|
210741
|
6.4 |
MEDIUM
Local
|
google opensuse
|
android leap
|
In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is no…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2020-0305
|
2024-11-21 13:53 |
2020-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210742
|
9.8 |
CRITICAL
Network
|
google
|
android
|
In crus_sp_shared_ioctl we first copy 4 bytes from userdata into "size" variable, and then use that variable as the size parameter for "copy_from_user", ending up overwriting memory following "crus_s…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0235
|
2024-11-21 13:53 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210743
|
7.8 |
HIGH
Local
|
google
|
android
|
In crus_afe_get_param of msm-cirrus-playback.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution pr…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0234
|
2024-11-21 13:53 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210744
|
9.8 |
CRITICAL
Network
|
google
|
android
|
Function abc_pcie_issue_dma_xfer_sync creates a transfer object, adds it to the session object then continues to work with it. A concurrent thread could retrieve created transfer object from the sess…
|
CWE-416
Use After Free
|
CVE-2020-0232
|
2024-11-21 13:53 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210745
|
9.8 |
CRITICAL
Network
|
google
|
android
|
This is an unbounded write into kernel global memory, via a user-controlled buffer size.Product: AndroidVersions: Android kernelAndroid ID: A-135130450
|
CWE-787
Out-of-bounds Write
|
CVE-2020-0223
|
2024-11-21 13:53 |
2020-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210746
|
7.5 |
HIGH
Network
|
intel
|
software_manager active_management_technology_firmware
|
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access.
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0597
|
2024-11-21 13:53 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210747
|
7.5 |
HIGH
Network
|
intel
|
active_management_technology_firmware service_manager
|
Improper input validation in DHCPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable informat…
|
CWE-20
Improper Input Validation
|
CVE-2020-0596
|
2024-11-21 13:53 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210748
|
9.8 |
CRITICAL
Network
|
intel
|
active_management_technology_firmware service_manager
|
Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privile…
|
CWE-416
Use After Free
|
CVE-2020-0595
|
2024-11-21 13:53 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210749
|
9.8 |
CRITICAL
Network
|
intel
|
active_management_technology_firmware service_manager
|
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of pri…
|
CWE-125
Out-of-bounds Read
|
CVE-2020-0594
|
2024-11-21 13:53 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210750
|
7.8 |
HIGH
Local
|
intel
|
server_platform_services
|
Improper initialization in subsystem for Intel(R) SPS versions before SPS_E3_04.01.04.109.0 and SPS_E3_04.08.04.070.0 may allow an authenticated user to potentially enable escalation of privilege and…
|
CWE-665
Improper Initialization
|
CVE-2020-0586
|
2024-11-21 13:53 |
2020-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|