Advisories
GoogleExploitedCISA KEV listedCRITICAL2020-06-09
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-20...
CVEs:CVE-2020-0986
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| windows_10_1507 |
affected |
microsoft |
— |
— |
| windows_10_1607 |
affected |
microsoft |
— |
— |
| windows_10_1709 |
affected |
microsoft |
— |
— |
| windows_10_1803 |
affected |
microsoft |
— |
— |
| windows_10_1809 |
affected |
microsoft |
— |
— |
| windows_10_1903 |
affected |
microsoft |
— |
— |
| windows_10_1909 |
affected |
microsoft |
— |
— |
| windows_10_2004 |
affected |
microsoft |
— |
— |
| windows_8.1 |
affected |
microsoft |
— |
— |
| windows_rt_8.1 |
affected |
microsoft |
— |
— |
| windows_server_1803 |
affected |
microsoft |
— |
— |
| windows_server_1903 |
affected |
microsoft |
— |
— |
| windows_server_1909 |
affected |
microsoft |
— |
— |
| windows_server_2004 |
affected |
microsoft |
— |
— |
| windows_server_2012 |
affected |
microsoft |
— |
— |
| windows_server_2016 |
affected |
microsoft |
— |
— |
| windows_server_2019 |
affected |
microsoft |
— |
— |
Project ZeroExploitedCISA KEV listed2020-06-09
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka 'Windows Kernel Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1237, CVE-2020-1246, CVE-2020-1262, CVE-2020-1264, CVE-2020-1266, CVE-2020-1269, CVE-2020-1273, CVE-2020-1274, CVE-2020-1275, CVE-2020-1276, CVE-2020-1307, CVE-2020-1316.
CVEs:CVE-2020-0986
GoogleExploitedCISA KEV listedHIGH2020-06-09
CVEs:CVE-2020-0986
GoogleExploitedCISA KEV listed2020-06-03
CVEs:CVE-2020-6453
GoogleExploitedCISA KEV listedHIGH2020-06-03
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6453
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceExploitedCISA KEV listedHIGH2020-06-03
DEBIAN-CVE-2020-6453
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Project ZeroExploitedCISA KEV listed2020-06-03
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6453
Open SourceWeaponized exploitCRITICAL2020-06-28
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.2 |
chromium |
— |
Open SourceWeaponized exploitCRITICAL2020-06-24
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP1 |
chromium |
— |
Open SourceWeaponized exploitCRITICAL2020-06-22
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
GoogleWeaponized exploitCRITICAL2020-06-16
Out of bounds write in V8 in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6507
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleWeaponized exploit2020-06-16
CVEs:CVE-2020-6507
GoogleActive exploitation (sightings)HIGH2020-06-16
Duplicate Advisory: possible DoS caused by malformed signature decoding in Pure-Python ECDSA
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| actionpack |
affected |
RubyGems |
actionpack |
— |
| activerecord-session_store |
affected |
RubyGems |
activerecord-session_store |
— |
| addressable |
affected |
RubyGems |
addressable |
— |
| aiohttp |
affected |
PyPI |
aiohttp |
— |
| aiohttp |
affected |
PyPI |
aiohttp |
— |
| com.google.guava:guava |
affected |
Maven |
com.google.guava:guava |
— |
| django |
affected |
PyPI |
django |
— |
| Django |
affected |
PyPI |
Django |
— |
| Django |
affected |
PyPI |
Django |
— |
| ecdsa |
affected |
PyPI |
ecdsa |
— |
| ecdsa |
affected |
PyPI |
ecdsa |
— |
| nokogiri |
affected |
RubyGems |
nokogiri |
— |
| puma |
affected |
RubyGems |
puma |
— |
| rake |
affected |
RubyGems |
rake |
— |
GoogleActive exploitation (sightings)HIGH2020-06-16
Duplicate Advisory: possible DoS caused by malformed signature decoding in Pure-Python ECDSA
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| ecdsa |
affected |
PyPI |
ecdsa |
— |
Open SourcePoC exploitCRITICAL2020-06-18
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP1 |
chromium |
— |
Open SourcePoC exploitCRITICAL2020-06-17
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
GooglePoC exploitHIGH2020-06-15
Denial of Service in Google Guava
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.googlecode.guava-osgi:guava-osgi |
affected |
Maven |
com.googlecode.guava-osgi:guava-osgi |
— |
| com.google.guava:guava |
affected |
Maven |
com.google.guava:guava |
— |
| com.google.guava:guava-jdk5 |
affected |
Maven |
com.google.guava:guava-jdk5 |
— |
| de.mhus.ports:vaadin-shared-deps |
affected |
Maven |
de.mhus.ports:vaadin-shared-deps |
— |
| org.hudsonci.lib.guava:guava |
affected |
Maven |
org.hudsonci.lib.guava:guava |
— |
| org.sonatype.sisu:sisu-guava |
affected |
Maven |
org.sonatype.sisu:sisu-guava |
— |
GooglePoC exploitHIGH2020-06-15
Denial of Service in Google Guava
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| com.googlecode.guava-osgi:guava-osgi |
affected |
Maven |
com.googlecode.guava-osgi:guava-osgi |
— |
| com.google.guava:guava |
affected |
Maven |
com.google.guava:guava |
— |
| com.google.guava:guava-jdk5 |
affected |
Maven |
com.google.guava:guava-jdk5 |
— |
| de.mhus.ports:vaadin-shared-deps |
affected |
Maven |
de.mhus.ports:vaadin-shared-deps |
— |
| druid |
affected |
chainguard |
druid |
— |
| druid |
affected |
wolfi |
druid |
— |
| elasticsearch-7 |
affected |
chainguard |
elasticsearch-7 |
— |
| hadoop-fips-3.3.6 |
affected |
chainguard |
hadoop-fips-3.3.6 |
— |
| org.hudsonci.lib.guava:guava |
affected |
Maven |
org.hudsonci.lib.guava:guava |
— |
| org.sonatype.sisu:sisu-guava |
affected |
Maven |
org.sonatype.sisu:sisu-guava |
— |
| spark-3.5 |
affected |
chainguard |
spark-3.5 |
— |
| spark-fips-3.5 |
affected |
chainguard |
spark-fips-3.5 |
— |
GooglePoC exploitHIGH2020-06-02
CVEs:CVE-2020-0198
Open SourcePoC exploitHIGH2020-06-02
In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: ...
CVEs:CVE-2020-0198
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| libexif |
affected |
libexif_project |
— |
— |
| ubuntu_linux |
affected |
canonical |
— |
— |
GooglePoC exploitCRITICAL2020-06-16
Insufficient policy enforcement in WebView in Google Chrome on Android prior to 83.0.4103.106 allowed a remote attacker to bypass site isolation via a crafted HTML page.
CVEs:CVE-2020-6506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GooglePoC exploitMEDIUM2020-06-16
Android WebView Universal Cross-site Scripting
CVEs:CVE-2020-6506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| react-native-webview |
affected |
npm |
react-native-webview |
— |
GooglePoC exploitMEDIUM2020-06-16
Android WebView Universal Cross-site Scripting
CVEs:CVE-2020-6506
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| react-native-webview |
affected |
npm |
react-native-webview |
— |
Open SourcePoC exploitHIGH2020-06-05
DEBIAN-CVE-2020-8555
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
Debian:14 |
kubernetes |
— |
| kubernetes |
affected |
Debian:11 |
kubernetes |
— |
| kubernetes |
affected |
Debian:12 |
kubernetes |
— |
| kubernetes |
affected |
Debian:13 |
kubernetes |
— |
Open SourcePoC exploitMEDIUM2020-06-04
Server Side Request Forgery (SSRF) in Kubernetes
CVEs:CVE-2020-8555
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| kubernetes |
affected |
k8s.io |
k8s.io/kubernetes |
— |
Open SourcePoC exploitHIGH2020-06-04
The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users to leak up to 500 bytes of arbit...
CVEs:CVE-2020-8555
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| kubernetes |
affected |
kubernetes |
— |
— |
GooglePoC exploitHIGH2020-06-02
CVEs:CVE-2020-0181
Open SourcePoC exploitHIGH2020-06-02
In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2020-0181
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| fedora |
affected |
fedoraproject |
— |
— |
| libexif |
affected |
libexif_project |
— |
— |
Open SourcePoC exploitHIGH2020-06-22
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| containerd |
affected |
openSUSE:Leap 15.1 |
containerd |
— |
| docker |
affected |
openSUSE:Leap 15.1 |
docker |
— |
| docker-runc |
affected |
openSUSE:Leap 15.1 |
docker-runc |
— |
| golang-github-docker-libnetwork |
affected |
openSUSE:Leap 15.1 |
golang-github-docker-libnetwork |
— |
Open SourcePoC exploitHIGH2020-06-18
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| containerd |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
containerd |
— |
| docker |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
docker |
— |
| docker-runc |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
docker-runc |
— |
| golang-github-docker-libnetwork |
affected |
SUSE:Linux Enterprise Module for Containers 12 |
golang-github-docker-libnetwork |
— |
Open SourcePoC exploitHIGH2020-06-18
Security update for containerd, docker, docker-runc, golang-github-docker-libnetwork
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| containerd |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP1 |
containerd |
— |
| docker |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP1 |
docker |
— |
| docker-runc |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP1 |
docker-runc |
— |
| golang-github-docker-libnetwork |
affected |
SUSE:Linux Enterprise Module for Containers 15 SP1 |
golang-github-docker-libnetwork |
— |
Open SourcePoC exploitMEDIUM2020-06-03
DEBIAN-CVE-2020-10749
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-github-containernetworking-plugins |
affected |
Debian:11 |
golang-github-containernetworking-plugins |
— |
| golang-github-containernetworking-plugins |
affected |
Debian:12 |
golang-github-containernetworking-plugins |
— |
| golang-github-containernetworking-plugins |
affected |
Debian:13 |
golang-github-containernetworking-plugins |
— |
| golang-github-containernetworking-plugins |
affected |
Debian:14 |
golang-github-containernetworking-plugins |
— |
Open SourcePoC exploitCRITICAL2020-06-18
Angular vulnerable to Cross-site Scripting
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
Open SourcePoC exploitCRITICAL2020-06-18
Angular vulnerable to Cross-site Scripting
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
Open SourcePoC exploitMEDIUM2020-06-08
Angular vulnerable to Cross-site Scripting
CVEs:CVE-2020-7676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
Open SourcePoC exploitMEDIUM2020-06-08
Angular vulnerable to Cross-site Scripting
CVEs:CVE-2020-7676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular |
affected |
npm |
angular |
— |
Open SourcePoC exploitCRITICAL2020-06-08
angular.js prior to 1.8.0 allows cross site scripting. The regex-based input HTML replacement may turn sanitized code into unsanitized one. Wrapping "<option>" elements in "<select>" ones changes parsing behavior, leading to possibly unsanitizing code.
CVEs:CVE-2020-7676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angularjs |
affected |
angularjs |
— |
— |
Open SourcePoC exploitCRITICAL2020-06-08
DEBIAN-CVE-2020-7676
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| angular.js |
affected |
Debian:11 |
angular.js |
— |
| angular.js |
affected |
Debian:13 |
angular.js |
— |
| angular.js |
affected |
Debian:14 |
angular.js |
— |
| angular.js |
affected |
Debian:12 |
angular.js |
— |
Open SourcePoC exploitHIGH2020-06-17
DEBIAN-CVE-2020-14040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| golang-golang-x-text |
affected |
Debian:11 |
golang-golang-x-text |
— |
| golang-golang-x-text |
affected |
Debian:12 |
golang-golang-x-text |
— |
| golang-golang-x-text |
affected |
Debian:13 |
golang-golang-x-text |
— |
| golang-golang-x-text |
affected |
Debian:14 |
golang-golang-x-text |
— |
Open SourcePoC exploitHIGH2020-06-17
golang.org/x/text Infinite loop
CVEs:CVE-2020-14040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| x/text |
affected |
golang.org |
golang.org/x/text |
— |
GooglePoC exploitHIGH2020-06-17
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decode...
CVEs:CVE-2020-14040
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| fedora |
affected |
fedoraproject |
— |
— |
| text |
affected |
golang |
— |
— |
GooglePoC exploitHIGH2020-06-02
CVEs:CVE-2020-0201
Open SourcePoC exploitCRITICAL2020-06-02
In showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2020-0201
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitCRITICAL2020-06-02
In get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution if bluetoothtbd were used, which it isn't in typical Android platforms, with no additional execution ...
CVEs:CVE-2020-0138
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0138
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0160
Open SourcePoC exploitHIGH2020-06-02
In setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Prod...
CVEs:CVE-2020-0160
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0192
Open SourcePoC exploitMEDIUM2020-06-02
In ih264d_decode_slice_thread of ih264d_thread_parse_decode.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is...
CVEs:CVE-2020-0192
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0162
Open SourcePoC exploitHIGH2020-06-02
In parseSampleAuxiliaryInformationOffsets of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is nee...
CVEs:CVE-2020-0162
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0113
Open SourcePoC exploitHIGH2020-06-02
In sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2020-0113
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2020-06-02
In onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead to local escalation of privilege that allows actions performed as the System UI, with no additional execution priv...
CVEs:CVE-2020-0114
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2020-06-02
CVEs:CVE-2020-0114
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0219
Open SourcePoC exploitHIGH2020-06-02
In onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: ...
CVEs:CVE-2020-0219
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0188
Open SourcePoC exploitHIGH2020-06-02
In onCreatePermissionRequest of SettingsSliceProvider.java, there is a possible permissions bypass due to a PendingIntent error. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for ...
CVEs:CVE-2020-0188
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2020-06-02
In handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10...
CVEs:CVE-2020-0183
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0183
Open SourcePoC exploitHIGH2020-06-02
In onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass. This could lead to local escalation of privilege that exposes a pairing Bluetooth MAC address with no additional execution privil...
CVEs:CVE-2020-0215
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitHIGH2020-06-02
CVEs:CVE-2020-0215
Open SourcePoC exploitMEDIUM2020-06-02
In updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local information disclosure of location data with User execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2020-0121
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploitLOW2020-06-02
CVEs:CVE-2020-0121
Open SourcePoC exploitHIGH2020-06-02
In multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not neede...
CVEs:CVE-2020-0136
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0136
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0155
Open SourcePoC exploitHIGH2020-06-02
In phNxpNciHal_send_ese_hal_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exp...
CVEs:CVE-2020-0155
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2020-06-02
In freeIsolatedUidLocked of ProcessList.java, there is a possible UID reuse due to improper cleanup. This could lead to local escalation of privilege between constrained processes with no additional execution privileges needed. User interaction is not ...
CVEs:CVE-2020-0203
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0203
Open SourcePoC exploitHIGH2020-06-02
In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...
CVEs:CVE-2020-0209
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0209
GooglePoC exploitHIGH2020-06-02
CVEs:CVE-2020-0137
Open SourcePoC exploitHIGH2020-06-02
In setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2020-0137
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourcePoC exploitHIGH2020-06-02
In MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for explo...
CVEs:CVE-2020-0133
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0133
Open SourcePoC exploitHIGH2020-06-02
In loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is no...
CVEs:CVE-2020-0218
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GooglePoC exploit2020-06-02
CVEs:CVE-2020-0218
Open SourceCoalition ESS < 30%HIGH2020-06-02
Istio 1.4.x before 1.4.9 and Istio 1.5.x before 1.5.4 contain the following vulnerability when telemetry v2 is enabled: by sending a specially crafted packet, an attacker could trigger a Null Pointer Exception resulting in a Denial of Service. This cou...
CVEs:CVE-2020-10739
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| istio |
affected |
istio |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-10739
GoogleCoalition ESS < 30%CRITICAL2020-06-03
Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2020-6493
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2020-06-03
CVEs:CVE-2020-6493
Open SourceCoalition ESS < 30%CRITICAL2020-06-03
DEBIAN-CVE-2020-6493
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In aes_cmac of aes_cmac.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution in the bluetooth server with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2020-0117
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-02
CVEs:CVE-2020-0117
GoogleCoalition ESS < 30%MEDIUM2020-06-03
CVEs:CVE-2020-6494
GoogleCoalition ESS < 30%MEDIUM2020-06-03
Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2020-6494
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-03
DEBIAN-CVE-2020-6494
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-03
Cryptographic Issues in ECK
CVEs:CVE-2020-7010
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| elastic/cloud-on-k8s |
affected |
github.com |
github.com/elastic/cloud-on-k8s |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-06-03
Elastic Cloud on Kubernetes (ECK) versions prior to 1.1.0 generate passwords using a weak random number generator. If an attacker is able to determine when the current Elastic Stack cluster was deployed they may be able to more easily brute force the E...
CVEs:CVE-2020-7010
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| elastic_cloud_on_kubernetes |
affected |
elastic |
— |
— |
GoogleCoalition ESS < 30%2020-06-03
CVEs:CVE-2020-6496
GoogleCoalition ESS < 30%CRITICAL2020-06-03
Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2020-6496
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports_sle |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| leap |
affected |
opensuse |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-06-03
DEBIAN-CVE-2020-6496
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0182
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitati...
CVEs:CVE-2020-0182
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2020-06-03
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVEs:CVE-2020-6495
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| backports |
affected |
opensuse |
— |
— |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-06-03
CVEs:CVE-2020-6495
Open SourceCoalition ESS < 30%CRITICAL2020-06-03
DEBIAN-CVE-2020-6495
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2020-06-16
Use after free in speech in Google Chrome prior to 83.0.4103.106 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
CVEs:CVE-2020-6505
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2020-06-16
CVEs:CVE-2020-6505
GoogleCoalition ESS < 30%MEDIUM2020-06-03
Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
CVEs:CVE-2020-6498
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-06-03
CVEs:CVE-2020-6498
Open SourceCoalition ESS < 30%MEDIUM2020-06-03
DEBIAN-CVE-2020-6498
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-05
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200007 (June 2020).
CVEs:CVE-2020-13839
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-05
CVEs:CVE-2020-13839
GoogleCoalition ESS < 30%MEDIUM2020-06-02
CVEs:CVE-2020-0213
Open SourceCoalition ESS < 30%HIGH2020-06-02
In hevcd_fmt_conv_420sp_to_420sp_av8 of ihevcd_fmt_conv_420sp_to_420sp.s, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User inter...
CVEs:CVE-2020-0213
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-06-02
In RW_T4tPresenceCheck of rw_t4t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.Product...
CVEs:CVE-2020-0217
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-02
CVEs:CVE-2020-0217
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0127
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In AudioStream::decode of AudioGroup.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the phone process with no additional execution privileges needed. User interaction is ne...
CVEs:CVE-2020-0127
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0176
Open SourceCoalition ESS < 30%HIGH2020-06-02
In avdt_msg_prs_rej of avdt_msg.cc, there is a possible out-of-bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2020-0176
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-06-29
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
SUSE:Package Hub 15 SP1 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2020-06-27
CVEs:CVE-2020-6509
GoogleCoalition ESS < 30%CRITICAL2020-06-27
Use after free in extensions in Google Chrome prior to 83.0.4103.116 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
CVEs:CVE-2020-6509
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-06-27
Security update for chromium
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
openSUSE:Leap 15.1 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2020-06-03
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI.
CVEs:CVE-2020-6497
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
| debian_linux |
affected |
debian |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-06-03
CVEs:CVE-2020-6497
Open SourceCoalition ESS < 30%CRITICAL2020-06-03
DEBIAN-CVE-2020-6497
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In addPacket of AMPEG4ElementaryAssembler, there is an out of bounds read due to an integer overflow. This could lead to remote information disclosure with no additional execution privileges required. User interaction is not needed for exploitation.Pro...
CVEs:CVE-2020-0128
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0128
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0140
Open SourceCoalition ESS < 30%HIGH2020-06-02
In rw_i93_sm_detect_ndef of rw_i93.c, there is a possible information disclosure due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2020-0140
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In rw_i93_sm_format of rw_i93.c, there is a possible information disclosure due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation....
CVEs:CVE-2020-0142
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0142
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0214
Open SourceCoalition ESS < 30%HIGH2020-06-02
In ce_t4t_process_select_file_cmd of ce_t4t.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2020-0214
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0191
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In ih264d_update_default_index_list() of ih264d_dpb_mgr.c, there is a possible out of bounds read due to a logic error. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for expl...
CVEs:CVE-2020-0191
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0193
Open SourceCoalition ESS < 30%HIGH2020-06-02
In ihevc_intra_pred_chroma_mode_3_to_9_av8 of ihevc_intra_pred_chroma_mode_3_to_9.s, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. ...
CVEs:CVE-2020-0193
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In Parse_lart of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVe...
CVEs:CVE-2020-0171
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0171
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0172
Open SourceCoalition ESS < 30%HIGH2020-06-02
In Parse_art of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVer...
CVEs:CVE-2020-0172
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0174
Open SourceCoalition ESS < 30%HIGH2020-06-02
In Parse_ptbl of eas_mdls.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVe...
CVEs:CVE-2020-0174
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In RTTTL_Event of eas_rtttl.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Android...
CVEs:CVE-2020-0169
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0169
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0170
Open SourceCoalition ESS < 30%HIGH2020-06-02
In IMY_Event of eas_imelody.c, there is possible resource exhaustion due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Android...
CVEs:CVE-2020-0170
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0173
Open SourceCoalition ESS < 30%HIGH2020-06-02
In Parse_lins of eas_mdls.c, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Androi...
CVEs:CVE-2020-0173
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0175
Open SourceCoalition ESS < 30%HIGH2020-06-02
In XMF_ReadNode of eas_xmf.c, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andro...
CVEs:CVE-2020-0175
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-03
CVEs:CVE-2020-6419
GoogleCoalition ESS < 30%CRITICAL2020-06-03
Out of bounds write in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2020-6419
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-06-03
DEBIAN-CVE-2020-6419
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0190
Open SourceCoalition ESS < 30%HIGH2020-06-02
In ideint_weave_blk of ideint_utils.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: ...
CVEs:CVE-2020-0190
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%MEDIUM2020-06-03
CVEs:CVE-2020-6503
GoogleCoalition ESS < 30%HIGH2020-06-03
Inappropriate implementation in accessibility in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2020-6503
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-03
DEBIAN-CVE-2020-6503
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
| chromium |
affected |
Debian:11 |
chromium |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0180
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In GetOpusHeaderBuffers() of OpusHeader.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitat...
CVEs:CVE-2020-0180
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In ihevcd_iquant_itrans_recon_ctb of ihevcd_iquant_itrans_recon_ctb.c and related functions, there is a possible information disclosure due to uninitialized data. This could lead to remote information disclosure with no additional execution privileges ...
CVEs:CVE-2020-0195
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0195
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0200
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In ReadLittleEndian of raw_bit_reader.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User interaction is nee...
CVEs:CVE-2020-0200
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In the DaalaBitReader constructor of entropy_decoder.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure in the media server with no additional execution privileges needed. User int...
CVEs:CVE-2020-0205
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0205
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0207
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In next_marker of jdmarker.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product:...
CVEs:CVE-2020-0207
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In SumCompoundHorizontalTaps of convolve_neon.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for expl...
CVEs:CVE-2020-0211
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0211
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0212
Open SourceCoalition ESS < 30%HIGH2020-06-02
In _onBufferDestroyed of InputBufferManager.cpp, there is a possible out of bounds read due to a use after free. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitatio...
CVEs:CVE-2020-0212
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In addOrUpdateNetworkInternal and related functions of WifiConfigManager.java, there is a possible man in the middle attack due to improper certificate validation. This could lead to remote information disclosure with no additional execution privileges...
CVEs:CVE-2020-0119
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0119
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0131
Open SourceCoalition ESS < 30%HIGH2020-06-02
In parseChunk of MPEG4Extractor.cpp, there is a possible out of bounds write due to incompletely initialized data. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Prod...
CVEs:CVE-2020-0131
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In impeg2_fmt_conv_yuv420p_to_yuv420sp_uv of impeg2_format_conv.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is neede...
CVEs:CVE-2020-0168
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0168
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0194
Open SourceCoalition ESS < 30%HIGH2020-06-02
In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exp...
CVEs:CVE-2020-0194
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-05
An issue was discovered on LG mobile devices with Android OS 9 and 10 (MTK chipsets). An AT command handler allows attackers to bypass intended access restrictions. The LG ID is LVE-SMP-200009 (June 2020).
CVEs:CVE-2020-13841
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-05
CVEs:CVE-2020-13841
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In nfa_hci_conn_cback of nfa_hci_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure via compromised device firmware with System execution privileges needed. User interaction i...
CVEs:CVE-2020-0157
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0157
GoogleCoalition ESS < 30%HIGH2020-06-05
CVEs:CVE-2020-13840
Open SourceCoalition ESS < 30%CRITICAL2020-06-05
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via an MTK AT command handler buffer overflow. The LG ID is LVE-SMP-200008 (June 2020).
CVEs:CVE-2020-13840
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-03
CVEs:CVE-2020-6499
GoogleCoalition ESS < 30%MEDIUM2020-06-03
Inappropriate implementation in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass AppCache security restrictions via a crafted HTML page.
CVEs:CVE-2020-6499
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-03
DEBIAN-CVE-2020-6499
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%HIGH2020-06-04
CVEs:CVE-2020-13832
Open SourceCoalition ESS < 30%CRITICAL2020-06-04
An issue was discovered on Samsung mobile devices with Q(10.0) (with TEEGRIS on Exynos chipsets) software. The Widevine Trustlet allows arbitrary code execution because of memory disclosure, The Samsung IDs are SVE-2020-17117, SVE-2020-17118, SVE-2020-...
CVEs:CVE-2020-13832
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-03
CVEs:CVE-2020-6500
GoogleCoalition ESS < 30%MEDIUM2020-06-03
Inappropriate implementation in interstitials in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
CVEs:CVE-2020-6500
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-03
DEBIAN-CVE-2020-6500
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%CRITICAL2020-06-03
Insufficient policy enforcement in CSP in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
CVEs:CVE-2020-6501
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-03
CVEs:CVE-2020-6501
Open SourceCoalition ESS < 30%CRITICAL2020-06-03
DEBIAN-CVE-2020-6501
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
GoogleCoalition ESS < 30%2020-06-03
CVEs:CVE-2020-6502
GoogleCoalition ESS < 30%MEDIUM2020-06-03
Incorrect implementation in permissions in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via a crafted HTML page.
CVEs:CVE-2020-6502
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-03
DEBIAN-CVE-2020-6502
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In parseChunk of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product...
CVEs:CVE-2020-0161
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0161
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0163
Open SourceCoalition ESS < 30%HIGH2020-06-02
In parseSampleAuxiliaryInformationSizes of MPEG4Extractor.cpp, there is possible resource exhaustion due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is neede...
CVEs:CVE-2020-0163
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0184
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In ihevcd_ref_list() of ihevcd_ref_list.c, there is a possible infinite loop due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product:...
CVEs:CVE-2020-0184
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0189
Open SourceCoalition ESS < 30%HIGH2020-06-02
In ihevcd_decode() of ihevcd_decode.c, there is possible resource exhaustion due to an infinite loop. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: Andro...
CVEs:CVE-2020-0189
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-03
CVEs:CVE-2020-6504
GoogleCoalition ESS < 30%CRITICAL2020-06-03
Insufficient policy enforcement in notifications in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass notification restrictions via a crafted HTML page.
CVEs:CVE-2020-6504
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-06-03
DEBIAN-CVE-2020-6504
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chromium |
affected |
Debian:11 |
chromium |
— |
| chromium |
affected |
Debian:12 |
chromium |
— |
| chromium |
affected |
Debian:13 |
chromium |
— |
| chromium |
affected |
Debian:14 |
chromium |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In OutputBuffersArray::realloc of CCodecBuffers.cpp, there is a possible heap disclosure due to a race condition. This could lead to remote information disclosure with System execution privileges needed. User interaction is needed for exploitation.Prod...
CVEs:CVE-2020-0141
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0141
Open SourceCoalition ESS < 30%HIGH2020-06-04
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. HWRResProvider allows path traversal for data exposure. The Samsung ID is SVE-2020-16954 (June 2020).
CVEs:CVE-2020-13836
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-04
CVEs:CVE-2020-13836
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0179
Open SourceCoalition ESS < 30%HIGH2020-06-02
In doSendObjectInfo of MtpServer.cpp, there is a possible path traversal attack due to insufficient input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is required for expl...
CVEs:CVE-2020-0179
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-04
CVEs:CVE-2020-13833
Open SourceCoalition ESS < 30%CRITICAL2020-06-04
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) software. The system area allows arbitrary file overwrites via a symlink attack. The Samsung ID is SVE-2020-17183 (June 2020).
CVEs:CVE-2020-13833
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-06-04
An issue was discovered on Samsung mobile devices with O(8.x) and P(9.0) (Exynos 7570 chipsets) software. The Trustonic Kinibi component allows arbitrary memory mapping. The Samsung ID is SVE-2019-16665 (June 2020).
CVEs:CVE-2020-13831
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-04
CVEs:CVE-2020-13831
GoogleCoalition ESS < 30%HIGH2020-06-02
CVEs:CVE-2020-0223
Open SourceCoalition ESS < 30%CRITICAL2020-06-02
This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450
CVEs:CVE-2020-0223
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%CRITICAL2020-06-02
Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread could retrieve created transfer object from the session object and delete it using abc_pcie_dma_user_xfer...
CVEs:CVE-2020-0232
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-02
CVEs:CVE-2020-0232
GoogleCoalition ESS < 30%HIGH2020-06-02
CVEs:CVE-2020-0235
Open SourceCoalition ESS < 30%CRITICAL2020-06-02
In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_sp_hdr". "crus_sp_hdr" is a static variable, of type "...
CVEs:CVE-2020-0235
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-04
CVEs:CVE-2020-13830
Open SourceCoalition ESS < 30%HIGH2020-06-04
An issue was discovered on Samsung mobile devices with P(9.0) software. One UI HOME logging can leak information. The Samsung ID is SVE-2019-16382 (June 2020).
CVEs:CVE-2020-13830
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0167
Open SourceCoalition ESS < 30%HIGH2020-06-02
In load of ResourceTypes.cpp, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: Androi...
CVEs:CVE-2020-0167
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-04
CVEs:CVE-2020-13835
Open SourceCoalition ESS < 30%CRITICAL2020-06-04
An issue was discovered on Samsung mobile devices with O(8.x) (with TEEGRIS) software. The Gatekeeper Trustlet allows a brute-force attack on user credentials. The Samsung ID is SVE-2020-16908 (June 2020).
CVEs:CVE-2020-13835
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In onHandleIntent of TraceService.java, there is a possible bypass of developer settings requirements for capturing system traces due to a missing permission check. This could lead to local escalation of privilege with no additional execution privilege...
CVEs:CVE-2020-0202
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-02
CVEs:CVE-2020-0202
GoogleCoalition ESS < 30%CRITICAL2020-06-22
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using the membership to the "lxd" group, an attacker can...
CVEs:CVE-2020-8933
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| guest-oslogin |
affected |
google |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-22
CVEs:CVE-2020-8933
Google CloudCoalition ESS < 30%2020-06-19
Date published: 2020-06-19 (High)
Google CloudCoalition ESS < 30%2020-06-19
GCP-COMPUTE-20200619 (High)
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0159
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In rw_mfc_writeBlock of rw_mfc.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation.Product: An...
CVEs:CVE-2020-0159
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-04
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. Attackers can disable the SEAndroid protection mechanism in the RKP. The Samsung ID is SVE-2019-15998 (June 2020).
CVEs:CVE-2020-13829
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-04
CVEs:CVE-2020-13829
Open SourceCoalition ESS < 30%HIGH2020-06-04
An issue was discovered on Samsung mobile devices with O(8.x), P(9.0), and Q(10.0) (with TEEGRIS) software. Secure Folder does not properly restrict use of Android Debug Bridge (adb) for arbitrary installations. The Samsung ID is SVE-2020-17369 (June 2...
CVEs:CVE-2020-13834
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-04
CVEs:CVE-2020-13834
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0204
Open SourceCoalition ESS < 30%HIGH2020-06-02
In InstallPackage of package.cpp, there is a possible bypass of a signature check due to a Time of Check/Time of Use condition. This could lead to local escalation of privilege by allowing a bypass of the initial zip file signature check for an OS upda...
CVEs:CVE-2020-0204
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%CRITICAL2020-06-22
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "adm" group, users with th...
CVEs:CVE-2020-8903
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| guest-oslogin |
affected |
google |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-22
CVEs:CVE-2020-8903
GoogleCoalition ESS < 30%CRITICAL2020-06-22
A vulnerability in Google Cloud Platform's guest-oslogin versions between 20190304 and 20200507 allows a user that is only granted the role "roles/compute.osLogin" to escalate privileges to root. Using their membership to the "docker" group, an attacke...
CVEs:CVE-2020-8907
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| guest-oslogin |
affected |
google |
— |
— |
| leap |
affected |
opensuse |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-22
CVEs:CVE-2020-8907
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0196
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In RegisterNotificationResponse::GetEvent of register_notification_packet.cc, there is a possible abort due to improper input validation. This could lead to remote denial of service of the Bluetooth service, over Bluetooth, with no additional execution...
CVEs:CVE-2020-0196
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0132
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In BnAAudioService::onTransact of IAAudioService.cpp, there is a possible out of bounds read due to unsafe deserialization. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed f...
CVEs:CVE-2020-0132
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In phNciNfc_RecvMfResp of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for expl...
CVEs:CVE-2020-0216
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0216
Open SourceCoalition ESS < 30%HIGH2020-06-02
In addListener of RegionSamplingThread.cpp, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploi...
CVEs:CVE-2020-0118
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0118
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In checkSystemLocationAccess of LocationAccessPolicy.java, there is a possible bypass of user profile isolation due to a permissions bypass. This could lead to local information disclosure with no additional execution privileges needed. User interactio...
CVEs:CVE-2020-0116
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0116
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0164
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In phNxpNciHal_NfcDep_cmd_ext of phNxpNciHal_NfcDepSWPrio.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed ...
CVEs:CVE-2020-0164
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0210
Open SourceCoalition ESS < 30%HIGH2020-06-02
In removeSharedAccountAsUser of AccountManager.java, there is a possible permissions bypass to a confused deputy. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation.Pr...
CVEs:CVE-2020-0210
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default handler for arbitrary domains. This could lead to local escalation of privilege with User execution privileges neede...
CVEs:CVE-2020-0115
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-02
CVEs:CVE-2020-0115
Open SourceCoalition ESS < 30%HIGH2020-06-02
In phNxpNciHal_NfcDep_cmd_ext of phNxpNciHal_NfcDepSWPrio.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege via compromised device firmware with System execution privileges neede...
CVEs:CVE-2020-0165
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%HIGH2020-06-02
CVEs:CVE-2020-0165
GoogleCoalition ESS < 30%HIGH2020-06-02
CVEs:CVE-2020-0233
Open SourceCoalition ESS < 30%HIGH2020-06-02
In main of main.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...
CVEs:CVE-2020-0233
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0153
Open SourceCoalition ESS < 30%HIGH2020-06-02
In phNxpNciHal_write_ext of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2020-0153
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In engineSetMode of BaseBlockCipher.java, there is a possible incorrect cryptographic algorithm chosen due to an incomplete comparison. This could lead to local information disclosure with no additional execution privileges needed. User interaction is ...
CVEs:CVE-2020-0187
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0187
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In getAllConfigFlags of SettingsProvider.cpp, there is a possible illegal read due to a missing permission check. This could lead to local information disclosure of config flags with no additional execution privileges needed. User interaction is not ne...
CVEs:CVE-2020-0178
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0178
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0124
Open SourceCoalition ESS < 30%HIGH2020-06-02
In markBootComplete of InstalldNativeService.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploi...
CVEs:CVE-2020-0124
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0129
Open SourceCoalition ESS < 30%HIGH2020-06-02
In SetData of btm_ble_multi_adv.cc, there is a possible out-of-bound write due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitatio...
CVEs:CVE-2020-0129
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0150
Open SourceCoalition ESS < 30%HIGH2020-06-02
In rw_t3t_message_set_block_list of rw_t3t.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for ex...
CVEs:CVE-2020-0150
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0166
Open SourceCoalition ESS < 30%HIGH2020-06-02
In multiple functions of URI.java, there is a possible escalation of privilege due to missing validation in the parceling of URI information. This could lead to a local escalation of privilege with no additional execution privileges needed. User intera...
CVEs:CVE-2020-0166
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0186
Open SourceCoalition ESS < 30%HIGH2020-06-02
In hal_fd_init of hal_fd.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: An...
CVEs:CVE-2020-0186
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0234
Open SourceCoalition ESS < 30%HIGH2020-06-02
In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for e...
CVEs:CVE-2020-0234
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0120
Open SourceCoalition ESS < 30%HIGH2020-06-02
In notifyErrorForPendingRequests of QCamera3HWI.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed ...
CVEs:CVE-2020-0120
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0197
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In InitDataParser::parsePssh of InitDataParser.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for...
CVEs:CVE-2020-0197
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0208
Open SourceCoalition ESS < 30%HIGH2020-06-02
In multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersi...
CVEs:CVE-2020-0208
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0144
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In btm_proc_sp_req_evt of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is not...
CVEs:CVE-2020-0144
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%HIGH2020-06-02
In btu_hcif_mode_change_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction ...
CVEs:CVE-2020-0149
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0149
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0152
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In avb_vbmeta_image_verify of avb_vbmeta_image.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2020-0152
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%LOW2020-06-04
An issue was discovered on Samsung mobile devices with Q(10.0) software. The Lockscreen feature does not block Quick Panel access to Music Share. The Samsung ID is SVE-2020-17145 (June 2020).
CVEs:CVE-2020-13837
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-04
CVEs:CVE-2020-13837
Open SourceCoalition ESS < 30%HIGH2020-06-02
In NDEF_MsgValidate of ndef_utils.c, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure if a malformed NFC tag is provided by the firmware. System execution privileges are needed and user ...
CVEs:CVE-2020-0139
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0139
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0143
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In nfa_dm_ndef_find_next_handler of nfa_dm_ndef.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure of heap data via compromised device firmware with System execution privileges neede...
CVEs:CVE-2020-0143
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0145
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In btm_simple_pair_complete of btm_sec.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction i...
CVEs:CVE-2020-0145
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0146
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In btu_hcif_hardware_error_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interacti...
CVEs:CVE-2020-0146
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0147
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In btu_hcif_esco_connection_chg_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User inte...
CVEs:CVE-2020-0147
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In btu_hcif_pin_code_request_evt, btu_hcif_link_key_request_evt, and btu_hcif_link_key_notification_evt of btu_hcif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure via compromise...
CVEs:CVE-2020-0148
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0148
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0151
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In avb_vbmeta_image_verify of avb_vbmeta_image.c there is a possible out of bounds read due to a missing bounds check. This could lead to a local information disclosure with System execution privileges needed. User interaction is not needed for exploit...
CVEs:CVE-2020-0151
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0154
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In nci_proc_core_rsp of nci_hrcv.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure via compromised device firmware with System execution privileges needed. User interaction is n...
CVEs:CVE-2020-0154
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In nfc_ncif_proc_t3t_polling_ntf of nfc_ncif.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2020-0158
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0158
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In mediadrm, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions:...
CVEs:CVE-2020-0125
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0125
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0134
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Prod...
CVEs:CVE-2020-0134
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In NxpNfc::ioctl of NxpNfc.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Androi...
CVEs:CVE-2020-0156
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0156
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0185
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In avrc_pars_browsing_cmd of avrc_pars_tg.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for explo...
CVEs:CVE-2020-0185
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0177
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In connect() of PanService.java, there is a possible permissions bypass. This could lead to local escalation of privilege to change network connection settings with no additional execution privileges needed. User interaction is not needed for exploitat...
CVEs:CVE-2020-0177
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In dump of RollbackManagerServiceImpl.java, there is a possible backup metadata exposure due to a missing permission check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for expl...
CVEs:CVE-2020-0135
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0135
Open SourceCoalition ESS < 30%HIGH2020-06-05
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). A dangerous AT command was made available even though it is unused. The LG ID is LVE-SMP-200010 (June 2020).
CVEs:CVE-2020-13842
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-05
CVEs:CVE-2020-13842
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0206
Open SourceCoalition ESS < 30%MEDIUM2020-06-02
In the settings app, there is a possible app crash due to improper input validation. This could lead to local denial of service of the Settings app with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidV...
CVEs:CVE-2020-0206
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%LOW2020-06-04
CVEs:CVE-2020-13838
Open SourceCoalition ESS < 30%LOW2020-06-04
An issue was discovered on Samsung mobile devices with P(9.0) and Q(10.0) software. The DeX Lockscreen feature does not block access to Quick Panel and notifications. The Samsung ID is SVE-2020-17187 (June 2020).
CVEs:CVE-2020-13838
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
Open SourceCoalition ESS < 30%MEDIUM2020-06-05
An issue was discovered on LG mobile devices with Android OS software before 2020-06-01. Local users can cause a denial of service because checking of the userdata partition is mishandled. The LG ID is LVE-SMP-200014 (June 2020).
CVEs:CVE-2020-13843
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-05
CVEs:CVE-2020-13843
Open SourceCoalition ESS < 30%HIGH2020-06-02
In multiple functions in DrmPlugin.cpp, there is a possible use after free due to a race condition. This could lead to local code execution with System execution privileges required. User interaction is not needed for exploitation.Product: AndroidVersi...
CVEs:CVE-2020-0126
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleCoalition ESS < 30%2020-06-02
CVEs:CVE-2020-0126
GoogleCoalition ESS < 30%LOW2020-06-02
CVEs:CVE-2020-0199
Open SourceCoalition ESS < 30%HIGH2020-06-02
In TimeCheck::TimeCheckThread::threadLoop of TimeCheck.cpp, there is a possible use-after-free due to a race condition. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploita...
CVEs:CVE-2020-0199
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| android |
affected |
google |
— |
— |
GoogleEPSS <= 49%HIGH2020-06-03
Bad cast in CSS in Google Chrome prior to 11.0.0.0 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVEs:CVE-2011-1805
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%2020-06-03
CVEs:CVE-2011-1805
GoogleEPSS <= 49%CRITICAL2020-06-03
Insufficient policy enforcement in V8 in Google Chrome prior to 14.0.0.0 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
CVEs:CVE-2011-2863
Affected products
| Product | Status | Vendor | Package | Ecosystem |
| chrome |
affected |
google |
— |
— |
GoogleEPSS <= 49%2020-06-03
CVEs:CVE-2011-2863