Skip to main content

Year archive

CVEs published in 2020

Archive summary

18,322 CVEs published in 2020 — 2,625 Critical, 7,666 High, 7,546 Medium, 485 Low, 0 Unrated.

CVE-2020-0007

Published Jan 8, 2020

In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no addit…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0006

Published Jan 8, 2020

In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to remote information disc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0004

Published Jan 8, 2020

In generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceeding maximum texture size. This could lead to local denial of service with no ad…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0003

Published Jan 8, 2020

In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-0002

Published Jan 8, 2020

In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution priv…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2020-0001

Published Jan 8, 2020

In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of privilege with no additional execution pri…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6585

Published Jan 8, 2020

A Denial of Service vulnerability exists in Symantec Norton Mobile Security for Android prior to 3.16, which could let a remote malicious user conduct a man-in-the-middle attack v…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-5511

Published Jan 8, 2020

PHPGurukul Small CRM v2.0 was found vulnerable to authentication bypass via SQL injection when logging into the administrator login page.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-5183

Published Jan 8, 2020

FTPGetter Professional 5.97.0.223 is vulnerable to a memory corruption bug when a user sends a specially crafted string to the application. This memory corruption bug can possibly…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2016-6587

Published Jan 8, 2020

An Information Disclosure vulnerability exists in the mid.dat file stored on the SD card in Symantec Norton Mobile Security for Android before 3.16, which could let a local malici…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20366

Published Jan 8, 2020

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via isTrustStore to Manage Store Contents.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-20365

Published Jan 8, 2020

An XSS issue was discovered in Ignite Realtime Openfire 4.4.4 via search to the Users/Group search page.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-19544

Published Jan 8, 2020

CA Automic Dollar Universe 5.3.3 contains a vulnerability, related to the uxdqmsrv binary being setuid root, that allows local attackers to elevate privileges. This vulnerability…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-10777

Published Jan 8, 2020

In aws-lambda versions prior to version 1.0.5, the "config.FunctioName" is used to construct the argument used within the "exec" function without any sanitization. It is possible…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2016-6588

Published Jan 8, 2020

A Cross-Site Scripting (XSS) vulnerability exists in the ITMS workflow process manager console in Symantec IT Management Suite 8.0.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-6586

Published Jan 8, 2020

A security bypass vulnerability exists in Symantec Norton Mobile Security for Android before 3.16, which could let a malicious user conduct a man-in-the-middle via specially craft…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2020-0009

Published Jan 8, 2020

In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 18,051-18,075 of 18,322 CVEsPage 723 of 733