2020 CVE Vulnerabilities

21,075 CVEs published in 2020.

CVE IDSeverityCVSSDescription
CVE-2020-10372MEDIUM5.4Ramp AltitudeCDN Altimeter before 2.4.0 allows authenticated Stored XSS via the vdms/ipmapping.jsp location field to the...
CVE-2020-0087MEDIUM5.5In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lea...
CVE-2020-0085HIGH7.8In setBluetoothTethering of PanService.java, there is a possible permission bypass due to a missing permission check. Th...
CVE-2020-0084HIGH7.8In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local e...
CVE-2020-0066MEDIUM6.4In the netlink driver, there is a possible out of bounds write due to a race condition. This could lead to local escalat...
CVE-2020-0063HIGH7.3In SurfaceFlinger, it is possible to override UI confirmation screen protected by the TEE. This could lead to local esca...
CVE-2020-0062HIGH7.5In Euicc, there is a possible information disclosure due to an included test Certificate. This could lead to remote info...
CVE-2020-0057MEDIUM5.5In btm_process_inq_results of btm_inq.cc, there is a possible out of bounds read due to a missing bounds check. This cou...
CVE-2020-0056MEDIUM5.5In btu_hcif_connection_comp_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. Th...
CVE-2020-0055MEDIUM5.5In l2c_link_process_num_completed_pkts of l2c_link.cc, there is a possible out of bounds read due to a missing bounds ch...
CVE-2020-0054HIGH7.8In WifiNetworkSuggestionsManager of WifiNetworkSuggestionsManager.java, there is a possible permission revocation due to...
CVE-2020-0053MEDIUM6.7In convertHidlNanDataPathInitiatorRequestToLegacy, and convertHidlNanDataPathIndicationResponseToLegacy of hidl_struct_u...
CVE-2020-0052MEDIUM4.3In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. T...
CVE-2020-0051HIGH7.8In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of p...
CVE-2020-0050MEDIUM6.7In nfa_hciu_send_msg of nfa_hci_utils.cc, there is a possible out of bounds write due to improper input validation. This...
CVE-2020-0049MEDIUM6.5In onReadBuffer() of StreamingSource.cpp, there is a possible information disclosure due to uninitialized data. This cou...
CVE-2020-0048MEDIUM5.5In onTransact of IAudioFlinger.cpp, there is a possible stack information leak due to uninitialized data. This could lea...
CVE-2020-0047LOW3.3In setMasterMute of AudioService.java, there is a missing permission check. This could lead to local silencing of audio ...
CVE-2020-0046HIGH7.8In DrmPlugin::releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow...
CVE-2020-0045MEDIUM6.4In StatsService::command of StatsService.cpp, there is possible memory corruption due to a race condition. This could le...
CVE-2020-9044CRITICAL9.1XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks...
CVE-2020-7579MEDIUM6.1A vulnerability has been identified in Spectrum Power™ 5 (All versions < v5.50 HF02). The web server could allow Cross-S...
CVE-2020-0083HIGH7.5In setRequirePmfInternal of sta_network.cpp, there is a possible default value being improperly applied due to a logic e...
CVE-2020-0069HIGH7.8In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient ...
CVE-2020-0061MEDIUM5.5In Pixel Recorder, there is a possible permissions bypass allowing arbitrary apps to record audio. This could lead to lo...

Check if your code is affected by 2020 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now