CVEs from 2020

4,010 normalized CVEs published or assigned in this year.

Total
4,010
critical
critical 194
high
high 479
medium
medium 679
low
low 57
% Critical
4.8%
% with KEV
3.6%
% with exploit
4.0%

Top products

  • banking_digital_experience 30
  • retail_xstore_point_of_service 28
  • primavera_unifier 27
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 10
  • communications_network_charging_and_control 10
  • communications_contacts_server 9
  • agile_plm 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-6829 medium 5.5 When performing EC scalar point multiplication, the wNAF point multiplication algorithm was used; which leaked partial information about the nonce used during signature generation. Given an electro-m…
CVE-2020-25715 medium 5.5 Moderate: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update
CVE-2020-28630 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-35628 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->…
CVE-2020-28632 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-0499 medium 5.5 In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional exe…
CVE-2020-28629 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-26558 medium 5.5 Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authe…
CVE-2020-35630 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-35478 medium 5.5 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki …
CVE-2020-28628 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-36149 medium 5.5 Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protec…
CVE-2020-28627 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-27748 medium 5.5 A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderb…
CVE-2020-24977 medium 5.5 GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
CVE-2020-13357 medium 5.5 multiple issues in gitlab
CVE-2020-20446 medium 5.5 FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aacpsy.c, which allows a remote malicious user to cause a Denial of Service.
CVE-2020-35499 medium 5.5 A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when usin…
CVE-2020-29074 medium 5.5 scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
CVE-2020-28622 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-28631 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-25669 medium 5.5 A vulnerability was found in the Linux Kernel where the function sunkbd_reinit having been scheduled by sunkbd_interrupt before sunkbd being freed. Though the dangling pointer is set to NULL in sunkb…
CVE-2020-35632 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-28636 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->…
CVE-2020-12740 medium 5.5 tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.
CVE-2020-18771 medium 5.5 Exiv2 0.27.99.0 has a global buffer over-read in Exiv2::Internal::Nikon1MakerNote::print0x0088 in nikonmn_int.cpp which can result in an information leak.
CVE-2020-25693 medium 5.5 A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can l…
CVE-2020-7957 medium 5.5 The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a den…
CVE-2020-26420 medium 5.5 Memory leak in RTPS protocol dissector in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
CVE-2020-10878 medium 5.5 Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of in…
CVE-2020-29385 medium 5.5 GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign t…
CVE-2020-20445 medium 5.5 FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/lpc.h, which allows a remote malicious user to cause a Denial of Service.
CVE-2020-24027 medium 5.5 multiple issues in live-media
CVE-2020-35979 medium 5.5 An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is heap-based buffer overflow in the function gp_rtp_builder_do_avc() in ietf/rtp_pck_mpeg4.c.
CVE-2020-35982 medium 5.5 An issue was discovered in GPAC version 0.8.0 and 1.0.1. There is an invalid pointer dereference in the function gf_hinter_track_finalize() in media_tools/isom_hinter.c.
CVE-2020-18971 medium 5.5 Stack-based Buffer Overflow in PoDoFo v0.9.6 allows attackers to cause a denial of service via the component 'src/base/PdfDictionary.cpp:65'.
CVE-2020-25718 medium 5.5 A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.
CVE-2020-24119 medium 5.5 A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect.
CVE-2020-35132 medium 5.5 An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
CVE-2020-35475 medium 5.5 In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to ch…
CVE-2020-35964 medium 5.5 track_header in libavformat/vividas.c in FFmpeg 4.3.1 has an out-of-bounds write because of incorrect extradata packing.
CVE-2020-28633 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu…
CVE-2020-20453 medium 5.5 FFmpeg 4.2 is affected by a Divide By Zero issue via libavcodec/aaccoder, which allows a remote malicious user to cause a Denial of Service
CVE-2020-28086 medium 5.5 pass through 1.7.3 has a possibility of using a password for an unintended resource. For exploitation to occur, the user must do a git pull, decrypt a password, and log into a remote service with the…
CVE-2020-22021 medium 5.5 Buffer Overflow vulnerability in FFmpeg 4.2 at filter_edges function in libavfilter/vf_yadif.c, which could let a remote malicious user cause a Denial of Service.
CVE-2020-27840 medium 5.5 A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds me…
CVE-2020-21603 medium 5.5 libde265 v1.0.4 contains a heap buffer overflow in the put_qpel_0_0_fallback_16 function, which can be exploited via a crafted a file.
CVE-2020-21599 medium 5.5 libde265 v1.0.4 contains a heap buffer overflow in the de265_image::available_zscan function, which can be exploited via a crafted a file.
CVE-2020-37174 medium 5.5 5.5 16d ago WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering XSS payloads in design …
CVE-2020-37169 medium 5.5 5.5 16d ago WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-u…
CVE-2020-36855 medium 5.5 5.5 7mo ago A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of the argument StorageQuota leads to stac…
CVE-2020-16156 medium 5.5 1y ago Moderate: perl-CPAN security update
CVE-2020-13790 medium 5.5 1y ago Moderate: libjpeg-turbo security update
CVE-2020-27792 medium 5.5 1y ago A heap-based buffer overwrite vulnerability was found in GhostScript's lp8000_print_page() function in the gdevlp8k.c file. This flaw allows an attacker to trick a user into opening a crafted PDF fil…
CVE-2020-10135 medium 5.5 2y ago RHSA-2024:9315: kernel security update (Moderate)
CVE-2020-27827 medium 5.5 2y ago Moderate: lldpd security update
CVE-2020-36777 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: Fix memory leak in dvb_media_device_free() dvb_media_device_free() is leaking memory. Free `dvbdev->adapter->conn`…
CVE-2020-25656 medium 5.5 2y ago Moderate: kernel security, bug fix, and enhancement update
CVE-2020-36024 medium 5.5 2y ago Moderate: poppler security update
CVE-2020-15778 medium 5.5 2y ago scp in OpenSSH through 8.3p1 allows command injection in the scp.c toremote function, as demonstrated by backtick characters in the destination argument. NOTE: the vendor reportedly has stated that t…
CVE-2020-18652 medium 5.5 2y ago Moderate: exempi security update
CVE-2020-18651 medium 5.5 2y ago Moderate: exempi security update
CVE-2020-18770 medium 5.5 2y ago Moderate: zziplib security update
CVE-2020-14370 medium 5.5 2y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update
CVE-2020-28991 medium 5.5 2y ago Improper Access Control in Gitea
CVE-2020-28241 medium 5.5 2y ago Moderate: libmaxminddb security update
CVE-2020-35177 medium 5.5 2y ago Enumeration of users in HashiCorp Vault in github.com/hashicorp/vault
CVE-2020-28053 medium 5.5 2y ago Privilege Escalation in HashiCorp Consul in github.com/hashicorp/consul
CVE-2020-25201 medium 5.5 2y ago Denial of service in HashiCorp Consul in github.com/hashicorp/consul
CVE-2020-22217 medium 5.5 3y ago Moderate: c-ares security update
CVE-2020-12762 medium 5.5 3y ago Moderate: libfastjson security update
CVE-2020-24736 medium 5.5 3y ago Moderate: sqlite security update
CVE-2020-17049 medium 5.5 3y ago Moderate: krb5 security, bug fix, and enhancement update
CVE-2020-36518 medium 5.5 3y ago Moderate: pki-core:10.6 and pki-deps:10.6 security update
CVE-2020-28851 medium 5.5 4y ago Moderate: podman security and bug fix update
CVE-2020-36516 medium 5.5 4y ago An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP…
CVE-2020-28852 medium 5.5 4y ago Moderate: podman security and bug fix update
CVE-2020-36558 medium 5.5 4y ago A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault.
CVE-2020-0256 medium 5.5 4y ago Moderate: gdisk security update
CVE-2020-10735 medium 5.5 4y ago A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for…
CVE-2020-35527 medium 5.5 4y ago Moderate: sqlite security update
CVE-2020-35525 medium 5.5 4y ago Moderate: sqlite security update
CVE-2020-28469 medium 5.5 4y ago Moderate: nodejs:14 security, bug fix, and enhancement update
CVE-2020-7788 medium 5.5 4y ago Moderate: nodejs:14 security, bug fix, and enhancement update
CVE-2020-35509 medium 5.5 4y ago Keycloak vulnerable to Improper Certificate Validation
CVE-2020-29652 medium 5.5 4y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update
CVE-2020-1695 medium 5.5 4y ago Improper Input Validation in RESTEasy
CVE-2020-25864 medium 5.5 4y ago HashiCorp Consul Cross-site Scripting vulnerability in github.com/hashicorp/consul
CVE-2020-10770 medium 5.5 4y ago Keycloak vulnerable to Server-Side Request Forgery
CVE-2020-24303 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update
CVE-2020-11110 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update
CVE-2020-10749 medium 5.5 4y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update
CVE-2020-13430 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update
CVE-2020-12458 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update
CVE-2020-12459 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update
CVE-2020-12245 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update
CVE-2020-1726 medium 5.5 4y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update
CVE-2020-35492 medium 5.5 4y ago Moderate: cairo and pixman security and bug fix update
CVE-2020-35452 medium 5.5 4y ago Moderate: httpd:2.4 security and bug fix update
CVE-2020-19131 medium 5.5 4y ago Moderate: libtiff security update