2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-29484MEDIUM6An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watc...
CVE-2020-29483MEDIUM6.5An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specifi...
CVE-2020-29482MEDIUM6An issue was discovered in Xen through 4.14.x. A guest may access xenstore paths via absolute paths containing a full pa...
CVE-2020-29481HIGH8.8An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing gr...
CVE-2020-29480LOW2.3An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting...
CVE-2020-29479HIGH8.8An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the...
CVE-2020-27147MEDIUM6.5The REST API component of TIBCO Software Inc.'s TIBCO PartnerExpress contains a vulnerability that theoretically allows ...
CVE-2020-29571MEDIUM6.2An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO e...
CVE-2020-29570MEDIUM6.2An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and tha...
CVE-2020-29569HIGH8.8An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block b...
CVE-2020-29568MEDIUM6.5An issue was discovered in Xen through 4.14.x. Some OSes (such as Linux, FreeBSD, and NetBSD) are processing watch event...
CVE-2020-29567MEDIUM6.2An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors...
CVE-2020-29566MEDIUM5.5An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must b...
CVE-2020-27777MEDIUM6.7A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually...
CVE-2020-27068CRITICAL9.8Product: AndroidVersions: Android kernelAndroid ID: A-127973231References: Upstream kernel
CVE-2020-27067MEDIUM6.4In the l2tp subsystem, there is a possible use after free due to a race condition. This could lead to local escalation o...
CVE-2020-27066MEDIUM6.7In xfrm6_tunnel_free_spi of net/ipv6/xfrm6_tunnel.c, there is a possible use after free due to improper locking. This co...
CVE-2020-27057LOW3.3In getGpuStatsGlobalInfo and getGpuStatsAppInfo of GpuService.cpp, there is a possible permission bypass due to a missin...
CVE-2020-27056LOW3.3In SELinux policies of mls, there is a missing permission check. This could lead to local information disclosure of pack...
CVE-2020-27055HIGH7.5In isSubmittable and showWarningMessagesIfAppropriate of WifiConfigController.java and WifiConfigController2.java, there...
CVE-2020-27054HIGH7.8In onFactoryReset of BluetoothManagerService.java, there is a missing permission check. This could lead to local escalat...
CVE-2020-27053MEDIUM4.4In broadcastWifiCredentialChanged of ClientModeImpl.java, there is a possible location permission bypass due to a missin...
CVE-2020-27052HIGH7.8In getLockTaskLaunchMode of ActivityRecord.java, there is a possible way for any app to start in Lock Task Mode due to a...
CVE-2020-27051HIGH7.8In NFA_RwI93WriteMultipleBlocks of nfa_rw_api.cc, there is a possible out of bounds write due to an integer overflow. Th...
CVE-2020-27050HIGH7.8In rw_i93_send_cmd_write_multi_blocks of rw_i93.cc, there is a possible out of bounds write due to a heap buffer overflo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now