|
210671
|
7.8 |
HIGH
Local
|
google
|
android
|
In skb_headlen of /include/linux/skbuff.h, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges ne…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0430
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210672
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In l2tp_session_delete and related functions of l2tp_core.c, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with System execution privil…
|
CWE-787 CWE-416
Out-of-bounds Write Use After Free
|
CVE-2020-0429
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210673
|
6.4 |
MEDIUM
Local
|
google
|
android
|
In CamX code, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges required. User interaction is not needed fo…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-0428
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210674
|
5.5 |
MEDIUM
Local
|
google debian opensuse starwindsoftware
|
android debian_linux leap starwind_virtual_san
|
In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User inter…
|
CWE-125 CWE-416
Out-of-bounds Read Use After Free
|
CVE-2020-0427
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210675
|
6.7 |
MEDIUM
Local
|
google
|
android
|
In the FPC TrustZone fingerprint App, there is a possible invalid command handler due to an exposed test feature. This could lead to local escalation of privilege in the TEE, with System execution pr…
|
CWE-269
Improper Privilege Management
|
CVE-2020-0403
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210676
|
7.8 |
HIGH
Local
|
google
|
android
|
In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no ad…
|
CWE-1021 CWE-862
Improper Restriction of Rendered UI Layers or Frames Missing Authorization
|
CVE-2020-0387
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210677
|
4.4 |
MEDIUM
Local
|
google
|
android
|
In various functions in fscrypt_ice.c and related files in some implementations of f2fs encryption that use encryption hardware which only supports 32-bit IVs (Initialization Vectors), 64-bit IVs are…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2020-0407
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210678
|
5.5 |
MEDIUM
Local
|
google oracle
|
android communications_cloud_native_core_binding_support_function communications_cloud_native_core_policy communications_cloud_native_core_network_exposure_function
|
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional e…
|
CWE-269
Improper Privilege Management
|
CVE-2020-0404
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210679
|
7.8 |
HIGH
Local
|
google
|
android
|
In setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of privilege and granting spurious permissions with no additional ex…
|
CWE-862
Missing Authorization
|
CVE-2020-0401
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210680
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In showLimitedSimFunctionWarningNotification of NotificationMgr.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead to local information disclosure with User e…
|
NVD-CWE-noinfo
|
CVE-2020-0399
|
2024-11-21 13:53 |
2020-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|