7
    High

    CVE-2020-0218

    Last Modified: 21 Nov 2024

    In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-136005905

    Published:11 Jun 2020
    7.8
    High

    CVE-2020-0215

    Last Modified: 21 Nov 2024

    In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass. This could lead to local escalation of privilege that exposes a pairing Bluetooth MAC address with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-9 Android-10 Android-11 Android-8.0 Android-8.1 Android ID: A-140417248

    Published:11 Jun 2020
    7.8
    High

    CVE-2020-0209

    Last Modified: 21 Nov 2024

    In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145206842

    Published:11 Jun 2020
    7.8
    High

    CVE-2020-0203

    Last Modified: 21 Nov 2024

    In freeIsolatedUidLocked of ProcessList.java, there is a possible UID reuse due to improper cleanup. This could lead to local escalation of privilege between constrained processes with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146313311

    Published:11 Jun 2020
    9.8
    Critical

    CVE-2020-0201

    Last Modified: 21 Nov 2024

    In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143601727

    Published:11 Jun 2020
    7.5
    High

    CVE-2020-0198

    Last Modified: 21 Nov 2024

    In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941

    Published:1 Jun 2020
    6.5
    Medium

    CVE-2020-0192

    Last Modified: 21 Nov 2024

    In ih264d_decode_slice_thread of ih264d_thread_parse_decode.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-144687080

    Published:11 Jun 2020
    7.8
    High

    CVE-2020-0188

    Last Modified: 21 Nov 2024

    In onCreatePermissionRequest of SettingsSliceProvider.java, there is a possible permissions bypass due to a PendingIntent error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147355897

    Published:11 Jun 2020
    7.8
    High

    CVE-2020-0183

    Last Modified: 21 Nov 2024

    In handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-110181479

    Published:11 Jun 2020
    7.5
    High

    CVE-2020-0181

    Last Modified: 21 Nov 2024

    In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145075076

    Published:1 Jun 2020
    6.5
    Medium

    CVE-2020-0162

    Last Modified: 21 Nov 2024

    In parseSampleAuxiliaryInformationOffsets of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124526959

    Published:11 Jun 2020
    8.8
    High

    CVE-2020-0160

    Last Modified: 21 Nov 2024

    In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-124771364

    Published:11 Jun 2020
    7.8
    High

    CVE-2020-0155

    Last Modified: 21 Nov 2024

    In phNxpNciHal_send_ese_hal_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-139736386

    Published:11 Jun 2020
    9.8
    Critical

    CVE-2020-0138

    Last Modified: 21 Nov 2024

    In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typical Android platforms, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-142878416

    Published:11 Jun 2020
    7.8
    High

    CVE-2020-0137

    Last Modified: 21 Nov 2024

    In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-141920289

    Published:11 Jun 2020
    7.8
    High

    CVE-2020-0136

    Last Modified: 21 Nov 2024

    In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-120078455

    Published:11 Jun 2020
    5.5
    Medium

    CVE-2020-0121

    Last Modified: 21 Nov 2024

    In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-148180766

    Published:10 Jun 2020
    7.8
    High

    CVE-2020-0114

    Last Modified: 21 Nov 2024

    In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-147606347

    Published:10 Jun 2020
    5.5
    Medium

    CVE-2020-0113

    Last Modified: 21 Nov 2024

    In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-9Android ID: A-150944913

    Published:10 Jun 2020
    7.8
    High

    CVE-2020-0108

    Last Modified: 21 Nov 2024

    In postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-8.1 Android-9Android ID: A-140108616

    Published:11 Aug 2020
    7.8
    High

    CVE-2020-0096

    Last Modified: 21 Nov 2024

    In startActivities of ActivityStartController.java, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9Android ID: A-145669109

    Published:14 May 2020
    7.8
    High

    CVE-2020-0082

    Last Modified: 21 Nov 2024

    In ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This could lead to local escalation of privilege to system_server with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-140417434

    Published:17 Apr 2020
    7.8
    High

    CVE-2020-0069

    Last Modified: 23 Oct 2025

    In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-147882143References: M-ALPS04356754

    Published:10 Mar 2020
    7.8
    High

    CVE-2020-0041

    Last Modified: 23 Oct 2025

    In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-145988638References: Upstream kernel

    Published:10 Mar 2020
    5.5
    Medium

    CVE-2020-0023

    Last Modified: 21 Nov 2024

    In setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing permission check. This could lead to local information disclosure if a malicious app enables contacts over a bluetooth connection, with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145130871

    Published:13 Feb 2020
    8.8
    High

    CVE-2020-0022

    Last Modified: 21 Nov 2024

    In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-143894715

    Published:13 Feb 2020
    5.5
    Medium

    CVE-2020-0014

    Last Modified: 21 Nov 2024

    It is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a local escalation of privilege with no additional execution privileges needed. User action is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-128674520

    Published:13 Feb 2020
    5.5
    Medium

    CVE-2020-0009

    Last Modified: 14 Jan 2020

    In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared between processes, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-142938932

    Source:Google Security Research
    Published:8 Jan 2020
    7.8
    High

    CVE-2020-0001

    Last Modified: 21 Nov 2024

    In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-140055304

    Published:8 Jan 2020
    6.1
    Medium

    CVE-2019-1020010

    Last Modified: 21 Nov 2024

    Misskey before 10.102.4 allows hijacking a user's token.

    Published:29 Jul 2019
    9.8
    Critical

    CVE-2019-1010298

    Last Modified: 5 Jun 2026

    Linaro/OP-TEE OP-TEE 3.3.0 and earlier is affected by: Buffer Overflow. The impact is: Code execution in the context of TEE core (kernel). The component is: optee_os. The fixed version is: 3.4.0 and later.

    Published:15 Jul 2019
    9.8
    Critical

    CVE-2019-1010268

    Last Modified: 21 Nov 2024

    Ladon since 0.6.1 (since ebef0aae48af78c159b6fce81bc6f5e7e0ddb059) is affected by: XML External Entity (XXE). The impact is: Information Disclosure, reading files and reaching internal network endpoints. The component is: SOAP request handlers. For instance: https://bitbucket.org/jakobsg/ladon/src/42944fc012a3a48214791c120ee5619434505067/src/ladon/interfaces/soap.py#lines-688. The attack vector is: Send a specially crafted SOAP call.

    Published:18 Jul 2019
    9.8
    Critical

    CVE-2019-1010174

    Last Modified: 21 Nov 2024

    CImg The CImg Library v.2.3.3 and earlier is affected by: command injection. The impact is: RCE. The component is: load_network() function. The attack vector is: Loading an image from a user-controllable url can lead to command injection, because no string sanitization is done on the url. The fixed version is: v.2.3.4.

    Published:25 Jul 2019
    5.4
    Medium

    CVE-2019-1010124

    Last Modified: 30 Aug 2019

    WebAppick WooCommerce Product Feed 2.2.18 and earlier is affected by: Cross Site Scripting (XSS). The impact is: XSS to RCE via editing theme files in WordPress. The component is: admin/partials/woo-feed-manage-list.php:63. The attack vector is: Administrator must be logged in.

    Source:Damian Ebelties
    Published:23 Jul 2019
    8.8
    High

    CVE-2019-1010054

    Last Modified: 21 Nov 2024

    Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.

    Published:18 Jul 2019
    9.9
    Critical

    CVE-2019-1003030

    Last Modified: 19 Oct 2020

    A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShell.java that allows attackers able to control pipeline scripts to execute arbitrary code on the Jenkins master JVM.

    Source:Daniel Morris
    Published:6 Mar 2019
    4.3
    Medium

    CVE-2019-1003010

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in Jenkins Git Plugin 3.9.1 and earlier in src/main/java/hudson/plugins/git/GitTagAction.java that allows attackers to create a Git tag in a workspace and attach corresponding metadata to a build record.

    Published:28 Jan 2019
    8.8
    High

    CVE-2019-1003002

    Last Modified: 28 Mar 2019

    A sandbox bypass vulnerability exists in Pipeline: Declarative Plugin 1.3.3 and earlier in pipeline-model-definition/src/main/groovy/org/jenkinsci/plugins/pipeline/modeldefinition/parser/Converter.groovy that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

    Source:Metasploit
    Published:8 Jan 2019
    8.8
    High

    CVE-2019-1003001

    Last Modified: 28 Mar 2019

    A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.61 and earlier in src/main/java/org/jenkinsci/plugins/workflow/cps/CpsFlowDefinition.java, src/main/java/org/jenkinsci/plugins/workflow/cps/CpsGroovyShellFactory.java that allows attackers with Overall/Read permission to provide a pipeline script to an HTTP endpoint that can result in arbitrary code execution on the Jenkins master JVM.

    Source:Metasploit
    Published:8 Jan 2019
    8.8
    High

    CVE-2019-1003000

    Last Modified: 28 Mar 2019

    A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/scriptsecurity/sandbox/groovy/GroovySandbox.java that allows attackers with the ability to provide sandboxed scripts to execute arbitrary code on the Jenkins master JVM.

    Source:Metasploit
    Published:8 Jan 2019
    6.4
    Medium

    CVE-2019-1002101

    Last Modified: 21 Nov 2024

    The kubectl cp command allows copying files between containers and the user machine. To copy files from a container, Kubernetes creates a tar inside the container, copies it over the network, and kubectl unpacks it on the user’s machine. If the tar binary in the container is malicious, it could run any code and output unexpected, malicious results. An attacker could use this to write files to any path on the user’s machine when kubectl cp is called, limited only by the system permissions of the local user. The untar function can both create and follow symbolic links. The issue is resolved in kubectl v1.11.9, v1.12.7, v1.13.5, and v1.14.0.

    Published:28 Mar 2019
    Unknown

    CVE-2019-89242

    https://www.exploit-db.com/exploits/49512

    Unknown

    CVE-2019-48814

    https://github.com/wucj001/cve-2019-48814

    6.9
    Medium

    CVE-2019-25485

    Last Modified: 15 Jul 2026

    R 3.4.4 on Windows x64 contains a buffer overflow vulnerability in the GUI Preferences language menu field that allows local attackers to bypass DEP and ASLR protections. Attackers can inject a crafted payload through the Language for menus preference to trigger a structured exception handler chain pivot and execute arbitrary shellcode with application privileges.

    Published:11 Mar 2026
    7.8
    High

    CVE-2019-25162

    Last Modified: 4 May 2025

    In the Linux kernel, the following vulnerability has been resolved: i2c: Fix a potential use after free Free the adap structure only after we are done using it. This patch just moves the put_device() down a bit to avoid the use after free. [wsa: added comment to the code, added Fixes tag]

    Published:26 Feb 2024
    7.2
    High

    CVE-2019-25137

    Last Modified: 22 Jan 2025

    Umbraco CMS 4.11.8 through 7.15.10, and 7.12.4, allows Remote Code Execution by authenticated administrators via msxsl:script in an xsltSelection to developer/Xslt/xsltVisualize.aspx.

    Published:18 May 2023
    6.3
    Medium

    CVE-2019-25065

    Last Modified: 15 Apr 2025

    A vulnerability was found in OpenNetAdmin 18.1.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to privilege escalation. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

    Published:9 Jun 2022
    6.1
    Medium

    CVE-2019-25046

    Last Modified: 14 Jun 2021

    The Web Client in Cerberus FTP Server Enterprise before 10.0.19 and 11.x before 11.0.4 allows XSS via an SVG document.

    Source:Mohammad Hossein Kaviyany
    Published:10 Jun 2021
    9.8
    Critical

    CVE-2019-25024

    Last Modified: 3 Dec 2025

    OpenRepeater (ORP) before 2.2 allows unauthenticated command injection via shell metacharacters in the functions/ajax_system.php post_service parameter.

    Source:CodeSecLab
    Published:19 Feb 2021
    9.8
    Critical

    CVE-2019-20933

    Last Modified: 21 Nov 2024

    InfluxDB before 1.7.6 has an authentication bypass vulnerability in the authenticate function in services/httpd/handler.go because a JWT token may have an empty SharedSecret (aka shared secret).

    Published:27 Mar 2019