2020 CVE Vulnerabilities
21,071 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-3684 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'QSEE reads the access permission policy for the SMEM TOC partition from the SMEM TOC contents populated by XBL Loader ... |
| CVE-2020-3678 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'A buffer overflow could occur if the API is improperly used due to UIE init does not contain a buffer size a param' in... |
| CVE-2020-3673 | CRITICAL | 9.8 | 1.0% | Nov 2, 2020 | u'Buffer overflow can happen as part of SIP message packet processing while storing values in array due to lack of check... |
| CVE-2020-3670 | CRITICAL | 9.1 | 0.9% | Nov 2, 2020 | u'Potential out of bounds read while processing downlink NAS transport message due to improper length check of Informati... |
| CVE-2020-3657 | CRITICAL | 9.8 | 28.3% | Nov 2, 2020 | u'Remote code execution can happen by sending a carefully crafted POST query when Device configuration is accessed from ... |
| CVE-2020-3654 | CRITICAL | 9.8 | 0.9% | Nov 2, 2020 | u'Buffer overflow occurs while processing SIP message packet due to lack of check of index validation before copying int... |
| CVE-2020-3638 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'An Unaligned address or size can propagate to the database due to improper page permissions and can lead to improper a... |
| CVE-2020-11174 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'Array index underflow issue in adsp driver due to improper check of channel id before used as array index.' in Snapdra... |
| CVE-2020-11173 | HIGH | 7 | 0.1% | Nov 2, 2020 | u'Two threads running simultaneously from user space can lead to race condition in fastRPC driver' in Snapdragon Auto, S... |
| CVE-2020-11172 | CRITICAL | 9.8 | 0.7% | Nov 2, 2020 | u'fscanf reads a string from a file and stores its contents on a statically allocated stack memory which leads to stack ... |
| CVE-2020-11169 | CRITICAL | 9.1 | 0.8% | Nov 2, 2020 | u'Buffer over-read while processing received L2CAP packet due to lack of integer overflow check' in Snapdragon Auto, Sna... |
| CVE-2020-11164 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'Third-party app may also call the broadcasts in Perfdump and cause privilege escalation issue due to improper access c... |
| CVE-2020-11162 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'Possible buffer overflow in MHI driver due to lack of input parameter validation of EOT events received from MHI devic... |
| CVE-2020-11157 | HIGH | 7.5 | 0.4% | Nov 2, 2020 | u'Lack of handling unexpected control messages while encryption was in progress can terminate the connection and thus le... |
| CVE-2020-11156 | HIGH | 8.1 | 0.4% | Nov 2, 2020 | u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap packet received from peer ... |
| CVE-2020-11155 | HIGH | 8.8 | 0.5% | Nov 2, 2020 | u'Buffer overflow while processing PDU packet in bluetooth due to lack of check of buffer length before copying into it.... |
| CVE-2020-11154 | HIGH | 8.8 | 0.5% | Nov 2, 2020 | u'Buffer overflow while processing a crafted PDU data packet in bluetooth due to lack of check of buffer size before cop... |
| CVE-2020-11153 | CRITICAL | 9.8 | 2.2% | Nov 2, 2020 | u'Out of bound memory access while processing GATT data received due to lack of check of pdu data length and leads to re... |
| CVE-2020-11141 | HIGH | 8.1 | 0.3% | Nov 2, 2020 | u'Buffer over-read issue in Bluetooth estack due to lack of check for invalid length of L2cap configuration request rece... |
| CVE-2020-11125 | HIGH | 7.8 | 0.2% | Nov 2, 2020 | u'Out of bound access can happen in MHI command process due to lack of check of channel id value received from MHI devic... |
| CVE-2020-11114 | HIGH | 8.8 | 0.4% | Nov 2, 2020 | u'Bluetooth devices does not properly restrict the L2CAP payload length allowing users in radio range to cause a buffer ... |
| CVE-2020-25849 | HIGH | 8.8 | 2.2% | Nov 1, 2020 | MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands... |
| CVE-2020-5425 | HIGH | 7.9 | 0.7% | Oct 31, 2020 | Single Sign-On for Vmware Tanzu all versions prior to 1.11.3 ,1.12.x versions prior to 1.12.4 and 1.13.x prior to 1.13.1... |
| CVE-2020-15703 | LOW | 3.3 | 0.5% | Oct 31, 2020 | There is no input validation on the Locale property in an apt transaction. An unprivileged user can supply a full path t... |
| CVE-2020-5991 | HIGH | 7.8 | 0.5% | Oct 30, 2020 | NVIDIA CUDA Toolkit, all versions prior to 11.1.1, contains a vulnerability in the NVJPEG library in which an out-of-bou... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now