2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-11256HIGH8.8Memory corruption due to lack of check of validation of pointer to buffer passed to trustzone in Snapdragon Wired Infras...
CVE-2020-11250HIGH7Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute,...
CVE-2020-11241HIGH7.5Out of bound read will happen if EAPOL Key length is less than expected while processing NAN shared key descriptor attri...
CVE-2020-11240HIGH7.8Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is alloc...
CVE-2020-11239HIGH7.8Use after free issue when importing a DMA buffer by using the CPU address of the buffer due to attachment is not cleaned...
CVE-2020-11238HIGH7.5Possible Buffer over-read in ARP/NS parsing due to lack of check of packet length received in Snapdragon Auto, Snapdrago...
CVE-2020-11235HIGH7.8Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto...
CVE-2020-11233HIGH7Time-of-check time-of-use race condition While processing partition entries due to newly created buffer was read again f...
CVE-2020-11182CRITICAL9.8Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon ...
CVE-2020-11178HIGH7.8Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with...
CVE-2020-11165HIGH7.8Memory corruption due to buffer overflow while copying the message provided by HLOS into buffer without validating the l...
CVE-2020-11161HIGH7.1Out-of-bounds memory access can occur while calculating alignment requirements for a negative width from external compon...
CVE-2020-11160MEDIUM6.7Resource leakage issue during dci client registration due to reference count is not decremented if dci client registrati...
CVE-2020-11159CRITICAL9.1Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length o...
CVE-2020-11134CRITICAL9.8Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like ...
CVE-2020-11126CRITICAL9.1Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, ...
CVE-2020-26136MEDIUM6.5In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authenticat...
CVE-2020-28713MEDIUM6.5Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote user...
CVE-2020-26138MEDIUM5.3In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation.
CVE-2020-25817MEDIUM4.8SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML ...
CVE-2020-26517MEDIUM4.8A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to per...
CVE-2020-26516HIGH8.8A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger ac...
CVE-2020-26515HIGH7.5An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The rememb...
CVE-2020-25716HIGH8.1A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is...
CVE-2020-1750MEDIUM6.5A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container co...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now