Latest CVE Feed
-
5.5
MEDIUMCVE-2020-0396
In various places in Telephony, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVe... Read more
Affected Products : android- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0399
In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not need... Read more
Affected Products : android- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0295
In Telecom, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11An... Read more
Affected Products : android- Published: Sep. 18, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0307
In Settings, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11A... Read more
Affected Products : android- Published: Sep. 18, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-9258
HUAWEI P30 smartphone with versions earlier than 10.1.0.135(C00E135R2P11) have an improper input verification vulnerability. An attribution in a module is not set correctly and some verification is lacked. Attackers with local access can exploit this vuln... Read more
- Published: Jul. 10, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0365
In netd, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11... Read more
Affected Products : android- Published: Sep. 18, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-21244
An issue was discovered in FrontAccounting 2.4.7. There is a Directory Traversal vulnerability that can empty folder via admin/inst_lang.php.... Read more
Affected Products : frontaccounting- Published: Sep. 30, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-5986
NVIDIA Virtual GPU Manager contains a vulnerability in the vGPU plugin, in which an input data size is not validated, which may lead to tampering or denial of service. This affects vGPU version 8.x (prior to 8.5), version 10.x (prior to 10.4) and version ... Read more
Affected Products : virtual_gpu_manager- Published: Oct. 02, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0385
In Parse_insh of eas_mdls.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote information disclosure in the media extractor with no additional execution privileges needed. User interaction is needed for e... Read more
Affected Products : android- Published: Sep. 17, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-1903
An issue when unzipping docx, pptx, and xlsx documents in WhatsApp for iOS prior to v2.20.61 and WhatsApp Business for iOS prior to v2.20.61 could have resulted in an out-of-memory denial of service. This issue would have required the receiver to explicit... Read more
- Published: Oct. 06, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-8671
Insufficient control flow management in BIOS firmware 8th, 9th Generation Intel(R) Core(TM) Processors and Intel(R) Celeron(R) Processor 4000 Series may allow an authenticated user to potentially enable information disclosure via local access.... Read more
Affected Products : bios core_i5_8400 core_i5_8400t core_i5_8500 core_i5_8500t core_i5_8600 core_i5_8600k core_i5_8600t core_i5_9400 core_i5_9400f +39 more products- Published: Oct. 05, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-12933
A denial of service vulnerability exists in the D3DKMTEscape handler functionality of AMD ATIKMDAG.SYS (e.g. version 26.20.15029.27017). A specially crafted D3DKMTEscape API request can cause an out-of-bounds read in Windows OS kernel memory area. This vu... Read more
Affected Products : atikmdag.sys- Published: Oct. 13, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0398
In updateMwi of NotificationMgr.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Andro... Read more
Affected Products : android- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0400
In showDataRoamingNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploit... Read more
Affected Products : android- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-0410
In setNotification of SapServer.java, there is a possible permission bypass due to a PendingIntent error. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: Andro... Read more
Affected Products : android- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2020-6933
An improper input validation vulnerability in the UEM Core of BlackBerry UEM version(s) 12.13.0, 12.12.1a QF2 (and earlier), and 12.11.1 QF3 (and earlier) could allow an attacker to potentially cause a Denial of Service (DoS) of the UEM Core service.... Read more
- Published: Oct. 14, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-14713
Verifone MX900 series Pinpad Payment Terminals with OS 30251000 allow installation of unsigned packages.... Read more
- Published: Oct. 23, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-4468
This issue was addressed by removing additional entitlements. This issue is fixed in macOS Mojave 10.14.1, Security Update 2018-002 High Sierra, Security Update 2018-005 Sierra. A malicious application may be able to access restricted files.... Read more
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-8538
A denial of service issue was addressed with improved validation. This issue is fixed in watchOS 5.2, macOS Mojave 10.14.4, Security Update 2019-002 High Sierra, Security Update 2019-002 Sierra, iOS 12.2. Processing a maliciously crafted vcf file may lead... Read more
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2019-8582
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iCloud for Windows 7.12, tvOS 12.3, iTunes 12.9.5 for Windows, macOS Mojave 10.14.5, Security Update 2019-003 High Sierra, Security Update 2019-003 Sierra, iOS 12.3.... Read more
- Published: Oct. 27, 2020
- Modified: Nov. 21, 2024