2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-11256 | HIGH | 8.8 | 0.2% | Jun 9, 2021 | Memory corruption due to lack of check of validation of pointer to buffer passed to trustzone in Snapdragon Wired Infras... |
| CVE-2020-11250 | HIGH | 7 | 0.1% | Jun 9, 2021 | Use after free due to race condition when reopening the device driver repeatedly in Snapdragon Auto, Snapdragon Compute,... |
| CVE-2020-11241 | HIGH | 7.5 | 0.6% | Jun 9, 2021 | Out of bound read will happen if EAPOL Key length is less than expected while processing NAN shared key descriptor attri... |
| CVE-2020-11240 | HIGH | 7.8 | 0.2% | Jun 9, 2021 | Memory corruption due to ioctl command size was incorrectly set to the size of a pointer and not enough storage is alloc... |
| CVE-2020-11239 | HIGH | 7.8 | 0.2% | Jun 9, 2021 | Use after free issue when importing a DMA buffer by using the CPU address of the buffer due to attachment is not cleaned... |
| CVE-2020-11238 | HIGH | 7.5 | 0.6% | Jun 9, 2021 | Possible Buffer over-read in ARP/NS parsing due to lack of check of packet length received in Snapdragon Auto, Snapdrago... |
| CVE-2020-11235 | HIGH | 7.8 | 0.2% | Jun 9, 2021 | Buffer overflow might occur while parsing unified command due to lack of check of input data received in Snapdragon Auto... |
| CVE-2020-11233 | HIGH | 7 | 0.1% | Jun 9, 2021 | Time-of-check time-of-use race condition While processing partition entries due to newly created buffer was read again f... |
| CVE-2020-11182 | CRITICAL | 9.8 | 0.8% | Jun 9, 2021 | Possible heap overflow while parsing NAL header due to lack of check of length of data received from user in Snapdragon ... |
| CVE-2020-11178 | HIGH | 7.8 | 0.2% | Jun 9, 2021 | Trusted APPS to overwrite the CPZ memory of another use-case as TZ only checks the physical address not overlapping with... |
| CVE-2020-11165 | HIGH | 7.8 | 0.2% | Jun 9, 2021 | Memory corruption due to buffer overflow while copying the message provided by HLOS into buffer without validating the l... |
| CVE-2020-11161 | HIGH | 7.1 | 0.1% | Jun 9, 2021 | Out-of-bounds memory access can occur while calculating alignment requirements for a negative width from external compon... |
| CVE-2020-11160 | MEDIUM | 6.7 | 0.1% | Jun 9, 2021 | Resource leakage issue during dci client registration due to reference count is not decremented if dci client registrati... |
| CVE-2020-11159 | CRITICAL | 9.1 | 0.8% | Jun 9, 2021 | Buffer over-read can happen while processing WPA,RSN IE of beacon and response frames if IE length is less than length o... |
| CVE-2020-11134 | CRITICAL | 9.8 | 0.8% | Jun 9, 2021 | Possible stack out of bound write might happen due to time bitmap length and bit duration fields of the attributes like ... |
| CVE-2020-11126 | CRITICAL | 9.1 | 0.8% | Jun 9, 2021 | Possible out of bound read while WLAN frame parsing due to lack of check for body and header length in Snapdragon Auto, ... |
| CVE-2020-26136 | MEDIUM | 6.5 | 1.2% | Jun 8, 2021 | In SilverStripe through 4.6.0-rc1, GraphQL doesn't honour MFA (multi-factor authentication) when using basic authenticat... |
| CVE-2020-28713 | MEDIUM | 6.5 | 1.4% | Jun 8, 2021 | Incorrect access control in push notification service in Night Owl Smart Doorbell FW version 20190505 allows remote user... |
| CVE-2020-26138 | MEDIUM | 5.3 | 1.3% | Jun 8, 2021 | In SilverStripe through 4.6.0-rc1, a FormField with square brackets in the field name skips validation. |
| CVE-2020-25817 | MEDIUM | 4.8 | 0.8% | Jun 8, 2021 | SilverStripe through 4.6.0-rc1 has an XXE Vulnerability in CSSContentParser. A developer utility meant for parsing HTML ... |
| CVE-2020-26517 | MEDIUM | 4.8 | 0.5% | Jun 8, 2021 | A cross-site scripting (XSS) issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. It is possible to per... |
| CVE-2020-26516 | HIGH | 8.8 | 0.8% | Jun 8, 2021 | A CSRF issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. Requests sent to the server that trigger ac... |
| CVE-2020-26515 | HIGH | 7.5 | 0.5% | Jun 8, 2021 | An insufficiently protected credentials issue was discovered in Intland codeBeamer ALM 10.x through 10.1.SP4. The rememb... |
| CVE-2020-25716 | HIGH | 8.1 | 0.8% | Jun 7, 2021 | A flaw was found in Cloudforms. A role-based privileges escalation flaw where export or import of administrator files is... |
| CVE-2020-1750 | MEDIUM | 6.5 | 0.9% | Jun 7, 2021 | A flaw was found in the machine-config-operator that causes an OpenShift node to become unresponsive when a container co... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now