CVE-2020-0453

    Last Modified: 21 Nov 2024

    In updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-8.0 Android-8.1Android ID: A-159060474

    Published:10 Nov 2020
    9.8
    Critical

    CVE-2020-0452

    Last Modified: 21 Nov 2024

    In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-159625731

    Published:10 Nov 2020
    8.8
    High

    CVE-2020-0451

    Last Modified: 21 Nov 2024

    In sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-9 Android-8.0 Android-8.1Android ID: A-158762825

    Published:10 Nov 2020
    5.5
    Medium

    CVE-2020-0443

    Last Modified: 21 Nov 2024

    In LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. This could lead to local denial of service requiring factory reset to restore with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-152410253

    Published:10 Nov 2020
    7.8
    High

    CVE-2020-0439

    Last Modified: 21 Nov 2024

    In generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This could lead to local escalation of privilege that allows instant apps access to permissions not allowed for instant apps, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-140256621

    Published:10 Nov 2020
    7.8
    High

    CVE-2020-0423

    Last Modified: 21 Nov 2024

    In binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-161151868References: N/A

    Published:14 Oct 2020
    7.8
    High

    CVE-2020-0421

    Last Modified: 21 Nov 2024

    In appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error handling. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-161894517

    Published:14 Oct 2020
    7.8
    High

    CVE-2020-0418

    Last Modified: 21 Nov 2024

    In getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-153879813

    Published:10 Nov 2020
    8.8
    High

    CVE-2020-0416

    Last Modified: 21 Nov 2024

    In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation of privilege and permissions with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1Android ID: A-155288585

    Published:14 Oct 2020
    7.5
    High

    CVE-2020-0413

    Last Modified: 21 Nov 2024

    In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-158778659

    Published:14 Oct 2020
    7.8
    High

    CVE-2020-0409

    Last Modified: 21 Nov 2024

    In create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.0 Android-8.1 Android-9Android ID: A-156997193

    Published:10 Nov 2020
    7.8
    High

    CVE-2020-0401

    Last Modified: 21 Nov 2024

    In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and granting spurious permissions with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150857253

    Published:17 Sept 2020
    7.8
    High

    CVE-2020-0394

    Last Modified: 21 Nov 2024

    In onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to local escalation of privilege and untrusted devices accessing contact lists with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-155648639

    Published:17 Sept 2020
    7.8
    High

    CVE-2020-0392

    Last Modified: 21 Nov 2024

    In getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-150226608

    Published:17 Sept 2020
    7.8
    High

    CVE-2020-0391

    Last Modified: 21 Nov 2024

    In applyPolicy of PackageManagerService.java, there is possible arbitrary command execution as System due to an unenforced protected-broadcast. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-9 Android-10 Android-11Android ID: A-158570769

    Published:17 Sept 2020
    7.5
    High

    CVE-2020-0381

    Last Modified: 21 Nov 2024

    In Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote information disclosure in a highly constrained process with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10 Android-11Android ID: A-150159669

    Published:17 Sept 2020
    9.8
    Critical

    CVE-2020-0380

    Last Modified: 21 Nov 2024

    In allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-146398979

    Published:17 Sept 2020
    7.5
    High

    CVE-2020-0377

    Last Modified: 21 Nov 2024

    In gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.1 Android-9 Android-10 Android-11 Android-8.0Android ID: A-158833854

    Published:14 Oct 2020
    8.8
    High

    CVE-2020-0245

    Last Modified: 21 Nov 2024

    In DecodeFrameCombinedMode of combined_decode.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11 Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-152496149

    Published:17 Sept 2020
    7.8
    High

    CVE-2020-0242

    Last Modified: 21 Nov 2024

    In reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of privilege in the media server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151643722

    Published:11 Aug 2020
    7.8
    High

    CVE-2020-0241

    Last Modified: 21 Nov 2024

    In NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-151456667

    Published:11 Aug 2020
    8.8
    High

    CVE-2020-0240

    Last Modified: 21 Nov 2024

    In NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150706594

    Published:11 Aug 2020
    7.8
    High

    CVE-2020-0227

    Last Modified: 21 Nov 2024

    In onCommand of CompanionDeviceManagerService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege allowing background data usage or launching from the background, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-129476618

    Published:17 Jul 2020
    7.8
    High

    CVE-2020-0226

    Last Modified: 21 Nov 2024

    In createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege in the graphics server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-150226994

    Published:17 Jul 2020
    9.8
    Critical

    CVE-2020-0225

    Last Modified: 21 Nov 2024

    In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142546668

    Published:17 Jul 2020
    7.8
    High

    CVE-2020-0219

    Last Modified: 21 Nov 2024

    In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-122836081

    Published:11 Jun 2020