2020 CVE Vulnerabilities
21,069 CVEs published in 2020.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2020-24175 | HIGH | 7.8 | 1.8% | Feb 22, 2021 | Buffer overflow in Yz1 0.30 and 0.32, as used in IZArc 4.4, ZipGenius 6.3.2.3116, and Explzh (extension) 8.14, allows at... |
| CVE-2020-11297 | HIGH | 7.5 | 0.6% | Feb 22, 2021 | Denial of service in WLAN module due to improper check of subtypes in logic where excessive frames are dropped in Snapdr... |
| CVE-2020-11296 | HIGH | 7.5 | 0.6% | Feb 22, 2021 | Arithmetic overflow can happen while processing NOA IE due to improper error handling in Snapdragon Auto, Snapdragon Com... |
| CVE-2020-11287 | HIGH | 7.5 | 0.7% | Feb 22, 2021 | Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to informati... |
| CVE-2020-11282 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Improper access control when using mmap with the kgsl driver with a special offset value that can be provided to map the... |
| CVE-2020-11281 | HIGH | 7.5 | 0.7% | Feb 22, 2021 | Allowing RTT frames to be linked with non randomized MAC address by comparing the sequence numbers can lead to informati... |
| CVE-2020-11280 | HIGH | 7.5 | 0.6% | Feb 22, 2021 | Denial of service while processing fine timing measurement request (FTMR) frame with reserved bits set in the FTM parame... |
| CVE-2020-11278 | HIGH | 7.5 | 0.6% | Feb 22, 2021 | Possible denial of service while handling host WMI command due to improper validation in Snapdragon Auto, Snapdragon Com... |
| CVE-2020-11277 | HIGH | 7.4 | 0.1% | Feb 22, 2021 | Possible race condition during async fastrpc session after sending RPC message due to the fastrpc ctx gets free during a... |
| CVE-2020-11271 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Possible out of bounds while accessing global control elements due to race condition in Snapdragon Auto, Snapdragon Comp... |
| CVE-2020-11270 | HIGH | 7.5 | 0.6% | Feb 22, 2021 | Possible denial of service due to RTT responder consistently rejects all FTMR by transmitting FTM1 with failure status i... |
| CVE-2020-11269 | HIGH | 8.8 | 0.3% | Feb 22, 2021 | Possible memory corruption while processing EAPOL frames due to lack of validation of key length before using it in Snap... |
| CVE-2020-11253 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Arbitrary memory write issue in video driver while setting the internal buffers in Snapdragon Auto, Snapdragon Compute, ... |
| CVE-2020-11223 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Out of bound in camera driver due to lack of check of validation of array index before copying into array in Snapdragon ... |
| CVE-2020-11204 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Possible memory corruption and information leakage in sub-system due to lack of check for validity and boundary complian... |
| CVE-2020-11203 | HIGH | 7.1 | 0.1% | Feb 22, 2021 | Stack overflow may occur if GSM/WCDMA broadcast config size received from user is larger than variable length array in S... |
| CVE-2020-11195 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Out of bound write and read in TA while processing command from NS side due to improper length check on command and resp... |
| CVE-2020-11194 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Possible out of bound access in TA while processing a command from NS side due to improper length check of response buff... |
| CVE-2020-11187 | HIGH | 7.8 | 0.2% | Feb 22, 2021 | Possible memory corruption in BSI module due to improper validation of parameter count in Snapdragon Auto, Snapdragon Co... |
| CVE-2020-11177 | HIGH | 8.8 | 0.2% | Feb 22, 2021 | User can overwrite Security Code NV item without knowing current SPC due to improper validation of SPC code setting and ... |
| CVE-2020-35681 | HIGH | 7.4 | 2.7% | Feb 22, 2021 | Django Channels 3.x before 3.0.3 allows remote attackers to obtain sensitive information from a different request scope.... |
| CVE-2020-35556 | HIGH | 7.5 | 1.0% | Feb 22, 2021 | An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service ... |
| CVE-2020-28248 | HIGH | 8.8 | 2.2% | Feb 20, 2021 | An integer overflow in the PngImg::InitStorage_() function of png-img before 3.1.0 leads to an under-allocation of heap ... |
| CVE-2020-27997 | HIGH | 8.8 | 0.8% | Feb 19, 2021 | An issue was discovered in SmartStoreNET before 4.1.0. Lack of Cross Site Request Forgery (CSRF) protection may lead to ... |
| CVE-2020-24617 | HIGH | 8.8 | 1.5% | Feb 19, 2021 | Mailtrain through 1.24.1 allows SQL Injection in statsClickedSubscribersByColumn in lib/models/campaigns.js via /campaig... |
Check if your code is affected by 2020 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now