2020 CVE Vulnerabilities

21,069 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-21224CRITICAL9.8A Remote Code Execution vulnerability has been found in Inspur ClusterEngine V4.0. A remote attacker can send a maliciou...
CVE-2020-19762MEDIUM6.1Automated Logic Corporation (ALC) WebCTRL System 6.5 and prior allows remote attackers to execute any JavaScript code vi...
CVE-2020-3664MEDIUM6Out of bound read access in hypervisor due to an invalid read access attempt by passing invalid addresses in Snapdragon ...
CVE-2020-11297HIGH7.5Denial of service in WLAN module due to improper check of subtypes in logic where excessive frames are dropped in Snapdr...
CVE-2020-11296HIGH7.5Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Com...
CVE-2020-11287HIGH7.5Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to informati...
CVE-2020-11286MEDIUM6.8An Untrusted Pointer Dereference can occur while doing USB control transfers, if multiple requests of different standard...
CVE-2020-11283CRITICAL9.8A buffer overflow can occur when playing an MKV clip due to lack of input validation in Snapdragon Auto, Snapdragon Comp...
CVE-2020-11282HIGH7.8Improper access control when using mmap with the kgsl driver with a special offset value that can be provided to map the...
CVE-2020-11281HIGH7.5Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to informati...
CVE-2020-11280HIGH7.5Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parame...
CVE-2020-11278HIGH7.5Possible denial of service while handling host WMI command due to improper validation in Snapdragon Auto, Snapdragon Com...
CVE-2020-11277HIGH7.4Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during a...
CVE-2020-11276CRITICAL9.1Possible buffer over read while processing P2P IE and NOA attribute of beacon and probe response frames due to improper ...
CVE-2020-11275CRITICAL9.1Possible buffer over-read while parsing quiet IE in Rx beacon frame due to improper check of IE length in received beaco...
CVE-2020-11272CRITICAL9.8Before enqueuing a frame to the PE queue for further processing, an entry in a hash table can be deleted and using a sta...
CVE-2020-11271HIGH7.8Possible out of bounds while accessing global control elements due to race condition in Snapdragon Auto, Snapdragon Comp...
CVE-2020-11270HIGH7.5Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status i...
CVE-2020-11269HIGH8.8Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snap...
CVE-2020-11253HIGH7.8Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, ...
CVE-2020-11223HIGH7.8Out of bound in camera driver due to lack of check of validation of array index before copying into array in Snapdragon ...
CVE-2020-11204HIGH7.8Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary complian...
CVE-2020-11203HIGH7.1Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in S...
CVE-2020-11198MEDIUM6.7Key material used for TZ diag buffer encryption and other data related to log buffer is not wiped securely due to improp...
CVE-2020-11195HIGH7.8Out of bound write and read in TA while processing command from NS side due to improper length check on command and resp...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now