2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-28203MEDIUM5.5An issue was discovered in Foxit Reader and PhantomPDF 10.1.0.37527 and earlier. There is a null pointer access/derefere...
CVE-2020-28442CRITICAL9.8All versions of package js-data are vulnerable to Prototype Pollution via the deepFillIn function.
CVE-2020-35471HIGH7.5Envoy before 1.16.1 mishandles dropped and truncated datagrams, as demonstrated by a segmentation fault for a UDP packet...
CVE-2020-35470HIGH8.8Envoy before 1.16.1 logs an incorrect downstream address because it considers only the directly connected peer, not the ...
CVE-2020-35460MEDIUM5.3common/InputStreamHelper.java in Packwood MPXJ before 8.3.5 allows directory traversal in the zip stream handler flow, l...
CVE-2020-35457HIGH7.8GNOME GLib before 2.65.3 has an integer overflow, that might lead to an out-of-bounds write, in g_option_group_add_entri...
CVE-2020-0456CRITICAL9.8There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A...
CVE-2020-0019MEDIUM5.5In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local information disclosure i...
CVE-2020-0016HIGH7.8In the Broadcom Nexus firmware, there is an insecure default password. This could lead to local escalation of privilege ...
CVE-2020-0470MEDIUM5.5In extend_frame_highbd of restoration.c, there is a possible out of bounds write due to a heap buffer overflow. This cou...
CVE-2020-0469MEDIUM5.5In addEscrowToken of LockSettingsService.java, there is a possible loss of the synthetic password due to logic error. Th...
CVE-2020-0468MEDIUM5.5In listen() and related functions of TelephonyRegistry.java, there is a possible permissions bypass of location permissi...
CVE-2020-0467MEDIUM5.5In onUserStopped of Vpn.java, there is a possible resetting of user preferences due to a logic issue. This could lead to...
CVE-2020-0466HIGH7.8In do_epoll_ctl and ep_loop_check_proc of eventpoll.c, there is a possible use after free due to a logic error. This cou...
CVE-2020-0465MEDIUM6.8In various methods of hid-multitouch.c, there is a possible out of bounds write due to a missing bounds check. This coul...
CVE-2020-0464MEDIUM5.5In resolv_cache_lookup of res_cache.cpp, there is a possible side channel information disclosure. This could lead to loc...
CVE-2020-0463HIGH7.5In sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. ...
CVE-2020-0460HIGH7.5In createNameCredentialDialog of CertInstaller.java, there exists the possibility of improperly installed certificates d...
CVE-2020-0459LOW3.3In sendConfiguredNetworkChangedBroadcast of WifiConfigManager.java, there is a possible leak of sensitive WiFi configura...
CVE-2020-0458HIGH7.8In SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible out of bounds write ...
CVE-2020-0457CRITICAL9.8There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A...
CVE-2020-0455CRITICAL9.8There is a possible out of bounds write due to a missing bounds check.Product: AndroidVersions: Android SoCAndroid ID: A...
CVE-2020-0444HIGH7.8In audit_free_lsm_field of auditfilter.c, there is a possible bad kfree due to a logic error in audit_data_to_entry. Thi...
CVE-2020-0440HIGH7.8In createVirtualDisplay of DisplayManagerService.java, there is a possible way to create a trusted virtual display due t...
CVE-2020-0099HIGH7.8In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. T...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now