CVE-2020-0 to CVE-2020-999
85 CVEs with public proof-of-concept exploits.
- CVE-2020-00012 PoCsIn getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of…
- CVE-2020-00041 PoCIn generateCrop of WallpaperManagerService.java, there is a possible sysui crash due to image exceeding maximum texture size. This could…
- CVE-2020-00061 PoCIn rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data.…
- CVE-2020-00092 PoCsIn calc_vm_may_flags of ashmem.c, there is a possible arbitrary write to shared memory due to a permissions bypass. This could lead to…
- CVE-2020-00141 PoCIt is possible for a malicious application to construct a TYPE_TOAST window manually and make that window clickable. This could lead to a…
- CVE-2020-002210 PoCsIn reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This…
- CVE-2020-00231 PoCIn setPhonebookAccessPermission of AdapterService.java, there is a possible disclosure of user contacts over bluetooth due to a missing…
- CVE-2020-00418 PoCsKEVIn binder_transaction of binder.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local…
- CVE-2020-00695 PoCsKEVIn the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization…
- CVE-2020-00744 PoCsIn verifyIntentFiltersIfNeeded of PackageManagerService.java, there is a possible settings bypass allowing an app to become the default…
- CVE-2020-00821 PoCIn ExternalVibration of ExternalVibration.java, there is a possible activation of an arbitrary intent due to unsafe deserialization. This…
- CVE-2020-00966 PoCsIn startActivities of ActivityStartController.java, there is a possible escalation of privilege due to a confused deputy. This could lead…
- CVE-2020-00975 PoCsIn various methods of PackageManagerService.java, there is a possible permission bypass due to a missing condition for system apps. This…
- CVE-2020-01081 PoCIn postNotification of ServiceRecord.java, there is a possible bypass of foreground process restrictions due to an uncaught exception.…
- CVE-2020-01131 PoCIn sendCaptureResult of Camera3OutputUtils.cpp, there is a possible out of bounds read due to a use after free. This could lead to local…
- CVE-2020-01148 PoCsIn onCreateSliceProvider of KeyguardSliceProvider.java, there is a possible confused deputy due to a PendingIntent error. This could lead…
- CVE-2020-01211 PoCIn updateUidProcState of AppOpsService.java, there is a possible permission bypass due to a logic error. This could lead to local…
- CVE-2020-01334 PoCsIn MockLocationAppPreferenceController.java, it is possible to mock the GPS location of the device due to a permissions bypass. This could…
- CVE-2020-01361 PoCIn multiple locations of Parcel.cpp, there is a possible out-of-bounds write due to an integer overflow. This could lead to local…
- CVE-2020-01371 PoCIn setIPv6AddrGenMode of NetworkManagementService.java, there is a possible bypass of networking permissions due to a missing permission…
- CVE-2020-01381 PoCIn get_element_attr_rsp of btif_rc.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote…
- CVE-2020-01551 PoCIn phNxpNciHal_send_ese_hal_cmd of phNxpNciHal_ext.cc, there is a possible out of bounds write due to a missing bounds check. This could…
- CVE-2020-01601 PoCIn setSyncSampleParams of SampleTable.cpp, there is possible resource exhaustion due to a missing bounds check. This could lead to remote…
- CVE-2020-01811 PoCIn exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to…
- CVE-2020-01831 PoCIn handleMessage of BluetoothManagerService, there is an incomplete reset. This could lead to local escalation of privilege with no…
- CVE-2020-01887 PoCsIn onCreatePermissionRequest of SettingsSliceProvider.java, there is a possible permissions bypass due to a PendingIntent error. This…
- CVE-2020-01981 PoCIn exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote…
- CVE-2020-02012 PoCsIn showSecurityFields of WifiConfigController.java there is a possible credential leak due to a confused deputy. This could lead to remote…
- CVE-2020-02031 PoCIn freeIsolatedUidLocked of ProcessList.java, there is a possible UID reuse due to improper cleanup. This could lead to local escalation…
- CVE-2020-02091 PoCIn multiple functions of AccountManager.java, there is a possible permissions bypass. This could lead to local escalation of privilege…
- CVE-2020-02151 PoCIn onCreate of ConfirmConnectActivity.java, there is a possible leak of Bluetooth information due to a permissions bypass. This could lead…
- CVE-2020-02181 PoCIn loadSoundModel and related functions of SoundTriggerHwService.cpp, there is possible out of bounds write due to a race condition. This…
- CVE-2020-02194 PoCsIn onCreate of SliceDeepLinkSpringBoard.java there is a possible insecure Intent. This could lead to local elevation of privilege with no…
- CVE-2020-02251 PoCIn a2dp_vendor_ldac_decoder_decode_packet of a2dp_vendor_ldac_decoder.cc, there is a possible out of bounds write due to a missing bounds…
- CVE-2020-02262 PoCsIn createWithSurfaceParent of Client.cpp, there is a possible out of bounds write due to type confusion. This could lead to local…
- CVE-2020-02401 PoCIn NewFixedDoubleArray of factory.cc, there is a possible out of bounds write due to an integer overflow. This could lead to remote code…
- CVE-2020-02411 PoCIn NuPlayerStreamListener of NuPlayerStreamListener.cpp, there is possible memory corruption due to a double free. This could lead to…
- CVE-2020-02422 PoCsIn reset of NuPlayerDriver.cpp, there is a possible use-after-free due to improper locking. This could lead to local escalation of…
- CVE-2020-02431 PoCIn clearPropValue of MediaAnalyticsItem.cpp, there is a possible use-after-free due to improper locking. This could lead to local…
- CVE-2020-02451 PoCIn DecodeFrameCombinedMode of combined_decode.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead…
- CVE-2020-03771 PoCIn gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to…
- CVE-2020-03801 PoCIn allocExcessBits of bitalloc.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code…
- CVE-2020-03811 PoCIn Parse_wave of eas_mdls.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote information…
- CVE-2020-03921 PoCIn getLayerDebugInfo of SurfaceFlinger.cpp, there is a possible code execution due to a double free. This could lead to local escalation…
- CVE-2020-03943 PoCsIn onCreate of BluetoothPairingDialog.java, there is a possible tapjacking vector due to an insecure default value. This could lead to…
- CVE-2020-04011 PoCIn setInstallerPackageName of PackageManagerService.java, there is a missing permission check. This could lead to local escalation of…
- CVE-2020-04091 PoCIn create of FileMap.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of…
- CVE-2020-04131 PoCIn gatt_process_read_by_type_rsp of gatt_cl.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to…
- CVE-2020-04162 PoCsIn multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead to local escalation…
- CVE-2020-04182 PoCsIn getPermissionInfosForGroup of Utils.java, there is a logic error. This could lead to local escalation of privilege with User execution…
- CVE-2020-04211 PoCIn appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error handling. This could lead to local…
- CVE-2020-04233 PoCsIn binder_release_work of binder.c, there is a possible use-after-free due to improper locking. This could lead to local escalation of…
- CVE-2020-04391 PoCIn generatePackageInfo of PackageManagerService.java, there is a possible permissions bypass due to an incorrect permission check. This…
- CVE-2020-04431 PoCIn LocaleList of LocaleList.java, there is a possible forced reboot due to an uncaught exception. This could lead to local denial of…
- CVE-2020-04511 PoCIn sbrDecoder_AssignQmfChannels2SbrChannels of sbrdecoder.cpp, there is a possible out of bounds write due to a heap buffer overflow. This…
- CVE-2020-04521 PoCIn exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote…
- CVE-2020-04533 PoCsIn updateNotification of BeamTransferManager.java, there is a possible permission bypass due to an unsafe PendingIntent. This could lead…
- CVE-2020-04581 PoCIn SPDIFEncoder::writeBurstBufferBytes and related methods of SPDIFEncoder.cpp, there is a possible out of bounds write due to an integer…
- CVE-2020-04631 PoCIn sdp_server_handle_client_req of sdp_server.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to…
- CVE-2020-04711 PoCIn reassemble_and_dispatch of packet_fragmenter.cc, there is a possible way to inject packets into an encrypted Bluetooth connection due…
- CVE-2020-05511 PoCLoad value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable…
- CVE-2020-05571 PoCInsecure inherited permissions in Intel(R) PROSet/Wireless WiFi products before version 21.70 on Windows 10 may allow an authenticated…
- CVE-2020-05681 PoCRace condition in the Intel(R) Driver and Support Assistant before version 20.1.5 may allow an authenticated user to potentially enable…
- CVE-2020-060136 PoCsKEVA spoofing vulnerability exists in the way Windows CryptoAPI (Crypt32.dll) validates Elliptic Curve Cryptography (ECC) certificates.An…
- CVE-2020-06094 PoCsA remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to…
- CVE-2020-06103 PoCsA remote code execution vulnerability exists in Windows Remote Desktop Gateway (RD Gateway) when an unauthenticated attacker connects to…
- CVE-2020-06188 PoCsKEVA remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka…
- CVE-2020-06241 PoCAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2020-06421 PoCAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2020-06464 PoCsKEVA remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.NET Framework…
- CVE-2020-06651 PoCAn elevation of privilege vulnerability exists in Active Directory Forest trusts due to a default setting that lets an attacker in the…
- CVE-2020-066811 PoCsAn elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory, aka 'Windows Kernel Elevation…
- CVE-2020-067410 PoCsKEVA remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer, aka…
- CVE-2020-06834 PoCsKEVAn elevation of privilege vulnerability exists in the Windows Installer when MSI packages process symbolic links, aka 'Windows Installer…
- CVE-2020-068832 PoCsKEVA remote code execution vulnerability exists in Microsoft Exchange software when the software fails to properly handle objects in memory,…
- CVE-2020-07281 PoCAn information vulnerability exists when Windows Modules Installer Service improperly discloses file information, aka 'Windows Modules…
- CVE-2020-07532 PoCsAn elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error…
- CVE-2020-07542 PoCsAn elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error…
- CVE-2020-07651 PoCAn information disclosure vulnerability exists in the Remote Desktop Connection Manager (RDCMan) application when it improperly parses XML…
- CVE-2020-07875 PoCsKEVAn elevation of privilege vulnerability exists when the Windows Background Intelligent Transfer Service (BITS) improperly handles symbolic…
- CVE-2020-079698 PoCsKEVA remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain…
- CVE-2020-08832 PoCsA remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory,…
- CVE-2020-08871 PoCAn elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka…
- CVE-2020-08902 PoCsWindows Hyper-V Denial of Service Vulnerability
- CVE-2020-09101 PoCA remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated…