2020 CVE Vulnerabilities

21,070 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-25112CRITICAL9.8An issue was discovered in the IPv6 stack in Contiki through 3.0. There are inconsistent checks for IPv6 header extensio...
CVE-2020-25111CRITICAL9.8An issue was discovered in the IPv6 stack in Contiki through 3.0. There is an insufficient check for the IPv6 header len...
CVE-2020-25110CRITICAL9.8An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The length byte of a domain name in a DNS q...
CVE-2020-25109CRITICAL9.8An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The number of DNS queries/responses (set in...
CVE-2020-25108CRITICAL9.8An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. The DNS response data length is not checked...
CVE-2020-25107CRITICAL9.8An issue was discovered in the DNS implementation in Ethernut in Nut/OS 5.1. There is no check on whether a domain name ...
CVE-2020-24383CRITICAL9.1An issue was discovered in FNET through 4.6.4. The code for processing resource records in mDNS queries doesn't check fo...
CVE-2020-24341CRITICAL9.1An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The TCP input data processing function in pico_tcp.c do...
CVE-2020-24340HIGH7.5An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The code that processes DNS responses in pico_mdns_hand...
CVE-2020-24339HIGH7.5An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. The DNS domain name record decompression functionality ...
CVE-2020-24338CRITICAL9.8An issue was discovered in picoTCP through 1.7.0. The DNS domain name record decompression functionality in pico_dns_dec...
CVE-2020-24337HIGH7.5An issue was discovered in picoTCP and picoTCP-NG through 1.7.0. When an unsupported TCP option with zero length is prov...
CVE-2020-24336CRITICAL9.8An issue was discovered in Contiki through 3.0 and Contiki-NG through 4.5. The code for parsing Type A domain name answe...
CVE-2020-24334HIGH8.2The code that processes DNS responses in uIP through 1.0, as used in Contiki and Contiki-NG, does not check whether the ...
CVE-2020-17470MEDIUM5.3An issue was discovered in FNET through 4.6.4. The code that initializes the DNS client interface structure does not set...
CVE-2020-17469HIGH7.5An issue was discovered in FNET through 4.6.4. The code for IPv6 fragment reassembly tries to access a previous fragment...
CVE-2020-17468HIGH7.5An issue was discovered in FNET through 4.6.4. The code for processing the hop-by-hop header (in the IPv6 extension head...
CVE-2020-17467CRITICAL9.1An issue was discovered in FNET through 4.6.4. The code for processing the hostname from an LLMNR request doesn't check ...
CVE-2020-17445HIGH7.5An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 destination options does not check for a vali...
CVE-2020-17444HIGH7.5An issue was discovered in picoTCP 1.7.0. The routine for processing the next header field (and deducing whether the IPv...
CVE-2020-17443HIGH7.5An issue was discovered in picoTCP 1.7.0. The code for creating an ICMPv6 echo replies doesn't check whether the ICMPv6 ...
CVE-2020-17442HIGH7.5An issue was discovered in picoTCP 1.7.0. The code for parsing the hop-by-hop IPv6 extension headers does not validate t...
CVE-2020-17441CRITICAL9.1An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 pa...
CVE-2020-17440HIGH7.5An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets...
CVE-2020-17439HIGH8.3An issue was discovered in uIP 1.0, as used in Contiki 3.0 and other products. The code that parses incoming DNS packets...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now