|
211131
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no addit…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0225
|
2024-11-21 13:53 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211132
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In FastKeyAccumulator::GetKeysSlow of keys.cc, there is a possible out of bounds write due to type confusion. This could lead to remote code execution when processing a proxy configuration with no ad…
|
CWE-787 CWE-843
Out-of-bounds Write Type Confusion
|
CVE-2020-0224
|
2024-11-21 13:53 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211133
|
6.4 |
MEDIUM
Local
|
google opensuse
|
android leap
|
In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-0305
|
2024-11-21 13:53 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211134
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_s…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0235
|
2024-11-21 13:53 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211135
|
7.8 |
HIGH
Local
|
google
|
android
|
In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution pr…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0234
|
2024-11-21 13:53 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211136
|
9.8 |
CRITICAL
Network
|
google
|
android
|
Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread could retrieve created transfer object from the sess…
|
CWE-416
Use After Free
|
CVE-2020-0232
|
2024-11-21 13:53 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211137
|
9.8 |
CRITICAL
Network
|
google
|
android
|
This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0223
|
2024-11-21 13:53 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211138
|
7.5 |
HIGH
Network
|
intel
|
software_manager active_management_technology_firmware
|
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0597
|
2024-11-21 13:53 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211139
|
7.5 |
HIGH
Network
|
intel
|
active_management_technology_firmware service_manager
|
Improper input validation in DHCPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable informat…
|
CWE-20
Improper Input Validation
|
CVE-2020-0596
|
2024-11-21 13:53 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211140
|
9.8 |
CRITICAL
Network
|
intel
|
active_management_technology_firmware service_manager
|
Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privile…
|
CWE-416
Use After Free
|
CVE-2020-0595
|
2024-11-21 13:53 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|