2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-0104MEDIUM5.5In onShowingStateChanged of KeyguardStateMonitor.java, there is a possible inappropriate read due to a logic error. This...
CVE-2020-0103CRITICAL9.8In a2dp_aac_decoder_cleanup of a2dp_aac_decoder.cc, there is a possible invalid free due to memory corruption. This coul...
CVE-2020-0102HIGH7.8In GattServer::SendResponse of gatt_server.cc, there is a possible out of bounds write due to an incorrect bounds check....
CVE-2020-0101MEDIUM5.5In BnCrypto::onTransact of ICrypto.cpp, there is a possible information disclosure due to uninitialized data. This could...
CVE-2020-0100MEDIUM5.5In onTransact of IHDCP.cpp, there is a possible out of bounds read due to incorrect error handling. This could lead to l...
CVE-2020-0098HIGH7.8In navigateUpToLocked of ActivityStack.java, there is a possible permission bypass due to a confused deputy. This could ...
CVE-2020-0097HIGH7.8In various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for s...
CVE-2020-0096HIGH7.8In startActivities of ActivityStartController.java, there is a possible escalation of privilege due to a confused deputy...
CVE-2020-0094HIGH7.8In setImageHeight and setImageWidth of ExifUtils.cpp, there is a possible out of bounds write due to an incorrect bounds...
CVE-2020-0093MEDIUM5In exif_data_save_data_entry of exif-data.c, there is a possible out of bounds read due to a missing bounds check. This ...
CVE-2020-0092MEDIUM5In setHideSensitive of NotificationStackScrollLayout.java, there is a possible disclosure of sensitive notification cont...
CVE-2020-0091MEDIUM5.5In mnld, an incorrect configuration in driver_cfg of mnld for meta factory mode.Product: AndroidVersions: Android SoCAnd...
CVE-2020-0090MEDIUM5.5An improper authorization in the receiver component of Email.Product: AndroidVersions: Android SoCAndroid ID: A-14981304...
CVE-2020-0065MEDIUM5.5An improper authorization in the receiver component of the Android Suite Daemon.Product: AndroidVersions: Android SoCAnd...
CVE-2020-0064MEDIUM5.5An improper authorization while processing the provisioning data.Product: AndroidVersions: Android SoCAndroid ID: A-1498...
CVE-2020-0024HIGH7.8In onCreate of SettingsBaseActivity.java, there is a possible unauthorized setting modification due to a permissions byp...
CVE-2020-12877HIGH7.5Veritas APTARE versions prior to 10.4 allowed sensitive information to be accessible without authentication.
CVE-2020-12876HIGH7.5Veritas APTARE versions prior to 10.4 allowed remote users to access several unintended files on the server. This vulner...
CVE-2020-12875MEDIUM6.3Veritas APTARE versions prior to 10.4 did not perform adequate authorization checks. An authenticated user could gain un...
CVE-2020-12874CRITICAL9.8Veritas APTARE versions prior to 10.4 included code that bypassed the normal login process when specific authentication ...
CVE-2020-5408MEDIUM6.5Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4....
CVE-2020-12677MEDIUM6.1An issue was discovered in Progress MOVEit Automation Web Admin. A Web Admin application endpoint failed to adequately s...
CVE-2020-1960MEDIUM4.7A vulnerability in Apache Flink (1.1.0 to 1.1.5, 1.2.0 to 1.2.1, 1.3.0 to 1.3.3, 1.4.0 to 1.4.2, 1.5.0 to 1.5.6, 1.6.0 t...
CVE-2020-1941MEDIUM6.1In Apache ActiveMQ 5.0.0 to 5.15.11, the webconsole admin GUI is open to XSS, in the view that lists the contents of a q...
CVE-2020-11973CRITICAL9.8Apache Camel Netty enables Java deserialization by default. Apache Camel 2.22.x, 2.23.x, 2.24.x, 2.25.0, 3.0.0 up to 3.1...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now