Google Security Advisories · March 2020 — Google Security Advisories
405 advisories 211 CVEs 18 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2020-03. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 18 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

DSA-4638-1

Open SourceExploitedCISA KEV listed2020-03-10

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

MGASA-2020-0123

Open SourceExploitedCISA KEV listedCRITICAL2020-03-06

Updated chromium-browser-stable packages fix security vulnerabilities

Affected products

ProductStatusVendorPackageEcosystem
chromium-browser-stable affected Mageia:7 chromium-browser-stable
icu affected Mageia:7 icu
Upstream advisory

CVE-2020-0938

GoogleExploitedCISA KEV listedCRITICAL2020-03-24

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who s...

CVEs:CVE-2020-0938

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1709 affected microsoft
windows_10_1803 affected microsoft
windows_10_1809 affected microsoft
windows_10_1903 affected microsoft
windows_10_1909 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_1803 affected microsoft
windows_server_1903 affected microsoft
windows_server_1909 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

CVE-2020-0938

Project ZeroExploitedCISA KEV listed2020-03-24

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-1020.

CVEs:CVE-2020-0938

Upstream advisory

CVE-2020-1020

GoogleExploitedCISA KEV listedCRITICAL2020-03-24

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who s...

CVEs:CVE-2020-1020

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1709 affected microsoft
windows_10_1803 affected microsoft
windows_10_1809 affected microsoft
windows_10_1903 affected microsoft
windows_10_1909 affected microsoft
windows_7 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_1903 affected microsoft
windows_server_1909 affected microsoft
windows_server_2008 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

CVE-2020-1020

Project ZeroExploitedCISA KEV listed2020-03-24

A remote code execution vulnerability exists in Microsoft Windows when the Windows Adobe Type Manager Library improperly handles a specially-crafted multi-master font - Adobe Type 1 PostScript format.For all systems except Windows 10, an attacker who successfully exploited the vulnerability could execute code remotely, aka 'Adobe Font Manager Library Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-0938.

CVEs:CVE-2020-1020

Upstream advisory

CVE-2020-8467

GoogleExploitedCISA KEV listedCRITICAL2020-03-18

A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.

CVEs:CVE-2020-8467

Affected products

ProductStatusVendorPackageEcosystem
apex_one affected trendmicro
officescan affected trendmicro
Upstream advisory

CVE-2020-8467

Project ZeroExploitedCISA KEV listed2020-03-18

A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.

CVEs:CVE-2020-8467

Upstream advisory

CVE-2020-8468

GoogleExploitedCISA KEV listedHIGH2020-03-18

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted atta...

CVEs:CVE-2020-8468

Affected products

ProductStatusVendorPackageEcosystem
apex_one affected trendmicro
officescan affected trendmicro
worry-free_business_security affected trendmicro
Upstream advisory

CVE-2020-8468

Project ZeroExploitedCISA KEV listed2020-03-18

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.

CVEs:CVE-2020-8468

Upstream advisory

CVE-2020-0041

Open SourceExploitedCISA KEV listedHIGH2020-03-03

In binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2020-0041

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0069

Open SourceExploitedCISA KEV listedHIGH2020-03-03

In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution p...

CVEs:CVE-2020-0069

Affected products

ProductStatusVendorPackageEcosystem
android affected google
berkeley-l09_firmware affected huawei
columbia-al10b_firmware affected huawei
columbia-l29d_firmware affected huawei
columbia-tl00b_firmware affected huawei
columbia-tl00d_firmware affected huawei
cornell-al00a_firmware affected huawei
cornell-tl10b_firmware affected huawei
dura-al00a_firmware affected huawei
honor_20_pro_firmware affected huawei
honor_8a_firmware affected huawei
honor_view_20_firmware affected huawei
jakarta-al00a_firmware affected huawei
katyusha-al00a_firmware affected huawei
katyusha-al10a_firmware affected huawei
madrid-al00a_firmware affected huawei
nova_3_firmware affected huawei
nova_4_firmware affected huawei
paris-l29b_firmware affected huawei
princeton-al10b_firmware affected huawei
sydney-al00_firmware affected huawei
sydneym-al00_firmware affected huawei
sydney-tl00_firmware affected huawei
tony-al00b_firmware affected huawei
tony-tl00b_firmware affected huawei
y6_2019_firmware affected huawei
yale-al00a_firmware affected huawei
yale-l21a_firmware affected huawei
yalep-al10b_firmware affected huawei
Upstream advisory

CVE-2020-10531

GooglePoC exploitCRITICAL2020-03-12

An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unistr.cpp.

CVEs:CVE-2020-10531

Affected products

ProductStatusVendorPackageEcosystem
banking_extensibility_workbench affected oracle
chrome affected google
debian_linux affected debian
enterprise_linux_desktop affected redhat
enterprise_linux_server affected redhat
enterprise_linux_workstation affected redhat
fedora affected fedoraproject
international_components_for_unicode affected icu-project
leap affected opensuse
node.js affected nodejs
ubuntu_linux affected canonical
Upstream advisory

DEBIAN-CVE-2020-10675

Open SourcePoC exploitHIGH2020-03-19

DEBIAN-CVE-2020-10675

Affected products

ProductStatusVendorPackageEcosystem
golang-github-buger-jsonparser affected Debian:11 golang-github-buger-jsonparser
golang-github-buger-jsonparser affected Debian:12 golang-github-buger-jsonparser
golang-github-buger-jsonparser affected Debian:13 golang-github-buger-jsonparser
golang-github-buger-jsonparser affected Debian:14 golang-github-buger-jsonparser
Upstream advisory

DEBIAN-CVE-2020-8552

Open SourcePoC exploitHIGH2020-03-27

DEBIAN-CVE-2020-8552

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2020-8552

Open SourcePoC exploitHIGH2020-03-27

The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.

CVEs:CVE-2020-8552

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
kubernetes affected kubernetes
Upstream advisory

CVE-2020-8552

Open SourcePoC exploitMEDIUM2020-03-27

Kubernetes API Server DoS Via API Requests

CVEs:CVE-2020-8552

Affected products

ProductStatusVendorPackageEcosystem
apiserver affected k8s.io k8s.io/apiserver
Upstream advisory

DEBIAN-CVE-2020-8551

Open SourcePoC exploitMEDIUM2020-03-27

DEBIAN-CVE-2020-8551

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
kubernetes affected Debian:14 kubernetes
Upstream advisory

CVE-2020-8551

Open SourcePoC exploitMEDIUM2020-03-27

The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and th...

CVEs:CVE-2020-8551

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
kubernetes affected kubernetes
Upstream advisory

CVE-2020-8551

Open SourcePoC exploitMEDIUM2020-03-27

Allocation of Resources Without Limits or Throttling and Uncontrolled Memory Allocation in Kubernetes

CVEs:CVE-2020-8551

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

openSUSE-SU-2020:0389-1

Open SourceCoalition ESS 30-63%CRITICAL2020-03-27

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:0365-1

Open SourceCoalition ESS 30-63%CRITICAL2020-03-22

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP3 chromium
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

DSA-4645-1

Open SourceCoalition ESS 30-63%2020-03-22

chromium - security update

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:10 chromium
Upstream advisory

DEBIAN-CVE-2020-6422

Open SourceCoalition ESS 30-63%CRITICAL2020-03-23

DEBIAN-CVE-2020-6422

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6422

GoogleCoalition ESS 30-63%CRITICAL2020-03-19

Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6422

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
suse_linux_enterprise_desktop affected suse
suse_linux_enterprise_server affected suse
Upstream advisory

DEBIAN-CVE-2020-6424

Open SourceCoalition ESS < 30%CRITICAL2020-03-23

DEBIAN-CVE-2020-6424

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6424

GoogleCoalition ESS < 30%CRITICAL2020-03-19

Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6424

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
suse_linux_enterprise_desktop affected suse
suse_linux_enterprise_server affected suse
Upstream advisory

DEBIAN-CVE-2019-20503

Open SourceCoalition ESS < 30%MEDIUM2020-03-06

DEBIAN-CVE-2019-20503

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
firefox-esr affected Debian:11 firefox-esr
firefox-esr affected Debian:12 firefox-esr
firefox-esr affected Debian:13 firefox-esr
firefox-esr affected Debian:14 firefox-esr
libusrsctp affected Debian:13 libusrsctp
libusrsctp affected Debian:11 libusrsctp
libusrsctp affected Debian:12 libusrsctp
libusrsctp affected Debian:14 libusrsctp
thunderbird affected Debian:11 thunderbird
thunderbird affected Debian:12 thunderbird
thunderbird affected Debian:13 thunderbird
thunderbird affected Debian:14 thunderbird
Upstream advisory

DEBIAN-CVE-2020-6426

Open SourceCoalition ESS < 30%MEDIUM2020-03-23

DEBIAN-CVE-2020-6426

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6426

GoogleCoalition ESS < 30%MEDIUM2020-03-19

Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6426

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
suse_linux_enterprise_desktop affected suse
suse_linux_enterprise_server affected suse
Upstream advisory

DEBIAN-CVE-2020-10696

Open SourceCoalition ESS < 30%HIGH2020-03-31

DEBIAN-CVE-2020-10696

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containers-buildah affected Debian:11 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:12 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:13 golang-github-containers-buildah
golang-github-containers-buildah affected Debian:14 golang-github-containers-buildah
Upstream advisory

DEBIAN-CVE-2020-6449

Open SourceCoalition ESS < 30%CRITICAL2020-03-23

DEBIAN-CVE-2020-6449

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6449

GoogleCoalition ESS < 30%CRITICAL2020-03-19

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6449

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
suse_linux_enterprise_desktop affected suse
suse_linux_enterprise_server affected suse
Upstream advisory

CVE-2020-7919

GoogleCoalition ESS < 30%HIGH2020-03-16

Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate.

CVEs:CVE-2020-7919

Affected products

ProductStatusVendorPackageEcosystem
cloud_insights_telegraf affected netapp
debian_linux affected debian
fedora affected fedoraproject
go affected golang
Upstream advisory

CVE-2020-7919

Open SourceCoalition ESS < 30%HIGH2020-03-16

Helm uses crypto package vulnerable to panic from malformed X.509 certificate

CVEs:CVE-2020-7919

Affected products

ProductStatusVendorPackageEcosystem
helm/helm affected github.com github.com/helm/helm
helm/v3 affected helm.sh helm.sh/helm/v3
x/crypto affected golang.org golang.org/x/crypto
Upstream advisory

DEBIAN-CVE-2020-6427

Open SourceCoalition ESS < 30%CRITICAL2020-03-23

DEBIAN-CVE-2020-6427

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6427

GoogleCoalition ESS < 30%CRITICAL2020-03-19

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6427

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
suse_linux_enterprise_desktop affected suse
suse_linux_enterprise_server affected suse
Upstream advisory

DEBIAN-CVE-2020-6428

Open SourceCoalition ESS < 30%CRITICAL2020-03-23

DEBIAN-CVE-2020-6428

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:13 chromium
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:14 chromium
Upstream advisory

DEBIAN-CVE-2020-6429

Open SourceCoalition ESS < 30%CRITICAL2020-03-23

DEBIAN-CVE-2020-6429

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6428

GoogleCoalition ESS < 30%CRITICAL2020-03-19

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6428

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
suse_linux_enterprise_desktop affected suse
suse_linux_enterprise_server affected suse
Upstream advisory

CVE-2020-6429

GoogleCoalition ESS < 30%CRITICAL2020-03-19

Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6429

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
suse_linux_enterprise_desktop affected suse
suse_linux_enterprise_server affected suse
Upstream advisory

CVE-2020-0034

Open SourceCoalition ESS < 30%HIGH2020-03-03

In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execution privileges needed. User int...

CVEs:CVE-2020-0034

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

CVE-2020-0032

Open SourceCoalition ESS < 30%HIGH2020-03-03

In ih264d_release_display_bufs of ih264d_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitatio...

CVEs:CVE-2020-0032

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

DEBIAN-CVE-2020-6420

Open SourceCoalition ESS < 30%CRITICAL2020-03-23

DEBIAN-CVE-2020-6420

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

openSUSE-SU-2020:0324-1

Open SourceCoalition ESS < 30%CRITICAL2020-03-09

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 12 SP3 chromium
Upstream advisory

openSUSE-SU-2020:0322-1

Open SourceCoalition ESS < 30%CRITICAL2020-03-09

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2020-6420

GoogleCoalition ESS < 30%CRITICAL2020-03-05

Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

CVEs:CVE-2020-6420

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

DEBIAN-CVE-2020-6425

Open SourceCoalition ESS < 30%CRITICAL2020-03-23

DEBIAN-CVE-2020-6425

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6425

GoogleCoalition ESS < 30%CRITICAL2020-03-19

Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.

CVEs:CVE-2020-6425

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
fedora affected fedoraproject
Upstream advisory

CVE-2020-0037

Open SourceCoalition ESS < 30%HIGH2020-03-03

In rw_i93_sm_set_read_only of rw_i93.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure over NFC with no additional execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2020-0037

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0038

Open SourceCoalition ESS < 30%HIGH2020-03-03

In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2020-0038

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0039

Open SourceCoalition ESS < 30%HIGH2020-03-03

In rw_i93_sm_update_ndef of rw_i93.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2020-0039

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0083

Open SourceCoalition ESS < 30%HIGH2020-03-03

In setRequirePmfInternal of sta_network.cpp, there is a possible default value being improperly applied due to a logic error. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2020-0083

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20607

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (MSM8996, MSM8998, Exynos7420, Exynos7870, Exynos8890, and Exynos8895 chipsets) software. A heap overflow in the keymaster Trustlet allows attackers to write to TEE memor...

CVEs:CVE-2019-20607

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20611

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), Go(8.1), P(9.0), and Go(9.0) (Exynos chipsets) software. A baseband stack overflow leads to arbitrary code execution. The Samsung ID is SVE-2019-13963 (April 2019).

CVEs:CVE-2019-20611

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20567

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. A up_parm heap overflow leads to code execution in the bootloader. The Samsung ID is SVE-2019-14993 (September 2019).

CVEs:CVE-2019-20567

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10850

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The secure bootloade has a buffer overflow of the USB buffer, leading to arbitrary code execution. The Samsung ID is SVE-2019-15872 (January ...

CVEs:CVE-2020-10850

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10837

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (with TEEGRIS) software. The Esecomm Trustlet allows a stack overflow and arbitrary code execution. The Samsung ID is SVE-2019-15984 (February 2020).

CVEs:CVE-2020-10837

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20589

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the SKPM Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14892 (August 2019).

CVEs:CVE-2019-20589

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20588

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the SEM Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14891 (August 2019).

CVEs:CVE-2019-20588

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20587

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (with TEEGRIS) software. There is type confusion in the MLDAP Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14867 (August 2019).

CVEs:CVE-2019-20587

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20586

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (with TEEGRIS) software. There is type confusion in the FINGERPRINT Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14864 (August 2019).

CVEs:CVE-2019-20586

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20585

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the SEC_FR Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14851 (August 2019).

CVEs:CVE-2019-20585

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20584

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the HDCP Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14850 (August 2019).

CVEs:CVE-2019-20584

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20583

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. There is type confusion in the EXT_FR Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14847 (August 2019).

CVEs:CVE-2019-20583

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20537

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (TEEGRIS and Qualcomm chipsets). There is arbitrary memory overwrite in the SEM Trustlet, leading to arbitrary code execution. The Samsung IDs are SVE-2019-14651, SVE-2019-14666 (November 20...

CVEs:CVE-2019-20537

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9474

Open SourceCoalition ESS < 30%HIGH2020-03-15

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versi...

CVEs:CVE-2019-9474

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-9473

Open SourceCoalition ESS < 30%HIGH2020-03-15

In Bluetooth, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versi...

CVEs:CVE-2019-9473

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2058

Open SourceCoalition ESS < 30%MEDIUM2020-03-15

In libAACdec, there is a possible out of bounds read. This could lead to remote information disclosure, with no additional execution privileges needed. User interaction is needed for exploitation.Product: Android Versions: Android-10 Android ID: A-1360...

CVEs:CVE-2019-2058

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0049

Open SourceCoalition ESS < 30%HIGH2020-03-03

In onReadBuffer() of StreamingSource.cpp, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation...

CVEs:CVE-2020-0049

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20581

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. A stack overflow in the HDCP Trustlet causes arbitrary code execution. The Samsung ID is SVE-2019-14665 (August 2019).

CVEs:CVE-2019-20581

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0088

Open SourceCoalition ESS < 30%HIGH2020-03-15

In parseTrackFragmentRun of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitat...

CVEs:CVE-2020-0088

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20571

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. There is type confusion in the WVDRM Trustlet, leading to arbitrary code execution. The Samsung ID is SVE-2019-14885 (September 2019).

CVEs:CVE-2019-20571

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0086

Open SourceCoalition ESS < 30%CRITICAL2020-03-15

In readCString of Parcel.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to arbitrary code execution if IntSan were not enabled, which it is by default. No additional execution privileges are required. User inte...

CVEs:CVE-2020-0086

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0062

Open SourceCoalition ESS < 30%HIGH2020-03-03

In Euicc, there is a possible information disclosure due to an included test Certificate. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2020-0062

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20622

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband stack overflow. The Samsung ID is SVE-2018-13188 (February 2019).

CVEs:CVE-2019-20622

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20621

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a baseband heap overflow. The Samsung ID is SVE-2018-13187 (February 2019).

CVEs:CVE-2019-20621

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20610

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code execution. The Samsung ID is SVE-2019-1...

CVEs:CVE-2019-20610

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10848

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos 9810 chipsets) software. Arbitrary memory mapping exists in TEE. The Samsung ID is SVE-2019-16665 (February 2020).

CVEs:CVE-2020-10848

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20605

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. A heap overflow occurs for baseband in the Shannon modem. The Samsung ID is SVE-2019-14071 (May 2019).

CVEs:CVE-2019-20605

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20545

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos chipsets) software. A buffer overflow in the HDCP Trustlet affects secure TEEGRIS memory. The Samsung ID is SVE-2019-15283 (November 2019).

CVEs:CVE-2019-20545

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20561

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. The bootloader has an integer signedness error. The Samsung ID is SVE-2019-15230 (October 2019).

CVEs:CVE-2019-20561

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20549

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom chipsets) software. A heap out-of-bounds access can occur during LE Packet reception in Broadcom Bluetooth. The Samsung ID is SVE-2019-15724 (November 2019).

CVEs:CVE-2019-20549

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8910

GoogleCoalition ESS < 30%MEDIUM2020-03-26

Improper Input Validation in Google Closure Library

CVEs:CVE-2020-8910

Affected products

ProductStatusVendorPackageEcosystem
google-closure-library affected npm google-closure-library
Upstream advisory

CVE-2020-8910

GoogleCoalition ESS < 30%MEDIUM2020-03-26

A URL parsing issue in goog.uri of the Google Closure Library versions up to and including v20200224 allows an attacker to send malicious URLs to be parsed by the library and return the wrong authority. Mitigation: update your library to version v20200...

CVEs:CVE-2020-8910

Affected products

ProductStatusVendorPackageEcosystem
closure_library affected google
Upstream advisory

CVE-2020-8910

GoogleCoalition ESS < 30%MEDIUM2020-03-26

Improper Input Validation in Google Closure Library

CVEs:CVE-2020-8910

Affected products

ProductStatusVendorPackageEcosystem
google-closure-library affected npm google-closure-library
Upstream advisory

CVE-2019-20603

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.0), and P(9.0) (Qualcomm chipsets) software. The ESECOMM Trustlet has a NULL pointer dereference. The Samsung ID is SVE-2019-13950 (May 2019).

CVEs:CVE-2019-20603

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20602

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.0), and P(9.0) (Qualcomm chipsets) software. The Authnr Trustlet has a NULL pointer dereference. The Samsung ID is SVE-2019-13949 (May 2019).

CVEs:CVE-2019-20602

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20563

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. The SEC_FR trustlet has an out of bounds write. The Samsung ID is SVE-2019-15272 (October 2019).

CVEs:CVE-2019-20563

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20560

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (with TEEGRIS) software. The BIOSUB Trustlet has an out of bounds write. The Samsung ID is SVE-2019-15261 (October 2019).

CVEs:CVE-2019-20560

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20596

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Exynos chipsets) software. There is information disclosure in the GateKeeper Trustlet. The Samsung ID is SVE-2019-13958 (June 2019).

CVEs:CVE-2019-20596

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20544

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos chipsets) software. There is an out-of-bounds write in the ICCC Trustlet. The Samsung ID is SVE-2019-15274 (November 2019).

CVEs:CVE-2019-20544

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10836

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos chipsets) software. The Widevine Trustlet allows read and write operations on arbitrary memory locations. The Samsung ID is SVE-2019-15873 (February 2020).

CVEs:CVE-2020-10836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20562

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (with TEEGRIS) software. There is a buffer overflow in the BIOSUB Trustlet. The Samsung ID is SVE-2019-15264 (October 2019).

CVEs:CVE-2019-20562

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20590

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) (Qualcomm chipsets) software. There is an integer underflow in the Secure Storage Trustlet. The Samsung ID is SVE-2019-13952 (July 2019).

CVEs:CVE-2019-20590

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20582

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos9810 chipsets) software. There is a use after free in the ion driver. The Samsung ID is SVE-2019-14837 (August 2019).

CVEs:CVE-2019-20582

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20556

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (SM6150, SM8150, SM8150_FUSION, exynos7885, exynos9610, and exynos9820 chipsets) software. RKP memory corruption allows attackers to control the effective address in EL2. The Samsung ID is S...

CVEs:CVE-2019-20556

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20553

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (SM6150, SM8150, SM8150_FUSION, exynos7885, exynos9610, and exynos9820 chipsets) software. Arbitrary memory read and write operations can occur in RKP. The Samsung ID is SVE-2019-15143 (Octo...

CVEs:CVE-2019-20553

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20578

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (Exynos 9820 chipsets) software. A Buffer overflow occurs when loading the UH Partition during Secure Boot. The Samsung ID is SVE-2019-14412 (August 2019).

CVEs:CVE-2019-20578

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20572

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (Exynos chipsets) software. load_kernel has a buffer overflow via untrusted data. The Samsung ID is SVE-2019-14939 (September 2019).

CVEs:CVE-2019-20572

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20558

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a Buffer Overflow in the Touch Screen Driver. The Samsung ID is SVE-2019-14990 (October 2019).

CVEs:CVE-2019-20558

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20548

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) devices (Qualcomm chipsets) software. There is a buffer overflow in the bootloader. The Samsung ID is SVE-2019-15399 (November 2019).

CVEs:CVE-2019-20548

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20536

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2019).

CVEs:CVE-2019-20536

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20577

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The MALI GPU Driver allows a kernel panic. The Samsung ID is SVE-2019-14372 (August 2019).

CVEs:CVE-2019-20577

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20530

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), P(9.0), and Q(10.0) software. Arbitrary code execution is possible on the lock screen. The Samsung ID is SVE-2019-15266 (December 2019).

CVEs:CVE-2019-20530

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20612

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) (Broadcom Wi-Fi, and SEC Wi-Fi chipsets) software. Wi-Fi allows a denial of service via TCP SYN packets. The Samsung ID is SVE-2018-13162 (March 2019).

CVEs:CVE-2019-20612

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20604

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) software. Attackers can disable Gallery permanently. The Samsung ID is SVE-2019-14031 (May 2019).

CVEs:CVE-2019-20604

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20619

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Secure Startup leaks keyboard suggested words. The Samsung ID is SVE-2019-13773 (March 2019).

CVEs:CVE-2019-20619

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10854

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Kernel stack addresses are leaked to userspace. The Samsung ID is SVE-2019-16161 (January 2020).

CVEs:CVE-2020-10854

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10849

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (Exynos7885, Exynos8895, and Exynos9810 chipsets) software. The Gatekeeper trustlet allows a brute-force attack on the screen lock password. The Samsung ID is SVE-2019-1...

CVEs:CVE-2020-10849

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20576

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. The MemorySaver Content Provider allows SQL injection. The Samsung ID is SVE-2019-14365 (August 2019).

CVEs:CVE-2019-20576

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20614

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Allshare allows attackers to access sensitive information. The Samsung ID is SVE-2018-13453 (March 2019).

CVEs:CVE-2019-20614

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10833

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with Q(10.0) software. The DeX Lockscreen allows attackers to access the quick panel and notifications. The Samsung ID is SVE-2019-16532 (March 2020).

CVEs:CVE-2020-10833

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10844

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.x), and Q(10.0) software. There is an out-of-bounds read vulnerability in media.audio_policy. The Samsung ID is SVE-2019-16333 (February 2020).

CVEs:CVE-2020-10844

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20570

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0), O(8.0), and N(7.1) software. Attackers can bypass Factory Reset Protection (FRP) via Smart Switch. The Samsung ID is SVE-2019-15138 (September 2019).

CVEs:CVE-2019-20570

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20552

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via an RCS call. The Samsung ID is SVE-2019-15035 (October 2019).

CVEs:CVE-2019-20552

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20551

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via a Class 0 Type Message. The Samsung ID is SVE-2019-14941 (October 2019).

CVEs:CVE-2019-20551

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20613

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. There is time-based SQL injection in Contacts. The Samsung ID is SVE-2018-13452 (March 2019).

CVEs:CVE-2019-20613

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20565

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Attackers can change the USB configuration without authentication. The Samsung ID is SVE-2018-13300 (September 2019).

CVEs:CVE-2019-20565

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20580

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. The Motion photo player allows attackers to bypass the Secure Folder feature to view images. The Samsung ID is SVE-2019-14653 (August 2019).

CVEs:CVE-2019-20580

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20532

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can access the Developer options without authentication. The Samsung ID is SVE-2019-15800 (December 2019).

CVEs:CVE-2019-20532

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20608

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. An attacker can use Emergency mode to disable features. The Samsung IDs are SVE-2018-13164, SVE-2018-13165 (April 2019).

CVEs:CVE-2019-20608

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20601

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos7570, 7580, 7870, 7880, and 8890 chipsets) software. RKP memory corruption causes an arbitrary write to protected memory. The Samsung ID is SVE-2019-13921-2 (May 2...

CVEs:CVE-2019-20601

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20593

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks Private Mode thumbnails. The Samsung ID is SVE-2019-14208 (July 2019).

CVEs:CVE-2019-20593

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20617

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Secure Folder leaks preview data of recent apps. The Samsung ID is SVE-2018-13764 (March 2019).

CVEs:CVE-2019-20617

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20616

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Gallery leaks a thumbnail of Private Mode content. The Samsung ID is SVE-2018-13563 (March 2019).

CVEs:CVE-2019-20616

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20606

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with any (before May 2019) software. A phishing attack against OMACP can change the network and internet settings. The Samsung ID is SVE-2019-14073 (May 2019).

CVEs:CVE-2019-20606

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20547

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. Data may leak via a Bluetooth debug command. The Samsung ID is SVE-2019-15398 (November 2019).

CVEs:CVE-2019-20547

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20539

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom chipsets) software. An out-of-bounds Read in the Wi-Fi vendor command leads to an information leak. The Samsung ID is SVE-2019-14869 (November 2019).

CVEs:CVE-2019-20539

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10853

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery leaks cached data. The Samsung IDs are SVE-2019-16010, SVE-2019-16011, SVE-2019-16012 (January 2020).

CVEs:CVE-2020-10853

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10834

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view notifications on the lock screen via Routines. The Samsung ID is SVE-2019-15074 (February 2020).

CVEs:CVE-2020-10834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20620

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. The Settings application allows unauthenticated changes. The Samsung IDs are SVE-2019-13814, SVE-2019-13815 (March 2019).

CVEs:CVE-2019-20620

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20618

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. The Pin Window feature allows unauthenticated unpinning of an app. The Samsung ID is SVE-2018-13765 (March 2019).

CVEs:CVE-2019-20618

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20599

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Voice Assistant mishandles the notification audibility of a secured app. The Samsung ID is SVE-2018-13326 (May 2019).

CVEs:CVE-2019-20599

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20624

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. S-Voice leaks keyboard learned words via the lock screen. The Samsung ID is SVE-2018-12981 (February 2019).

CVEs:CVE-2019-20624

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20555

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x) software. The Gallery app allows attackers to view all pictures of a locked device. The Samsung ID is SVE-2019-15189 (October 2019).

CVEs:CVE-2019-20555

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8923

Open SourceCoalition ESS < 30%CRITICAL2020-03-26

An improper HTML sanitization in Dart versions up to and including 2.7.1 and dev versions 2.8.0-dev.16.0, allows an attacker leveraging DOM Clobbering techniques to skip the sanitization and inject custom html/javascript (XSS). Mitigation: update your ...

CVEs:CVE-2020-8923

Affected products

ProductStatusVendorPackageEcosystem
dart_software_development_kit affected dart
Upstream advisory

CVE-2019-20568

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) devices (Exynos and Qualcomm chipsets) software. A race condition causes a Use-After-Free. The Samsung ID is SVE-2019-15067 (September 2019).

CVEs:CVE-2019-20568

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20597

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. SPENgesture allows arbitrary applications to read or modify user-input logs. The Samsung ID is SVE-2019-14170 (June 2019).

CVEs:CVE-2019-20597

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20546

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Broadcom Wi-Fi chipsets) software. A denial-of-service attack can leverage a shared interface between Broadcom Bluetooth and Broadcom Wi-Fi. The Samsung ID is SVE-2019-1...

CVEs:CVE-2019-20546

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10831

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can trigger an update to arbitrary touch-screen firmware. The Samsung ID is SVE-2019-16013 (March 2020).

CVEs:CVE-2020-10831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0033

Open SourceCoalition ESS < 30%HIGH2020-03-03

In CryptoPlugin::decrypt of CryptoPlugin.cpp, there is a possible out of bounds write due to stale pointer. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation...

CVEs:CVE-2020-0033

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20609

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can use Smartwatch to view Secure Folder notification content. The Samsung ID is SVE-2019-13899 (April 2019).

CVEs:CVE-2019-20609

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0036

Open SourceCoalition ESS < 30%HIGH2020-03-03

In hasPermissions of PermissionMonitor.java, there is a possible access to restricted permissions due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not need...

CVEs:CVE-2020-0036

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0011

Open SourceCoalition ESS < 30%HIGH2020-03-03

In get_auth_result of fpc_ta_hw_auth.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2020-0011

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0012

Open SourceCoalition ESS < 30%HIGH2020-03-03

In fpc_ta_pn_get_unencrypted_image of fpc_ta_pn.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2020-0012

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20591

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Gear VR Service Content Provider. The Samsung ID is SVE-2019-14058 (July 2019).

CVEs:CVE-2019-20591

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20573

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the RCS Content Provider. The Samsung IDs are SVE-2019-14059, SVE-2019-14685 (August 2019).

CVEs:CVE-2019-20573

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0063

Open SourceCoalition ESS < 30%HIGH2020-03-03

In SurfaceFlinger, it is possible to override UI confirmation screen protected by the TEE. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVers...

CVEs:CVE-2020-0063

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2216

Open SourceCoalition ESS < 30%HIGH2020-03-15

In overlay notifications, there is a possible hidden notification due to improper input validation. This could lead to a local escalation of privilege because the user is not notified of an overlaying app, with User execution privileges needed. User in...

CVEs:CVE-2019-2216

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0010

Open SourceCoalition ESS < 30%HIGH2020-03-03

In fpc_ta_get_build_info of fpc_ta_kpi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2020-0010

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0051

Open SourceCoalition ESS < 30%HIGH2020-03-03

In onCreate of SettingsHomepageActivity, there is a possible tapjacking attack. This could lead to local escalation of privilege in Settings with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVer...

CVEs:CVE-2020-0051

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0060

Open SourceCoalition ESS < 30%HIGH2020-03-03

In query of SmsProvider.java and MmsSmsProvider.java, there is a possible permission bypass due to SQL injection. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.P...

CVEs:CVE-2020-0060

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20592

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Story Video Editor Content Provider. The Samsung ID is SVE-2019-14062 (July 2019).

CVEs:CVE-2019-20592

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20574

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. There is local SQL injection in the Wi-Fi history Content Provider. The Samsung ID is SVE-2019-14061 (August 2019).

CVEs:CVE-2019-20574

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2089

Open SourceCoalition ESS < 30%HIGH2020-03-15

In app uninstallation, there is a possible set of permissions that may not be removed from a shared app ID. This could lead to a local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. ...

CVEs:CVE-2019-2089

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0055

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In l2c_link_process_num_completed_pkts of l2c_link.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2020-0055

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0061

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In Pixel Recorder, there is a possible permissions bypass allowing arbitrary apps to record audio. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: ...

CVEs:CVE-2020-0061

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0035

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In query of TelephonyProvider.java, there is a possible access to SIM card info due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2020-0035

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0046

Open SourceCoalition ESS < 30%HIGH2020-03-03

In DrmPlugin::releaseSecureStops of DrmPlugin.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed fo...

CVEs:CVE-2020-0046

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0050

Open SourceCoalition ESS < 30%HIGH2020-03-03

In nfa_hciu_send_msg of nfa_hci_utils.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege in the NFC server with System execution privileges needed. User interaction is not need...

CVEs:CVE-2020-0050

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0058

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In l2c_rcv_acl_data of l2c_main.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produc...

CVEs:CVE-2020-0058

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10829

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.0), P(9.0), and Q(10.0) (Broadcom chipsets) software. A kernel driver heap overflow leads to arbitrary code execution. The Samsung ID is SVE-2019-15880 (March 2020).

CVEs:CVE-2020-10829

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0042

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In fpc_ta_hw_auth_unwrap_key of fpc_ta_hw_auth_qsee.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2020-0042

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0043

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In authorize_enrol of fpc_ta_hw_auth.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Produ...

CVEs:CVE-2020-0043

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0052

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction ...

CVEs:CVE-2020-0052

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0031

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In triggerAugmentedAutofillLocked and related functions of Session.java, it is possible for Augmented Autofill to display sensitive information to the user inappropriately. This could lead to local information disclosure with no additional execution pr...

CVEs:CVE-2020-0031

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0053

Open SourceCoalition ESS < 30%HIGH2020-03-03

In convertHidlNanDataPathInitiatorRequestToLegacy, and convertHidlNanDataPathIndicationResponseToLegacy of hidl_struct_util.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege wit...

CVEs:CVE-2020-0053

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0056

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In btu_hcif_connection_comp_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2020-0056

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0057

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In btm_process_inq_results of btm_inq.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2020-0057

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0059

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In btm_ble_batchscan_filter_track_adv_vse_cback of btm_ble_batchscan.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interact...

CVEs:CVE-2020-0059

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2194

Open SourceCoalition ESS < 30%HIGH2020-03-03

In SurfaceFlinger::createLayer of SurfaceFlinger.cpp, there is a possible arbitrary code execution due to improper casting. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2019-2194

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10838

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. PROCA allows a use-after-free and arbitrary code execution. The Samsung ID is SVE-2019-16132 (February 2020).

CVEs:CVE-2020-10838

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0029

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In the WifiConfigManager, there is a possible storage of location history which can only be deleted by triggering a factory reset. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed f...

CVEs:CVE-2020-0029

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0084

Open SourceCoalition ESS < 30%HIGH2020-03-03

In several functions of NotificationManagerService.java, there are missing permission checks. This could lead to local escalation of privilege by creating fake system notifications with no additional execution privileges needed. User interaction is not...

CVEs:CVE-2020-0084

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0085

Open SourceCoalition ESS < 30%HIGH2020-03-03

In setBluetoothTethering of PanService.java, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege to activate tethering with no additional execution privileges needed. User interactio...

CVEs:CVE-2020-0085

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0087

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In getProcessPss of ActivityManagerService.java, there is a possible side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Produc...

CVEs:CVE-2020-0087

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-2088

Open SourceCoalition ESS < 30%MEDIUM2020-03-15

In StatsService, there is a possible out of bounds read. This could lead to local information disclosure if UBSAN were not enabled, with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versio...

CVEs:CVE-2019-2088

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0044

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In set_nonce of fpc_ta_qc_auth.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2020-0044

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0054

Open SourceCoalition ESS < 30%HIGH2020-03-03

In WifiNetworkSuggestionsManager of WifiNetworkSuggestionsManager.java, there is a possible permission revocation due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User i...

CVEs:CVE-2020-0054

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0066

Open SourceCoalition ESS < 30%HIGH2020-03-03

In the netlink driver, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...

CVEs:CVE-2020-0066

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10839

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card. The Samsung ID is SVE-2019-16193 (February 2020).

CVEs:CVE-2020-10839

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20623

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) software. Gallery has uninitialized memory disclosure. The Samsung ID is SVE-2018-13060 (February 2019).

CVEs:CVE-2019-20623

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20594

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.1) and P(9.0) (Exynos chipsets) software. A heap overflow exists in the bootloader. The Samsung ID is SVE-2019-14371 (July 2019).

CVEs:CVE-2019-20594

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20534

Open SourceCoalition ESS < 30%LOW2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can view home-screen wallpaper by adjusting the brightness of a locked screen. The Samsung ID is SVE-2019-15540 (December 2019).

CVEs:CVE-2019-20534

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10830

Open SourceCoalition ESS < 30%LOW2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can view notifications by entering many PINs in Lockdown mode. The Samsung ID is SVE-2019-16590 (March 2020).

CVEs:CVE-2020-10830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0048

Open SourceCoalition ESS < 30%MEDIUM2020-03-03

In onTransact of IAudioFlinger.cpp, there is a possible stack information leak due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2020-0048

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20600

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.0) and P(9.0) (Exynos8890 chipsets) software. A use-after-free occurs in the MALI GPU driver. The Samsung ID is SVE-2019-13921-1 (May 2019).

CVEs:CVE-2019-20600

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20595

Open SourceCoalition ESS < 30%LOW2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Quick Panel allows enabling or disabling the Bluetooth stack without authentication. The Samsung ID is SVE-2019-14545 (July 2019).

CVEs:CVE-2019-20595

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20579

Open SourceCoalition ESS < 30%LOW2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Gallery allows attackers to enable Location information sharing from the lock screen. The Samsung ID is SVE-2019-14462 (August 2019).

CVEs:CVE-2019-20579

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20542

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (Exynos chipsets) software. There is a stack overflow in the kernel driver. The Samsung ID is SVE-2019-15034 (November 2019).

CVEs:CVE-2019-20542

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20541

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi kernel drivers have a stack overflow. The Samsung IDs are SVE-2019-14965, SVE-2019-14966, SVE-2019-14968, SVE-2019-14969, SVE-2019-14970, SVE-2019-14980...

CVEs:CVE-2019-20541

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20538

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. There is a heap overflow in the knox_kap driver. The Samsung ID is SVE-2019-14857 (November 2019).

CVEs:CVE-2019-20538

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10842

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets) software. There is a heap out-of-bounds write in the tsmux driver. The Samsung ID is SVE-2019-16295 (February 2020).

CVEs:CVE-2020-10842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10841

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) software. There is an arbitrary kfree in the vipx and vertex drivers. The Samsung ID is SVE-2019-16294 (February 2020).

CVEs:CVE-2020-10841

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10852

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a stack overflow in display driver. The Samsung ID is SVE-2019-15877 (January 2020).

CVEs:CVE-2020-10852

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10851

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. There is a stack overflow in the kperfmon driver. The Samsung ID is SVE-2019-15876 (January 2020).

CVEs:CVE-2020-10851

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10847

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (Galaxy S8 and Note8) software. Facial recognition can be spoofed. The Samsung ID is SVE-2019-16614 (February 2020).

CVEs:CVE-2020-10847

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10832

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. Kernel Wi-Fi drivers allow out-of-bounds Read or Write operations (e.g., a buffer overflow). The Samsung IDs are SVE-2019-16125, SVE-2019-16134, SVE-2019-16158, S...

CVEs:CVE-2020-10832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20615

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x) and O(8.x) software. Attackers can bypass Factory Reset Protection (FRP) via SVoice T&C. The Samsung ID is SVE-2018-13547 (March 2019).

CVEs:CVE-2019-20615

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20598

Open SourceCoalition ESS < 30%LOW2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) software. Bixby leaks the keyboard's learned words, and the clipboard contents, via the lock screen. The Samsung IDs are SVE-2018-12896, SVE-2018-12897 (May 2019).

CVEs:CVE-2019-20598

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20569

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via the status bar. The Samsung ID is SVE-2019-15089 (September 2019).

CVEs:CVE-2019-20569

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20559

Open SourceCoalition ESS < 30%LOW2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Gallery allows viewing of photos on the lock screen. The Samsung ID is SVE-2019-15055 (October 2019).

CVEs:CVE-2019-20559

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20557

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via a SIM card by blocking the PUK code. The Samsung ID is SVE-2019-15262 (October 2019).

CVEs:CVE-2019-20557

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20554

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) software. Attackers can bypass Factory Reset Protection (FRP) via an external keyboard. The Samsung ID is SVE-2019-15164 (October 2019).

CVEs:CVE-2019-20554

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20540

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (Exynos chipsets) software. There is a buffer over-read and possible information leak in the core touch screen driver. The Samsung ID is SVE-2019-14942 (November 2019).

CVEs:CVE-2019-20540

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10855

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via AppTray. The Samsung ID is SVE-2019-16192 (January 2020).

CVEs:CVE-2020-10855

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20535

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) software. A connection to a new Bluetooth devices can be established from the lock screen. The Samsung ID is SVE-2019-15533 (December 2019).

CVEs:CVE-2019-20535

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20531

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi kernel drivers have an out-of-bounds Read. The Samsung IDs are SVE-2019-15692, SVE-2019-15693 (December 2019).

CVEs:CVE-2019-20531

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10840

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) (Exynos 9610 chipsets) software. There is a kernel pointer leak in the vipx driver. The Samsung ID is SVE-2019-16293 (February 2020).

CVEs:CVE-2020-10840

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20625

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with N(7.1) and O(8.x) (Exynos chipsets) software. The ion debugfs driver allows information disclosure. The Samsung ID is SVE-2018-13427 (February 2019).

CVEs:CVE-2019-20625

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20543

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. Attackers can bypass Factory Reset Protection (FRP) via SamsungPay mini. The Samsung ID is SVE-2019-15090 (November 2019).

CVEs:CVE-2019-20543

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0047

Open SourceCoalition ESS < 30%LOW2020-03-03

In setMasterMute of AudioService.java, there is a missing permission check. This could lead to local silencing of audio with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10...

CVEs:CVE-2020-0047

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20550

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x) (released in China and India) software. The S Secure app can access the content of a locked app without a password. The Samsung ID is SVE-2019-13805 (October 2019).

CVEs:CVE-2019-20550

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10846

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.x) and Q(10.x) software. Attackers can enable the OEM unlock feature on a KG-enrolled devices, leading to potentially unwanted binaries being downloaded. The Samsung ID is SVE-2019-16554 (Febru...

CVEs:CVE-2020-10846

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20575

Open SourceCoalition ESS < 30%MEDIUM2020-03-24

An issue was discovered on Samsung mobile devices with P(9.0) software. The WPA3 handshake feature allows a downgrade or dictionary attack. The Samsung ID is SVE-2019-14204 (August 2019).

CVEs:CVE-2019-20575

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2019-20533

Open SourceCoalition ESS < 30%LOW2020-03-24

An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) (released in China or India) software. The S Secure app can launch masked apps without a password. The Samsung ID is SVE-2019-13996 (December 2019).

CVEs:CVE-2019-20533

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0045

Open SourceCoalition ESS < 30%HIGH2020-03-03

In StatsService::command of StatsService.cpp, there is possible memory corruption due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2020-0045

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10845

Open SourceCoalition ESS < 30%CRITICAL2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. There is a race condition leading to a use-after-free in MTP. The Samsung ID is SVE-2019-16520 (February 2020).

CVEs:CVE-2020-10845

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10843

Open SourceCoalition ESS < 30%HIGH2020-03-24

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (S.LSI chipsets) software. There are race conditions in the hdcp2 driver. The Samsung ID is SVE-2019-16296 (February 2020).

CVEs:CVE-2020-10843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.