Date published: 2020-01-21
Date published: 2020-01-21 (Medium)
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 10 are already weaponised in the wild.
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Date published: 2020-01-21 (Medium)
GCP-COMPUTE-20200121 (Medium)
CVEs:CVE-2020-0601
A spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, ...
CVEs:CVE-2020-0601
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| go | affected | golang | — | — |
| windows_10_1507 | affected | microsoft | — | — |
| windows_10_1607 | affected | microsoft | — | — |
| windows_10_1709 | affected | microsoft | — | — |
| windows_10_1803 | affected | microsoft | — | — |
| windows_10_1809 | affected | microsoft | — | — |
| windows_10_1903 | affected | microsoft | — | — |
| windows_10_1909 | affected | microsoft | — | — |
| windows_server_1803 | affected | microsoft | — | — |
| windows_server_1903 | affected | microsoft | — | — |
| windows_server_1909 | affected | microsoft | — | — |
| windows_server_2016 | affected | microsoft | — | — |
| windows_server_2019 | affected | microsoft | — | — |
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-...
CVEs:CVE-2020-0674
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| internet_explorer | affected | microsoft | — | — |
CVEs:CVE-2020-0674
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka 'Scripting Engine Memory Corruption Vulnerability'. This CVE ID is unique from CVE-2020-0673, CVE-2020-0710, CVE-2020-0711, CVE-2020-0712, CVE-2020-0713, CVE-2020-0767.
CVEs:CVE-2020-0674
CVEs:CVE-2019-17026
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and ...
CVEs:CVE-2019-17026
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| firefox | affected | mozilla | — | — |
| thunderbird | affected | mozilla | — | — |
| ubuntu_linux | affected | canonical | — | — |
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68.4.1, Thunderbird < 68.4.1, and Firefox < 72.0.1.
CVEs:CVE-2019-17026
CVEs:CVE-2020-0009
In calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to local escalation of privilege by corrupting memory shared between processes, with no additional execution privileges ...
CVEs:CVE-2020-0009
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — | |
| debian_linux | affected | debian | — | — |
CVEs:CVE-2013-6792
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
CVEs:CVE-2013-6792
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
chromium - security update
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:10 | chromium | — |
Security update for chromium, re2
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP1 | chromium | — |
| re2 | affected | SUSE:Package Hub 15 SP1 | re2 | — |
DEBIAN-CVE-2019-14863
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular.js | affected | Debian:11 | angular.js | — |
| angular.js | affected | Debian:12 | angular.js | — |
| angular.js | affected | Debian:13 | angular.js | — |
| angular.js | affected | Debian:14 | angular.js | — |
AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes
CVEs:CVE-2019-14863
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
AngularJS Cross-site Scripting due to failure to sanitize `xlink.href` attributes
CVEs:CVE-2019-14863
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular | affected | npm | angular | — |
There is a vulnerability in all angular versions before 1.5.0-beta.0, where after escaping the context of the web application, the web application delivers data to its users along with other trusted dynamic content, without validating it.
CVEs:CVE-2019-14863
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angularjs | affected | angularjs | — | — |
| decision_manager | affected | redhat | — | — |
| process_automation | affected | redhat | — | — |
CVEs:CVE-2020-0001
In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product:...
CVEs:CVE-2020-0001
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP1 | chromium | — |
DEBIAN-CVE-2019-13767
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| containerd | affected | openSUSE:Leap 15.1 | containerd | — |
| docker | affected | openSUSE:Leap 15.1 | docker | — |
| docker-runc | affected | openSUSE:Leap 15.1 | docker-runc | — |
| golang-github-docker-libnetwork | affected | openSUSE:Leap 15.1 | golang-github-docker-libnetwork | — |
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| containerd | affected | SUSE:Linux Enterprise Module for Containers 12 | containerd | — |
| docker | affected | SUSE:Linux Enterprise Module for Containers 12 | docker | — |
| docker-runc | affected | SUSE:Linux Enterprise Module for Containers 12 | docker-runc | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise Module for Containers 12 | golang-github-docker-libnetwork | — |
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| containerd | affected | SUSE:Linux Enterprise Module for Containers 15 SP1 | containerd | — |
| containerd | affected | SUSE:Linux Enterprise Module for Containers 15 | containerd | — |
| docker | affected | SUSE:Linux Enterprise Module for Containers 15 | docker | — |
| docker | affected | SUSE:Linux Enterprise Module for Containers 15 SP1 | docker | — |
| docker-runc | affected | SUSE:Linux Enterprise Module for Containers 15 SP1 | docker-runc | — |
| docker-runc | affected | SUSE:Linux Enterprise Module for Containers 15 | docker-runc | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise Module for Containers 15 SP1 | golang-github-docker-libnetwork | — |
| golang-github-docker-libnetwork | affected | SUSE:Linux Enterprise Module for Containers 15 | golang-github-docker-libnetwork | — |
Angular Expressions before version 1.0.1 has a remote code execution vulnerability if you call expressions.compile(userControlledInput) where userControlledInput is text that comes from user input. If running angular-expressions in the browser, an atta...
CVEs:CVE-2020-5219
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | peerigon | — | — |
Remote Code Execution in Angular Expressions
CVEs:CVE-2020-5219
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | npm | angular-expressions | — |
Remote Code Execution in Angular Expressions
CVEs:CVE-2020-5219
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | npm | angular-expressions | — |
Remote Code Execution in Angular Expressions
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | npm | angular-expressions | — |
Remote Code Execution in Angular Expressions
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| angular-expressions | affected | npm | angular-expressions | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP1 | chromium | — |
| re2 | affected | SUSE:Package Hub 15 SP1 | re2 | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP1 | chromium | — |
| re2 | affected | SUSE:Package Hub 15 SP1 | re2 | — |
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | openSUSE:Leap 15.1 | chromium | — |
| re2 | affected | openSUSE:Leap 15.1 | re2 | — |
DEBIAN-CVE-2020-6377
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6377
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| debian_linux | affected | debian | — | — |
| enterprise_linux_desktop | affected | redhat | — | — |
| enterprise_linux_workstation | affected | redhat | — | — |
| fedora | affected | fedoraproject | — | — |
| leap | affected | opensuse | — | — |
CVEs:CVE-2020-6377
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 15 SP1 | chromium | — |
| chromium | affected | SUSE:Package Hub 12 SP3 | chromium | — |
DEBIAN-CVE-2019-5844
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2019-5845
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
DEBIAN-CVE-2019-5846
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2019-5845
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5845
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| leap | affected | opensuse | — | — |
CVEs:CVE-2019-5846
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5846
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| leap | affected | opensuse | — | — |
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-5844
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| backports_sle | affected | opensuse | — | — |
| chrome | affected | — | — | |
| leap | affected | opensuse | — | — |
CVEs:CVE-2019-5844
In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation Product: Andro...
CVEs:CVE-2020-0002
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0002
Security update for chromium
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | SUSE:Package Hub 12 SP3 | chromium | — |
| chromium | affected | SUSE:Package Hub 15 SP1 | chromium | — |
| chromium | affected | openSUSE:Leap 15.1 | chromium | — |
Use after free in speech in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6378
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2020-6378
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted Chrome Extension.
CVEs:CVE-2020-6380
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2020-6380
Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6379
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — | |
| fedora | affected | fedoraproject | — | — |
CVEs:CVE-2020-6379
In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to remote information disclosure in the NFC server with no additional execution privileges needed. ...
CVEs:CVE-2020-0006
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0006
DEBIAN-CVE-2019-13765
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
CVEs:CVE-2019-13765
Use-after-free in content delivery manager in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13765
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
DEBIAN-CVE-2019-13766
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chromium | affected | Debian:12 | chromium | — |
| chromium | affected | Debian:14 | chromium | — |
| chromium | affected | Debian:11 | chromium | — |
| chromium | affected | Debian:13 | chromium | — |
Use-after-free in accessibility in Google Chrome prior to 77.0.3865.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2019-13766
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| chrome | affected | — | — |
CVEs:CVE-2019-13766
PYSEC-2020-258
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
PYSEC-2020-303
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
PYSEC-2020-338
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segmentation faultin TensorFlow when converting a Python string to `tf.float16`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segmentation faultin TensorFlow when converting a Python string to `tf.float16`
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
PYSEC-2020-338
CVEs:CVE-2020-5215
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
Segmentation faultin TensorFlow when converting a Python string to `tf.float16`
CVEs:CVE-2020-5215
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | PyPI | tensorflow | — |
| tensorflow-cpu | affected | PyPI | tensorflow-cpu | — |
| tensorflow-gpu | affected | PyPI | tensorflow-gpu | — |
In TensorFlow before 1.15.2 and 2.0.1, converting a string (from Python) to a tf.float16 value results in a segmentation fault in eager mode as the format checks for this use case are only in the graph mode. This issue can lead to denial of service in ...
CVEs:CVE-2020-5215
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| tensorflow | affected | — | — |
In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2020-0007
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0007
CVEs:CVE-2020-0004
In generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceeding maximum texture size. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2020-0004
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0003
In onCreate of InstallStart.java, there is a possible package validation bypass due to a time-of-check time-of-use vulnerability. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is neede...
CVEs:CVE-2020-0003
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
In LowEnergyClient::MtuChangedCallback of low_energy_client.cc, there is a possible out of bounds read due to a race condition. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not need...
CVEs:CVE-2020-0008
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2020-0008
Kubernetes ingress exposes sensitive information
CVEs:CVE-2018-1002104
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| ingress-nginx | affected | k8s.io | k8s.io/ingress-nginx | — |
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
CVEs:CVE-2018-1002104
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| nginx_ingress_controller | affected | kubernetes | — | — |
CVEs:CVE-2014-7238
The WordPress plugin Contact Form Integrated With Google Maps 1.0-2.4 has Stored XSS
CVEs:CVE-2014-7238
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| contact_form_integrated_with_google_maps | affected | formget | — | — |
media/libmedia/IAudioPolicyService.cpp in Android before 5.1 allows attackers to execute arbitrary code with media_server privileges or cause a denial of service (integer overflow) via a crafted application that provides an invalid array size.
CVEs:CVE-2015-1530
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
CVEs:CVE-2015-1530
CVEs:CVE-2015-1525
audio/AudioPolicyManagerBase.cpp in Android before 5.1 allows attackers to cause a denial of service (audio_policy application outage) via a crafted application that provides a NULL device address.
CVEs:CVE-2015-1525
| Product | Status | Vendor | Package | Ecosystem |
|---|---|---|---|---|
| android | affected | — | — |
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.