CVEs from 2020

3,809 normalized CVEs published or assigned in this year.

Total
3,809
critical
critical 206
high
high 563
medium
medium 743
low
low 59
% Critical
5.4%
% with KEV
3.8%
% with exploit
5.4%

Top products

  • retail_xstore_point_of_service 33
  • banking_digital_experience 30
  • primavera_unifier 29
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 13
  • insurance_policy_administration_j2ee 11
  • communications_network_charging_and_control 10
  • enterprise_manager_base_platform 10
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-2928 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2020-2930 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2020-2760 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2020-2780 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2020-2812 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2020-2814 high 8.0 6y ago RHSA-2020:5500: mariadb:10.3 security, bug fix, and enhancement update (Important)
CVE-2020-14654 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2020-14680 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2020-2570 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2020-2660 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2020-2903 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2020-2926 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2020-14641 high 8.0 6y ago RHSA-2020:3732: mysql:8.0 security update (Important)
CVE-2020-12673 high 8.0 6y ago In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
CVE-2020-12674 high 8.0 6y ago In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
CVE-2020-12100 high 8.0 6y ago In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply ne…
CVE-2020-9490 high 8.0 6y ago Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resou…
CVE-2020-14352 high 8.0 6y ago RHSA-2020:3658: librepo security update (Important)
CVE-2020-15810 high 8.0 6y ago RHSA-2020:3623: squid:4 security update (Important)
CVE-2020-15811 high 8.0 6y ago RHSA-2020:3623: squid:4 security update (Important)
CVE-2020-15654 high 8.0 6y ago When in an endless loop, a website specifying a custom cursor using CSS could make it look like the user is interacting with the user interface, when they are not. This could lead to a perceived brok…
CVE-2020-12425 high 8.0 6y ago Due to confusion processing a hyphen character in Date.parse(), a one-byte out of bounds read could have occurred, leading to potential information disclosure. This vulnerability affects Firefox < 78.
CVE-2020-15653 high 8.0 6y ago An iframe sandbox element with the allow-popups flag could be bypassed when using noopener links. This could have led to security issues for websites relying on sandbox configurations that allowed po…
CVE-2020-15664 high 8.0 6y ago By holding a reference to the eval() function from an about:blank window, a malicious webpage could have gained access to the InstallTrigger object which would allow them to prompt the user to instal…
CVE-2020-12422 high 8.0 6y ago In non-standard configurations, a JPEG image created by JavaScript could have caused an internal variable to overflow, resulting in an out of bounds write, memory corruption, and a potentially exploi…
CVE-2020-15669 high 8.0 6y ago RHSA-2020:3634: thunderbird security update (Important)
CVE-2020-15648 high 8.0 6y ago Using object or embed tags, it was possible to frame other websites, even if they disallowed framing using the X-Frame-Options header. This vulnerability affects Thunderbird < 78 and Firefox < 78.0.2.
CVE-2020-12424 high 8.0 6y ago When constructing a permission prompt for WebRTC, a URI was supplied from the content process. This URI was untrusted, and could have been the URI of an origin that was previously granted permission;…
CVE-2020-15658 high 8.0 6y ago The code for downloading files did not properly take care of special characters, which led to an attacker being able to cut off the file ending at an earlier position, leading to a different file typ…
CVE-2020-15656 high 8.0 6y ago JIT optimizations involving the Javascript arguments object could confuse later optimizations. This risk was already mitigated by various precautions in the code, resulting in this bug rated at only …
CVE-2020-12399 high 8.0 6y ago NSS has shown timing differences when performing DSA signatures, which was exploitable and could eventually leak private keys. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and Firef…
CVE-2020-15652 high 8.0 6y ago By observing the stack trace for JavaScript errors in web workers, it was possible to leak the result of a cross-origin redirect. This applied only to content that can be parsed as script. This vulne…
CVE-2020-15659 high 8.0 6y ago Mozilla developers and community members reported memory safety bugs present in Firefox 78 and Firefox ESR 78.0. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
CVE-2020-6463 high 8.0 6y ago Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
CVE-2020-6514 high 8.0 6y ago Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to potentially exploit heap corruption via a crafted SCTP stream.
CVE-2020-11538 high 8.0 6y ago RHSA-2020:3185: python-pillow security update (Important)
CVE-2020-12654 high 8.0 6y ago An issue was found in Linux kernel before 5.5.4. mwifiex_ret_wmm_get_status() in drivers/net/wireless/marvell/mwifiex/wmm.c allows a remote AP to trigger a heap-based buffer overflow because of an in…
CVE-2020-12049 high 8.0 6y ago An issue was discovered in dbus >= 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A loca…
CVE-2020-12653 high 8.0 6y ago An issue was found in Linux kernel before 5.5.4. The mwifiex_cmd_append_vsie_tlv() function in drivers/net/wireless/marvell/mwifiex/scan.c allows local users to gain privileges or cause a denial of s…
CVE-2020-15646 high 8.0 6y ago RHSA-2020:3038: thunderbird security update (Important)
CVE-2020-10757 high 8.0 6y ago A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privi…
CVE-2020-10766 high 8.0 6y ago A logic bug flaw was found in Linux kernel before 5.8-rc1 in the implementation of SSBD. A bug in the logic handling allows an attacker with a local account to disable SSBD protection during a contex…
CVE-2020-10767 high 8.0 6y ago A flaw was found in the Linux kernel before 5.8-rc1 in the implementation of the Enhanced IBPB (Indirect Branch Prediction Barrier). The IBPB mitigation will be disabled when STIBP is not available o…
CVE-2020-10768 high 8.0 6y ago A flaw was found in the Linux Kernel before 5.8-rc1 in the prctl() function, where it can be used to enable indirect branch speculation after it has been disabled. This call incorrectly reports it as…
CVE-2020-12888 high 8.0 6y ago The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
CVE-2020-14573 high 8.0 6y ago RHSA-2020:2970: java-11-openjdk security and enhancement update (Important)
CVE-2020-14562 high 8.0 6y ago RHSA-2020:2970: java-11-openjdk security and enhancement update (Important)
CVE-2020-14556 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2020-14577 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2020-14578 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2020-14579 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2020-14583 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2020-14593 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2020-14621 high 8.0 6y ago RHSA-2020:3386: java-1.8.0-ibm security update (Important)
CVE-2020-12865 high 8.0 6y ago RHSA-2020:2902: sane-backends security update (Important)
CVE-2020-12861 high 8.0 6y ago RHSA-2020:2902: sane-backends security update (Important)
CVE-2020-10957 high 8.0 6y ago In Dovecot before 2.3.10.1, unauthenticated sending of malformed parameters to a NOOP command causes a NULL Pointer Dereference and crash in submission-login, submission, or lmtp.
CVE-2020-12268 high 8.0 6y ago RHSA-2020:2897: jbig2dec security update (Important)
CVE-2020-8172 high 8.0 6y ago RHSA-2020:2852: nodejs:12 security update (Important)
CVE-2020-8174 high 8.0 6y ago RHSA-2020:2852: nodejs:12 security update (Important)
CVE-2020-12417 high 8.0 6y ago Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially exploitable crash. *Note: this issue only affects…
CVE-2020-12421 high 8.0 6y ago When performing add-on updates, certificate chains terminating in non-built-in-roots were rejected (even if they were legitimately added by an administrator.) This could have caused add-ons to become…
CVE-2020-12418 high 8.0 6y ago Manipulating individual parts of a URL object could have caused an out-of-bounds read, leaking process memory to malicious JavaScript. This vulnerability affects Firefox ESR < 68.10, Firefox < 78, an…
CVE-2020-12419 high 8.0 6y ago When processing callbacks that occurred during window flushing in the parent process, the associated window may die; causing a use-after-free condition. This could have led to memory corruption and a…
CVE-2020-12420 high 8.0 6y ago When trying to connect to a STUN server, a race condition could have caused a use-after-free of a pointer, leading to memory corruption and a potentially exploitable crash. This vulnerability affects…
CVE-2020-11080 high 8.0 6y ago RHSA-2020:2852: nodejs:12 security update (Important)
CVE-2020-12398 high 8.0 6y ago multiple issues in thunderbird
CVE-2020-13777 high 8.0 6y ago RHSA-2020:2637: gnutls security update (Important)
CVE-2020-0543 high 8.0 6y ago Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVE-2020-12657 high 8.0 6y ago An issue was discovered in the Linux kernel before 5.6.5. There is a use-after-free in block/bfq-iosched.c related to bfq_idle_slice_timer_body.
CVE-2020-0548 high 8.0 6y ago RHSA-2021:3027: microcode_ctl security, bug fix and enhancement update (Important)
CVE-2020-0549 high 8.0 6y ago RHSA-2021:3027: microcode_ctl security, bug fix and enhancement update (Important)
CVE-2020-12663 high 8.0 6y ago RHSA-2020:2416: unbound security update (Important)
CVE-2020-12662 high 8.0 6y ago RHSA-2020:2416: unbound security update (Important)
CVE-2020-9402 high 8.0 6y ago Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a sui…
CVE-2020-13398 high 8.0 6y ago RHSA-2020:2407: freerdp security update (Important)
CVE-2020-12410 high 8.0 6y ago Mozilla developers reported memory safety bugs present in Firefox 76 and Firefox ESR 68.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
CVE-2020-12406 high 8.0 6y ago Mozilla Developer Iain Ireland discovered a missing type check during unboxed objects removal, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary cod…
CVE-2020-12405 high 8.0 6y ago When browsing a malicious page, a race condition in our SharedWorkerService could occur and lead to a potentially exploitable crash. This vulnerability affects Thunderbird < 68.9.0, Firefox < 77, and…
CVE-2020-11521 high 8.0 6y ago RHSA-2020:2336: freerdp security update (Important)
CVE-2020-11523 high 8.0 6y ago RHSA-2020:2336: freerdp security update (Important)
CVE-2020-11524 high 8.0 6y ago RHSA-2020:2336: freerdp security update (Important)
CVE-2020-8616 high 8.0 6y ago RHSA-2020:2338: bind security update (Important)
CVE-2020-9484 high 8.0 6y ago When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; …
CVE-2020-2732 high 8.0 6y ago A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 gu…
CVE-2020-11884 high 8.0 6y ago In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails…
CVE-2020-1763 high 8.0 6y ago RHSA-2020:2070: libreswan security update (Important)
CVE-2020-10711 high 8.0 6y ago A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's categor…
CVE-2020-11945 high 8.0 6y ago RHSA-2020:2041: squid:4 security update (Important)
CVE-2020-11008 high 8.0 6y ago RHSA-2020:1980: git security update (Important)
CVE-2020-7053 high 8.0 6y ago In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the i915_ppgtt_close function in drivers/gpu/drm/i915/i…
CVE-2020-1749 high 8.0 6y ago A flaw was found in the Linux kernel's implementation of some networking protocols in IPsec, such as VXLAN and GENEVE tunnels over IPv6. When an encrypted tunnel is created between two hosts, the ker…
CVE-2020-10690 high 8.0 6y ago There is a use-after-free in kernel versions before 5.5 due to a race condition between the release of ptp_clock and cdev while resource deallocation. When a (high privileged) process allocates a ptp…
CVE-2020-10699 high 8.0 6y ago RHSA-2020:1933: targetcli security update (Important)
CVE-2020-1967 high 8.0 6y ago Server or client applications that call the SSL_check_chain() function during or after a TLS 1.3 handshake may crash due to a NULL pointer dereference as a result of incorrect handling of the "signat…
CVE-2020-2757 high 8.0 6y ago RHSA-2020:2241: java-1.8.0-ibm security update (Important)
CVE-2020-5260 high 8.0 6y ago RHSA-2020:1513: git security update (Important)
CVE-2020-2756 high 8.0 6y ago RHSA-2020:2241: java-1.8.0-ibm security update (Important)
CVE-2020-2800 high 8.0 6y ago RHSA-2020:2241: java-1.8.0-ibm security update (Important)
CVE-2020-2803 high 8.0 6y ago RHSA-2020:2241: java-1.8.0-ibm security update (Important)