Google Security Advisories · June 2020 — Google Security Advisories
346 advisories 186 CVEs 7 EXPLOITED

GCVE / Google Cloud / Chrome / Android / Project Zero / OSS for 2020-06. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 7 are already weaponised in the wild.

What would you fix first?

The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.

Advisories

CVE-2020-0986

GoogleExploitedCISA KEV listedCRITICAL2020-06-09

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-20...

CVEs:CVE-2020-0986

Affected products

ProductStatusVendorPackageEcosystem
windows_10_1507 affected microsoft
windows_10_1607 affected microsoft
windows_10_1709 affected microsoft
windows_10_1803 affected microsoft
windows_10_1809 affected microsoft
windows_10_1903 affected microsoft
windows_10_1909 affected microsoft
windows_10_2004 affected microsoft
windows_8.1 affected microsoft
windows_rt_8.1 affected microsoft
windows_server_1803 affected microsoft
windows_server_1903 affected microsoft
windows_server_1909 affected microsoft
windows_server_2004 affected microsoft
windows_server_2012 affected microsoft
windows_server_2016 affected microsoft
windows_server_2019 affected microsoft
Upstream advisory

CVE-2020-0986

Project ZeroExploitedCISA KEV listed2020-06-09

An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.

CVEs:CVE-2020-0986

Upstream advisory

CVE-2020-6453

GoogleExploitedCISA KEV listedHIGH2020-06-03

Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6453

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6453

Open SourceExploitedCISA KEV listedHIGH2020-06-03

DEBIAN-CVE-2020-6453

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6453

Project ZeroExploitedCISA KEV listed2020-06-03

Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6453

Upstream advisory

openSUSE-SU-2020:0893-1

Open SourceWeaponized exploitCRITICAL2020-06-28

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.2 chromium
Upstream advisory

openSUSE-SU-2020:0856-1

Open SourceWeaponized exploitCRITICAL2020-06-24

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:0845-1

Open SourceWeaponized exploitCRITICAL2020-06-22

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2020-6507

GoogleWeaponized exploitCRITICAL2020-06-16

Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6507

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

GHSA-2mrj-435v-c2cr

GoogleActive exploitation (sightings)HIGH2020-06-16

Duplicate Advisory: possible DoS caused by malformed signature decoding in Pure-Python ECDSA

Affected products

ProductStatusVendorPackageEcosystem
actionpack affected RubyGems actionpack
activerecord-session_store affected RubyGems activerecord-session_store
addressable affected RubyGems addressable
aiohttp affected PyPI aiohttp
aiohttp affected PyPI aiohttp
com.google.guava:guava affected Maven com.google.guava:guava
django affected PyPI django
Django affected PyPI Django
Django affected PyPI Django
ecdsa affected PyPI ecdsa
ecdsa affected PyPI ecdsa
nokogiri affected RubyGems nokogiri
puma affected RubyGems puma
rake affected RubyGems rake
Upstream advisory

GHSA-2mrj-435v-c2cr

GoogleActive exploitation (sightings)HIGH2020-06-16

Duplicate Advisory: possible DoS caused by malformed signature decoding in Pure-Python ECDSA

Affected products

ProductStatusVendorPackageEcosystem
ecdsa affected PyPI ecdsa
Upstream advisory

openSUSE-SU-2020:0832-1

Open SourcePoC exploitCRITICAL2020-06-18

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

openSUSE-SU-2020:0823-1

Open SourcePoC exploitCRITICAL2020-06-17

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

GHSA-mvr2-9pj6-7w5j

GooglePoC exploitHIGH2020-06-15

Denial of Service in Google Guava

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.guava-osgi:guava-osgi affected Maven com.googlecode.guava-osgi:guava-osgi
com.google.guava:guava affected Maven com.google.guava:guava
com.google.guava:guava-jdk5 affected Maven com.google.guava:guava-jdk5
de.mhus.ports:vaadin-shared-deps affected Maven de.mhus.ports:vaadin-shared-deps
org.hudsonci.lib.guava:guava affected Maven org.hudsonci.lib.guava:guava
org.sonatype.sisu:sisu-guava affected Maven org.sonatype.sisu:sisu-guava
Upstream advisory

GHSA-mvr2-9pj6-7w5j

GooglePoC exploitHIGH2020-06-15

Denial of Service in Google Guava

Affected products

ProductStatusVendorPackageEcosystem
com.googlecode.guava-osgi:guava-osgi affected Maven com.googlecode.guava-osgi:guava-osgi
com.google.guava:guava affected Maven com.google.guava:guava
com.google.guava:guava-jdk5 affected Maven com.google.guava:guava-jdk5
de.mhus.ports:vaadin-shared-deps affected Maven de.mhus.ports:vaadin-shared-deps
druid affected chainguard druid
druid affected wolfi druid
elasticsearch-7 affected chainguard elasticsearch-7
hadoop-fips-3.3.6 affected chainguard hadoop-fips-3.3.6
org.hudsonci.lib.guava:guava affected Maven org.hudsonci.lib.guava:guava
org.sonatype.sisu:sisu-guava affected Maven org.sonatype.sisu:sisu-guava
spark-3.5 affected chainguard spark-3.5
spark-fips-3.5 affected chainguard spark-fips-3.5
Upstream advisory

CVE-2020-0198

Open SourcePoC exploitHIGH2020-06-02

In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: ...

CVEs:CVE-2020-0198

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
fedora affected fedoraproject
libexif affected libexif_project
ubuntu_linux affected canonical
Upstream advisory

CVE-2020-6506

GooglePoC exploitCRITICAL2020-06-16

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.

CVEs:CVE-2020-6506

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-6506

GooglePoC exploitMEDIUM2020-06-16

Android WebView Universal Cross-site Scripting

CVEs:CVE-2020-6506

Affected products

ProductStatusVendorPackageEcosystem
react-native-webview affected npm react-native-webview
Upstream advisory

CVE-2020-6506

GooglePoC exploitMEDIUM2020-06-16

Android WebView Universal Cross-site Scripting

CVEs:CVE-2020-6506

Affected products

ProductStatusVendorPackageEcosystem
react-native-webview affected npm react-native-webview
Upstream advisory

DEBIAN-CVE-2020-8555

Open SourcePoC exploitHIGH2020-06-05

DEBIAN-CVE-2020-8555

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected Debian:14 kubernetes
kubernetes affected Debian:11 kubernetes
kubernetes affected Debian:12 kubernetes
kubernetes affected Debian:13 kubernetes
Upstream advisory

CVE-2020-8555

Open SourcePoC exploitMEDIUM2020-06-04

Server Side Request Forgery (SSRF) in Kubernetes

CVEs:CVE-2020-8555

Affected products

ProductStatusVendorPackageEcosystem
kubernetes affected k8s.io k8s.io/kubernetes
Upstream advisory

CVE-2020-8555

Open SourcePoC exploitHIGH2020-06-04

The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbit...

CVEs:CVE-2020-8555

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
kubernetes affected kubernetes
Upstream advisory

CVE-2020-0181

Open SourcePoC exploitHIGH2020-06-02

In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2020-0181

Affected products

ProductStatusVendorPackageEcosystem
android affected google
fedora affected fedoraproject
libexif affected libexif_project
Upstream advisory

openSUSE-SU-2020:0846-1

Open SourcePoC exploitHIGH2020-06-22

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected openSUSE:Leap 15.1 containerd
docker affected openSUSE:Leap 15.1 docker
docker-runc affected openSUSE:Leap 15.1 docker-runc
golang-github-docker-libnetwork affected openSUSE:Leap 15.1 golang-github-docker-libnetwork
Upstream advisory

SUSE-SU-2020:1664-1

Open SourcePoC exploitHIGH2020-06-18

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Linux Enterprise Module for Containers 12 containerd
docker affected SUSE:Linux Enterprise Module for Containers 12 docker
docker-runc affected SUSE:Linux Enterprise Module for Containers 12 docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 12 golang-github-docker-libnetwork
Upstream advisory

SUSE-SU-2020:1657-1

Open SourcePoC exploitHIGH2020-06-18

Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork

Affected products

ProductStatusVendorPackageEcosystem
containerd affected SUSE:Linux Enterprise Module for Containers 15 SP1 containerd
docker affected SUSE:Linux Enterprise Module for Containers 15 SP1 docker
docker-runc affected SUSE:Linux Enterprise Module for Containers 15 SP1 docker-runc
golang-github-docker-libnetwork affected SUSE:Linux Enterprise Module for Containers 15 SP1 golang-github-docker-libnetwork
Upstream advisory

DEBIAN-CVE-2020-10749

Open SourcePoC exploitMEDIUM2020-06-03

DEBIAN-CVE-2020-10749

Affected products

ProductStatusVendorPackageEcosystem
golang-github-containernetworking-plugins affected Debian:11 golang-github-containernetworking-plugins
golang-github-containernetworking-plugins affected Debian:12 golang-github-containernetworking-plugins
golang-github-containernetworking-plugins affected Debian:13 golang-github-containernetworking-plugins
golang-github-containernetworking-plugins affected Debian:14 golang-github-containernetworking-plugins
Upstream advisory

GHSA-mhp6-pxh8-r675

Open SourcePoC exploitCRITICAL2020-06-18

Angular vulnerable to Cross-site Scripting

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

GHSA-mhp6-pxh8-r675

Open SourcePoC exploitCRITICAL2020-06-18

Angular vulnerable to Cross-site Scripting

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2020-7676

Open SourcePoC exploitMEDIUM2020-06-08

Angular vulnerable to Cross-site Scripting

CVEs:CVE-2020-7676

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2020-7676

Open SourcePoC exploitMEDIUM2020-06-08

Angular vulnerable to Cross-site Scripting

CVEs:CVE-2020-7676

Affected products

ProductStatusVendorPackageEcosystem
angular affected npm angular
Upstream advisory

CVE-2020-7676

Open SourcePoC exploitCRITICAL2020-06-08

angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.

CVEs:CVE-2020-7676

Affected products

ProductStatusVendorPackageEcosystem
angularjs affected angularjs
Upstream advisory

DEBIAN-CVE-2020-7676

Open SourcePoC exploitCRITICAL2020-06-08

DEBIAN-CVE-2020-7676

Affected products

ProductStatusVendorPackageEcosystem
angular.js affected Debian:11 angular.js
angular.js affected Debian:13 angular.js
angular.js affected Debian:14 angular.js
angular.js affected Debian:12 angular.js
Upstream advisory

DEBIAN-CVE-2020-14040

Open SourcePoC exploitHIGH2020-06-17

DEBIAN-CVE-2020-14040

Affected products

ProductStatusVendorPackageEcosystem
golang-golang-x-text affected Debian:11 golang-golang-x-text
golang-golang-x-text affected Debian:12 golang-golang-x-text
golang-golang-x-text affected Debian:13 golang-golang-x-text
golang-golang-x-text affected Debian:14 golang-golang-x-text
Upstream advisory

CVE-2020-14040

Open SourcePoC exploitHIGH2020-06-17

golang.org/x/text Infinite loop

CVEs:CVE-2020-14040

Affected products

ProductStatusVendorPackageEcosystem
x/text affected golang.org golang.org/x/text
Upstream advisory

CVE-2020-14040

GooglePoC exploitHIGH2020-06-17

The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decode...

CVEs:CVE-2020-14040

Affected products

ProductStatusVendorPackageEcosystem
fedora affected fedoraproject
text affected golang
Upstream advisory

CVE-2020-0201

Open SourcePoC exploitCRITICAL2020-06-02

In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2020-0201

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0138

Open SourcePoC exploitCRITICAL2020-06-02

In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typical Android platforms, with no additional execution ...

CVEs:CVE-2020-0138

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0160

Open SourcePoC exploitHIGH2020-06-02

In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Prod...

CVEs:CVE-2020-0160

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0192

Open SourcePoC exploitMEDIUM2020-06-02

In ih264d_decode_slice_thread of ih264d_thread_parse_decode.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is...

CVEs:CVE-2020-0192

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0162

Open SourcePoC exploitHIGH2020-06-02

In parseSampleAuxiliaryInformationOffsets of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is nee...

CVEs:CVE-2020-0162

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0113

Open SourcePoC exploitHIGH2020-06-02

In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2020-0113

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0114

Open SourcePoC exploitHIGH2020-06-02

In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution priv...

CVEs:CVE-2020-0114

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0219

Open SourcePoC exploitHIGH2020-06-02

In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...

CVEs:CVE-2020-0219

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0188

Open SourcePoC exploitHIGH2020-06-02

In onCreatePermissionRequest of SettingsSliceProvider.java, there is a possible permissions bypass due to a PendingIntent error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for ...

CVEs:CVE-2020-0188

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0183

Open SourcePoC exploitHIGH2020-06-02

In handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10...

CVEs:CVE-2020-0183

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0215

Open SourcePoC exploitHIGH2020-06-02

In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass. This could lead to local escalation of privilege that exposes a pairing Bluetooth MAC address with no additional execution privil...

CVEs:CVE-2020-0215

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0121

Open SourcePoC exploitMEDIUM2020-06-02

In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2020-0121

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0136

Open SourcePoC exploitHIGH2020-06-02

In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not neede...

CVEs:CVE-2020-0136

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0155

Open SourcePoC exploitHIGH2020-06-02

In phNxpNciHal_send_ese_hal_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exp...

CVEs:CVE-2020-0155

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0203

Open SourcePoC exploitHIGH2020-06-02

In freeIsolatedUidLocked of ProcessList.java, there is a possible UID reuse due to improper cleanup. This could lead to local escalation of privilege between constrained processes with no additional execution privileges needed. User interaction is not ...

CVEs:CVE-2020-0203

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0209

Open SourcePoC exploitHIGH2020-06-02

In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...

CVEs:CVE-2020-0209

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0137

Open SourcePoC exploitHIGH2020-06-02

In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2020-0137

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0133

Open SourcePoC exploitHIGH2020-06-02

In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for explo...

CVEs:CVE-2020-0133

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0218

Open SourcePoC exploitHIGH2020-06-02

In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...

CVEs:CVE-2020-0218

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-10739

Open SourceCoalition ESS < 30%HIGH2020-06-02

Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: by sending a specially crafted packet, an attacker could trigger a Null Pointer Exception resulting in a Denial of Service. This cou...

CVEs:CVE-2020-10739

Affected products

ProductStatusVendorPackageEcosystem
istio affected istio
Upstream advisory

CVE-2020-6493

GoogleCoalition ESS < 30%CRITICAL2020-06-03

Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6493

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6493

Open SourceCoalition ESS < 30%CRITICAL2020-06-03

DEBIAN-CVE-2020-6493

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0117

Open SourceCoalition ESS < 30%HIGH2020-06-02

In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2020-0117

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6494

GoogleCoalition ESS < 30%MEDIUM2020-06-03

Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2020-6494

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6494

Open SourceCoalition ESS < 30%MEDIUM2020-06-03

DEBIAN-CVE-2020-6494

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-7010

Open SourceCoalition ESS < 30%HIGH2020-06-03

Cryptographic Issues in ECK

CVEs:CVE-2020-7010

Affected products

ProductStatusVendorPackageEcosystem
elastic/cloud-on-k8s affected github.com github.com/elastic/cloud-on-k8s
Upstream advisory

CVE-2020-7010

Open SourceCoalition ESS < 30%CRITICAL2020-06-03

Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the E...

CVEs:CVE-2020-7010

Affected products

ProductStatusVendorPackageEcosystem
elastic_cloud_on_kubernetes affected elastic
Upstream advisory

CVE-2020-6496

GoogleCoalition ESS < 30%CRITICAL2020-06-03

Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6496

Affected products

ProductStatusVendorPackageEcosystem
backports_sle affected opensuse
chrome affected google
debian_linux affected debian
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6496

Open SourceCoalition ESS < 30%CRITICAL2020-06-03

DEBIAN-CVE-2020-6496

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0182

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...

CVEs:CVE-2020-0182

Affected products

ProductStatusVendorPackageEcosystem
android affected google
debian_linux affected debian
Upstream advisory

CVE-2020-6495

GoogleCoalition ESS < 30%CRITICAL2020-06-03

Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVEs:CVE-2020-6495

Affected products

ProductStatusVendorPackageEcosystem
backports affected opensuse
chrome affected google
debian_linux affected debian
leap affected opensuse
Upstream advisory

DEBIAN-CVE-2020-6495

Open SourceCoalition ESS < 30%CRITICAL2020-06-03

DEBIAN-CVE-2020-6495

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6505

GoogleCoalition ESS < 30%CRITICAL2020-06-16

Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

CVEs:CVE-2020-6505

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2020-6498

GoogleCoalition ESS < 30%MEDIUM2020-06-03

Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

CVEs:CVE-2020-6498

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2020-6498

Open SourceCoalition ESS < 30%MEDIUM2020-06-03

DEBIAN-CVE-2020-6498

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-13839

Open SourceCoalition ESS < 30%HIGH2020-06-05

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200007 (June 2020).

CVEs:CVE-2020-13839

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0213

Open SourceCoalition ESS < 30%HIGH2020-06-02

In hevcd_fmt_conv_420sp_to_420sp_av8 of ihevcd_fmt_conv_420sp_to_420sp.s, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User inter...

CVEs:CVE-2020-0213

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0217

Open SourceCoalition ESS < 30%CRITICAL2020-06-02

In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product...

CVEs:CVE-2020-0217

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0127

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the phone process with no additional execution privileges needed. User interaction is ne...

CVEs:CVE-2020-0127

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0176

Open SourceCoalition ESS < 30%HIGH2020-06-02

In avdt_msg_prs_rej of avdt_msg.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2020-0176

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

openSUSE-SU-2020:0902-1

Open SourceCoalition ESS < 30%CRITICAL2020-06-29

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected SUSE:Package Hub 15 SP1 chromium
Upstream advisory

CVE-2020-6509

GoogleCoalition ESS < 30%CRITICAL2020-06-27

Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

CVEs:CVE-2020-6509

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

openSUSE-SU-2020:0887-1

Open SourceCoalition ESS < 30%CRITICAL2020-06-27

Security update for chromium

Affected products

ProductStatusVendorPackageEcosystem
chromium affected openSUSE:Leap 15.1 chromium
Upstream advisory

CVE-2020-6497

GoogleCoalition ESS < 30%CRITICAL2020-06-03

Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI.

CVEs:CVE-2020-6497

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
debian_linux affected debian
Upstream advisory

DEBIAN-CVE-2020-6497

Open SourceCoalition ESS < 30%CRITICAL2020-06-03

DEBIAN-CVE-2020-6497

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0128

Open SourceCoalition ESS < 30%HIGH2020-06-02

In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges required. User interaction is not needed for exploitation.Pro...

CVEs:CVE-2020-0128

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0140

Open SourceCoalition ESS < 30%HIGH2020-06-02

In rw_i93_sm_detect_ndef of rw_i93.c, there is a possible information disclosure due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2020-0140

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0142

Open SourceCoalition ESS < 30%HIGH2020-06-02

In rw_i93_sm_format of rw_i93.c, there is a possible information disclosure due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....

CVEs:CVE-2020-0142

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0214

Open SourceCoalition ESS < 30%HIGH2020-06-02

In ce_t4t_process_select_file_cmd of ce_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2020-0214

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0191

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In ih264d_update_default_index_list() of ih264d_dpb_mgr.c, there is a possible out of bounds read due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for expl...

CVEs:CVE-2020-0191

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0193

Open SourceCoalition ESS < 30%HIGH2020-06-02

In ihevc_intra_pred_chroma_mode_3_to_9_av8 of ihevc_intra_pred_chroma_mode_3_to_9.s, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. ...

CVEs:CVE-2020-0193

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0171

Open SourceCoalition ESS < 30%HIGH2020-06-02

In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVe...

CVEs:CVE-2020-0171

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0172

Open SourceCoalition ESS < 30%HIGH2020-06-02

In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVer...

CVEs:CVE-2020-0172

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0174

Open SourceCoalition ESS < 30%HIGH2020-06-02

In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVe...

CVEs:CVE-2020-0174

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0169

Open SourceCoalition ESS < 30%HIGH2020-06-02

In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Android...

CVEs:CVE-2020-0169

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0170

Open SourceCoalition ESS < 30%HIGH2020-06-02

In IMY_Event of eas_imelody.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Android...

CVEs:CVE-2020-0170

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0173

Open SourceCoalition ESS < 30%HIGH2020-06-02

In Parse_lins of eas_mdls.c, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Androi...

CVEs:CVE-2020-0173

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0175

Open SourceCoalition ESS < 30%HIGH2020-06-02

In XMF_ReadNode of eas_xmf.c, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andro...

CVEs:CVE-2020-0175

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6419

GoogleCoalition ESS < 30%CRITICAL2020-06-03

Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2020-6419

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6419

Open SourceCoalition ESS < 30%CRITICAL2020-06-03

DEBIAN-CVE-2020-6419

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:11 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0190

Open SourceCoalition ESS < 30%HIGH2020-06-02

In ideint_weave_blk of ideint_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: ...

CVEs:CVE-2020-0190

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6503

GoogleCoalition ESS < 30%HIGH2020-06-03

Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2020-6503

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6503

Open SourceCoalition ESS < 30%HIGH2020-06-03

DEBIAN-CVE-2020-6503

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
chromium affected Debian:11 chromium
Upstream advisory

CVE-2020-0180

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In GetOpusHeaderBuffers() of OpusHeader.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitat...

CVEs:CVE-2020-0180

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0195

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges ...

CVEs:CVE-2020-0195

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0200

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In ReadLittleEndian of raw_bit_reader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is nee...

CVEs:CVE-2020-0200

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0205

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User int...

CVEs:CVE-2020-0205

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0207

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:...

CVEs:CVE-2020-0207

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0211

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In SumCompoundHorizontalTaps of convolve_neon.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for expl...

CVEs:CVE-2020-0211

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0212

Open SourceCoalition ESS < 30%HIGH2020-06-02

In _onBufferDestroyed of InputBufferManager.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitatio...

CVEs:CVE-2020-0212

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0119

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges...

CVEs:CVE-2020-0119

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0131

Open SourceCoalition ESS < 30%HIGH2020-06-02

In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely initialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Prod...

CVEs:CVE-2020-0131

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0168

Open SourceCoalition ESS < 30%HIGH2020-06-02

In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv of impeg2_format_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is neede...

CVEs:CVE-2020-0168

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0194

Open SourceCoalition ESS < 30%HIGH2020-06-02

In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exp...

CVEs:CVE-2020-0194

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13841

Open SourceCoalition ESS < 30%HIGH2020-06-05

An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command handler allows attackers to bypass intended access restrictions. The LG ID is LVE-SMP-200009 (June 2020).

CVEs:CVE-2020-13841

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0157

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In nfa_hci_conn_cback of nfa_hci_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure via compromised device firmware with System execution privileges needed. User interaction i...

CVEs:CVE-2020-0157

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13840

Open SourceCoalition ESS < 30%CRITICAL2020-06-05

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command handler buffer overflow. The LG ID is LVE-SMP-200008 (June 2020).

CVEs:CVE-2020-13840

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6499

GoogleCoalition ESS < 30%MEDIUM2020-06-03

Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppCache security restrictions via a crafted HTML page.

CVEs:CVE-2020-6499

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6499

Open SourceCoalition ESS < 30%MEDIUM2020-06-03

DEBIAN-CVE-2020-6499

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-13832

Open SourceCoalition ESS < 30%CRITICAL2020-06-04

An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) software. The Widevine Trustlet allows arbitrary code execution because of memory disclosure, The Samsung IDs are SVE-2020-17117, SVE-2020-17118, SVE-2020-...

CVEs:CVE-2020-13832

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6500

GoogleCoalition ESS < 30%MEDIUM2020-06-03

Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

CVEs:CVE-2020-6500

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6500

Open SourceCoalition ESS < 30%MEDIUM2020-06-03

DEBIAN-CVE-2020-6500

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6501

GoogleCoalition ESS < 30%CRITICAL2020-06-03

Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.

CVEs:CVE-2020-6501

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6501

Open SourceCoalition ESS < 30%CRITICAL2020-06-03

DEBIAN-CVE-2020-6501

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-6502

GoogleCoalition ESS < 30%MEDIUM2020-06-03

Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.

CVEs:CVE-2020-6502

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6502

Open SourceCoalition ESS < 30%MEDIUM2020-06-03

DEBIAN-CVE-2020-6502

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0161

Open SourceCoalition ESS < 30%HIGH2020-06-02

In parseChunk of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product...

CVEs:CVE-2020-0161

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0163

Open SourceCoalition ESS < 30%HIGH2020-06-02

In parseSampleAuxiliaryInformationSizes of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is neede...

CVEs:CVE-2020-0163

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0184

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In ihevcd_ref_list() of ihevcd_ref_list.c, there is a possible infinite loop due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product:...

CVEs:CVE-2020-0184

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0189

Open SourceCoalition ESS < 30%HIGH2020-06-02

In ihevcd_decode() of ihevcd_decode.c, there is possible resource exhaustion due to an infinite loop. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andro...

CVEs:CVE-2020-0189

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-6504

GoogleCoalition ESS < 30%CRITICAL2020-06-03

Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page.

CVEs:CVE-2020-6504

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

DEBIAN-CVE-2020-6504

Open SourceCoalition ESS < 30%CRITICAL2020-06-03

DEBIAN-CVE-2020-6504

Affected products

ProductStatusVendorPackageEcosystem
chromium affected Debian:11 chromium
chromium affected Debian:12 chromium
chromium affected Debian:13 chromium
chromium affected Debian:14 chromium
Upstream advisory

CVE-2020-0141

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In OutputBuffersArray::realloc of CCodecBuffers.cpp, there is a possible heap disclosure due to a race condition. This could lead to remote information disclosure with System execution privileges needed. User interaction is needed for exploitation.Prod...

CVEs:CVE-2020-0141

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13836

Open SourceCoalition ESS < 30%HIGH2020-06-04

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020).

CVEs:CVE-2020-13836

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0179

Open SourceCoalition ESS < 30%HIGH2020-06-02

In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is required for expl...

CVEs:CVE-2020-0179

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13833

Open SourceCoalition ESS < 30%CRITICAL2020-06-04

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).

CVEs:CVE-2020-13833

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13831

Open SourceCoalition ESS < 30%CRITICAL2020-06-04

An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic Kinibi component allows arbitrary memory mapping. The Samsung ID is SVE-2019-16665 (June 2020).

CVEs:CVE-2020-13831

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0223

Open SourceCoalition ESS < 30%CRITICAL2020-06-02

This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450

CVEs:CVE-2020-0223

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0232

Open SourceCoalition ESS < 30%CRITICAL2020-06-02

Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread could retrieve created transfer object from the session object and delete it using abc_pcie_dma_user_xfer...

CVEs:CVE-2020-0232

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0235

Open SourceCoalition ESS < 30%CRITICAL2020-06-02

In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "...

CVEs:CVE-2020-0235

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13830

Open SourceCoalition ESS < 30%HIGH2020-06-04

An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020).

CVEs:CVE-2020-13830

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0167

Open SourceCoalition ESS < 30%HIGH2020-06-02

In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Androi...

CVEs:CVE-2020-0167

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13835

Open SourceCoalition ESS < 30%CRITICAL2020-06-04

An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).

CVEs:CVE-2020-13835

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0202

Open SourceCoalition ESS < 30%HIGH2020-06-02

In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privilege...

CVEs:CVE-2020-0202

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8933

GoogleCoalition ESS < 30%CRITICAL2020-06-22

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can...

CVEs:CVE-2020-8933

Affected products

ProductStatusVendorPackageEcosystem
guest-oslogin affected google
leap affected opensuse
Upstream advisory

CVE-2020-0159

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In rw_mfc_writeBlock of rw_mfc.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: An...

CVEs:CVE-2020-0159

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13829

Open SourceCoalition ESS < 30%HIGH2020-06-04

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can disable the SEAndroid protection mechanism in the RKP. The Samsung ID is SVE-2019-15998 (June 2020).

CVEs:CVE-2020-13829

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13834

Open SourceCoalition ESS < 30%HIGH2020-06-04

An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict use of Android Debug Bridge (adb) for arbitrary installations. The Samsung ID is SVE-2020-17369 (June 2...

CVEs:CVE-2020-13834

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0204

Open SourceCoalition ESS < 30%HIGH2020-06-02

In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use condition. This could lead to local escalation of privilege by allowing a bypass of the initial zip file signature check for an OS upda...

CVEs:CVE-2020-0204

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-8903

GoogleCoalition ESS < 30%CRITICAL2020-06-22

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with th...

CVEs:CVE-2020-8903

Affected products

ProductStatusVendorPackageEcosystem
guest-oslogin affected google
leap affected opensuse
Upstream advisory

CVE-2020-8907

GoogleCoalition ESS < 30%CRITICAL2020-06-22

A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "docker" group, an attacke...

CVEs:CVE-2020-8907

Affected products

ProductStatusVendorPackageEcosystem
guest-oslogin affected google
leap affected opensuse
Upstream advisory

CVE-2020-0196

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could lead to remote denial of service of the Bluetooth service, over Bluetooth, with no additional execution...

CVEs:CVE-2020-0196

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0132

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...

CVEs:CVE-2020-0132

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0216

Open SourceCoalition ESS < 30%HIGH2020-06-02

In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for expl...

CVEs:CVE-2020-0216

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0118

Open SourceCoalition ESS < 30%HIGH2020-06-02

In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploi...

CVEs:CVE-2020-0118

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0116

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interactio...

CVEs:CVE-2020-0116

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0164

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In phNxpNciHal_NfcDep_cmd_ext of phNxpNciHal_NfcDepSWPrio.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed ...

CVEs:CVE-2020-0164

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0210

Open SourceCoalition ESS < 30%HIGH2020-06-02

In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Pr...

CVEs:CVE-2020-0210

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0115

Open SourceCoalition ESS < 30%HIGH2020-06-02

In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges neede...

CVEs:CVE-2020-0115

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0165

Open SourceCoalition ESS < 30%HIGH2020-06-02

In phNxpNciHal_NfcDep_cmd_ext of phNxpNciHal_NfcDepSWPrio.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege via compromised device firmware with System execution privileges neede...

CVEs:CVE-2020-0165

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0233

Open SourceCoalition ESS < 30%HIGH2020-06-02

In main of main.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...

CVEs:CVE-2020-0233

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0153

Open SourceCoalition ESS < 30%HIGH2020-06-02

In phNxpNciHal_write_ext of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2020-0153

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0187

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In engineSetMode of BaseBlockCipher.java, there is a possible incorrect cryptographic algorithm chosen due to an incomplete comparison. This could lead to local information disclosure with no additional execution privileges needed. User interaction is ...

CVEs:CVE-2020-0187

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0178

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This could lead to local information disclosure of config flags with no additional execution privileges needed. User interaction is not ne...

CVEs:CVE-2020-0178

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0124

Open SourceCoalition ESS < 30%HIGH2020-06-02

In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...

CVEs:CVE-2020-0124

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0129

Open SourceCoalition ESS < 30%HIGH2020-06-02

In SetData of btm_ble_multi_adv.cc, there is a possible out-of-bound write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...

CVEs:CVE-2020-0129

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0150

Open SourceCoalition ESS < 30%HIGH2020-06-02

In rw_t3t_message_set_block_list of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...

CVEs:CVE-2020-0150

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0166

Open SourceCoalition ESS < 30%HIGH2020-06-02

In multiple functions of URI.java, there is a possible escalation of privilege due to missing validation in the parceling of URI information. This could lead to a local escalation of privilege with no additional execution privileges needed. User intera...

CVEs:CVE-2020-0166

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0186

Open SourceCoalition ESS < 30%HIGH2020-06-02

In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: An...

CVEs:CVE-2020-0186

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0234

Open SourceCoalition ESS < 30%HIGH2020-06-02

In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...

CVEs:CVE-2020-0234

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0120

Open SourceCoalition ESS < 30%HIGH2020-06-02

In notifyErrorForPendingRequests of QCamera3HWI.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...

CVEs:CVE-2020-0120

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0197

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In InitDataParser::parsePssh of InitDataParser.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...

CVEs:CVE-2020-0197

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0208

Open SourceCoalition ESS < 30%HIGH2020-06-02

In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...

CVEs:CVE-2020-0208

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0144

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In btm_proc_sp_req_evt of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not...

CVEs:CVE-2020-0144

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0149

Open SourceCoalition ESS < 30%HIGH2020-06-02

In btu_hcif_mode_change_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction ...

CVEs:CVE-2020-0149

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0152

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In avb_vbmeta_image_verify of avb_vbmeta_image.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2020-0152

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13837

Open SourceCoalition ESS < 30%LOW2020-06-04

An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Panel access to Music Share. The Samsung ID is SVE-2020-17145 (June 2020).

CVEs:CVE-2020-13837

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0139

Open SourceCoalition ESS < 30%HIGH2020-06-02

In NDEF_MsgValidate of ndef_utils.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malformed NFC tag is provided by the firmware. System execution privileges are needed and user ...

CVEs:CVE-2020-0139

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0143

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In nfa_dm_ndef_find_next_handler of nfa_dm_ndef.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of heap data via compromised device firmware with System execution privileges neede...

CVEs:CVE-2020-0143

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0145

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In btm_simple_pair_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction i...

CVEs:CVE-2020-0145

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0146

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In btu_hcif_hardware_error_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interacti...

CVEs:CVE-2020-0146

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0147

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In btu_hcif_esco_connection_chg_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User inte...

CVEs:CVE-2020-0147

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0148

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In btu_hcif_pin_code_request_evt, btu_hcif_link_key_request_evt, and btu_hcif_link_key_notification_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromise...

CVEs:CVE-2020-0148

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0151

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In avb_vbmeta_image_verify of avb_vbmeta_image.c there is a possible out of bounds read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploit...

CVEs:CVE-2020-0151

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0154

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In nci_proc_core_rsp of nci_hrcv.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is n...

CVEs:CVE-2020-0154

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0158

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In nfc_ncif_proc_t3t_polling_ntf of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2020-0158

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0125

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...

CVEs:CVE-2020-0125

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0134

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...

CVEs:CVE-2020-0134

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0156

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In NxpNfc::ioctl of NxpNfc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Androi...

CVEs:CVE-2020-0156

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0185

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...

CVEs:CVE-2020-0185

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0177

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privilege to change network connection settings with no additional execution privileges needed. User interaction is not needed for exploitat...

CVEs:CVE-2020-0177

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0135

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for expl...

CVEs:CVE-2020-0135

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13842

Open SourceCoalition ESS < 30%HIGH2020-06-05

An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (June 2020).

CVEs:CVE-2020-13842

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0206

Open SourceCoalition ESS < 30%MEDIUM2020-06-02

In the settings app, there is a possible app crash due to improper input validation. This could lead to local denial of service of the Settings app with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...

CVEs:CVE-2020-0206

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13838

Open SourceCoalition ESS < 30%LOW2020-06-04

An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020).

CVEs:CVE-2020-13838

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-13843

Open SourceCoalition ESS < 30%MEDIUM2020-06-05

An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial of service because checking of the userdata partition is mishandled. The LG ID is LVE-SMP-200014 (June 2020).

CVEs:CVE-2020-13843

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0126

Open SourceCoalition ESS < 30%HIGH2020-06-02

In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local code execution with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersi...

CVEs:CVE-2020-0126

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2020-0199

Open SourceCoalition ESS < 30%HIGH2020-06-02

In TimeCheck::TimeCheckThread::threadLoop of TimeCheck.cpp, there is a possible use-after-free due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...

CVEs:CVE-2020-0199

Affected products

ProductStatusVendorPackageEcosystem
android affected google
Upstream advisory

CVE-2011-1805

GoogleEPSS <= 49%HIGH2020-06-03

Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

CVEs:CVE-2011-1805

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

CVE-2011-2863

GoogleEPSS <= 49%CRITICAL2020-06-03

Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.

CVEs:CVE-2011-2863

Affected products

ProductStatusVendorPackageEcosystem
chrome affected google
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.