CVE-2020-0001
published 2020-01-08CVE-2020-0001: In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of privilege with no…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.40%
33.0th percentile
In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-140055304
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6x24-j5v9-3mx6: In getProcessRecordLocked of ActivityManagerService
ghsa_unreviewed·2022-05-24
CVE-2020-0001 [HIGH] CWE-269 GHSA-6x24-j5v9-3mx6: In getProcessRecordLocked of ActivityManagerService
In getProcessRecordLocked of ActivityManagerService.java isolated apps are not handled correctly. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-140055304
Android
CVE-2020-0001: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0001
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 10
References: A-140055304
vendor_android·2020-01-01·CVSS 7.8
CVE-2020-0001 [HIGH] CVE-2020-0001: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0001
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 10
References: A-140055304
Android Security Bulletin 2020-01-01
CVE: CVE-2020-0001
Severity: MEDIUM
Type: EoP
Affected AOSP versions: 10
References: A-140055304
No detection rules found.
Nuclei
ListSERV Maestro <= 9.0-8 RCE
nuclei·CVSS 5.0
CVE-2010-1870 [MEDIUM] ListSERV Maestro <= 9.0-8 RCE
ListSERV Maestro <= 9.0-8 RCE
A struts-based OGNL remote code execution vulnerability exists in ListSERV Maestro before and including version 9.0-8.
Template:
id: CVE-2010-1870
info:
name: ListSERV Maestro <= 9.0-8 RCE
author: b0yd
severity: medium
description: A struts-based OGNL remote code execution vulnerability exists in ListSERV Maestro before and including version 9.0-8.
impact: |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
remediation: |
Upgrade to a patched version of ListSERV Maestro that is not affected by this vulnerability.
reference:
- https://www.securifera.com/advisories/sec-2020-0001/
- https://packetstormsecurity.com/files/159643/listservmaestro-exec.txt
- https://www.exploit-db.com/exploits/1
arXiv
Vulnerability Forecasting: In theory and practice
arxiv_fulltext·2020-12-07
Vulnerability Forecasting: In theory and practice
Vulnerability Forecasting: In theory and practice.
\'Eireann Leverett
Both authors contributed equally to this research.
[email protected]
0000-0001-6586-7359
Matilda Rhode
[1]
[email protected]
Adam Wedgbury
[email protected]
Airbus
Quadrant House, Celtic Springs Business Park, Coedkernew, Duffryn
Newport
U.K.
NP10 8FZ
## Abstract
Why wait for zero-days when you could predict them in advance? It is possible to predict the volume of CVEs released in the NVD as much as a year in advance. This can be done within 3 percent of the actual value, and different predictive algorithms perform well at different lookahead values. It is also possible to estimate the proportions of that total volumn belonging to specific vendors, software, CVSS scores, or vulnerability types
Bugzilla
CVE-2020-36567 gin: Unsanitized input in the default logger in github.com/gin-gonic/gin
bugzilla·2022-12-28·CVSS 7.5
CVE-2020-36567 [HIGH] CVE-2020-36567 gin: Unsanitized input in the default logger in github.com/gin-gonic/gin
CVE-2020-36567 gin: Unsanitized input in the default logger in github.com/gin-gonic/gin
Unsanitized input in the default logger in github.com/gin-gonic/gin before v1.6.0 allows remote attackers to inject arbitrary log lines.
https://pkg.go.dev/vuln/GO-2020-0001
https://github.com/gin-gonic/gin/commit/a71af9c144f9579f6dbe945341c1df37aaf09c0d
https://github.com/gin-gonic/gin/pull/2237
Discussion:
Created golang-github-gin-gonic tracking bugs for this issue:
Affects: fedora-all [bug 2158255]
Created golang-github-pact-foundation tracking bugs for this issue:
Affects: fedora-all [bug 2158256]
Created golang-github-tonistiigi-opentelemetry-contrib tracking bugs for this issue:
Affects: fedora-all [bug 2158257]
Created golang-opentelemetry-contrib tracking bugs for this issue:
Affe
Bugzilla
CVE-2020-13558 webkitgtk: Use-after-free in AudioSourceProviderGStreamer leading to arbitrary code execution
bugzilla·2021-02-15·CVSS 8.8
CVE-2020-13558 [HIGH] CVE-2020-13558 webkitgtk: Use-after-free in AudioSourceProviderGStreamer leading to arbitrary code execution
CVE-2020-13558 webkitgtk: Use-after-free in AudioSourceProviderGStreamer leading to arbitrary code execution
A flaw was found in WebKitGTK.
Impact: Processing maliciously crafted web content may lead to arbitrary code execution.
Description: A use after free issue in the AudioSourceProviderGStreamer class was addressed with improved memory management.
Reference:
https://webkitgtk.org/security/WSA-2021-0001.html
Discussion:
Created webkit2gtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1928887]
---
External References:
https://webkitgtk.org/security/WSA-2021-0001.html
---
Upstream fix:
https://trac.webkit.org/changeset/270184/webkit [trunk]
https://trac.webkit.org/changeset/272646/webkit [trunk]
https://trac.webkit.org/changeset/272713/webkit [2.30]
https://trac.webk
Bugzilla
CVE-2020-27672 xen: x86: race condition in Xen mapping code (XSA-345)
bugzilla·2020-10-23·CVSS 7.0
CVE-2020-27672 [HIGH] CVE-2020-27672 xen: x86: race condition in Xen mapping code (XSA-345)
CVE-2020-27672 xen: x86: race condition in Xen mapping code (XSA-345)
An issue was discovered in versions of Xen from at least 3.2 onward, allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1891097]
---
Acknowledgments:
Name: the Xen project
---
External References:
https://xenbits.xen.org/xsa/advisory-345.html
---
Upstream fix:
https://xenbits.xen.org/xsa/xsa345/0001-x86-mm-Refactor-map_pages_to_xen-to-have-only-a-sing.patch
https://xenbits.xen.org/xsa/xsa345/0002-x86-mm-Refactor-modify_xen_mappings-to-have-one-exit.patch
https://xenbit
Bugzilla
CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
bugzilla·2020-10-23·CVSS 5.3
CVE-2020-27674 [MEDIUM] CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
An issue was discovered in all versions of Xen allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1891092]
---
Acknowledgments:
Name: the Xen project
---
External References:
https://xenbits.xen.org/xsa/advisory-286.html
---
Upstream fix:
https://xenbits.xen.org/xsa/xsa286-unstable/0001-x86-pv-Drop-FLUSH_TLB_GLOBAL-in-do_mmu_update-for-XP.patch
https://xenbits.xen.org/xsa/xsa286-unstable/0002-x86-pv-Flush-TLB-in-response-to-paging-structure-cha.patch
---
This bug is now
Bugzilla
CVE-2020-7656 jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces
bugzilla·2020-06-23·CVSS 6.1
CVE-2020-7656 [MEDIUM] CVE-2020-7656 jquery: Cross-site scripting (XSS) via <script> HTML tags containing whitespaces
CVE-2020-7656 jquery: Cross-site scripting (XSS) via HTML tags containing whitespaces
jquery prior to 1.9.0 allows Cross-site Scripting attacks via the load method. The load method fails to recognize and remove "" HTML tags that contain a whitespace character, i.e: "", which results in the enclosed script logic to be executed.
https://security.netapp.com/advisory/ntap-20200528-0001/
https://snyk.io/vuln/SNYK-JS-JQUERY-569619
Discussion:
Created drupal7 tracking bugs for this issue:
Affects: epel-all [bug 1850138]
Affects: fedora-all [bug 1850136]
Created js-jquery tracking bugs for this issue:
Affects: epel-7 [bug 1850123]
Affects: fedora-all [bug 1850127]
Created js-jquery1 tracking bugs for this issue:
Affects: epel-7 [bug 1850134]
Affects: fedora-all [bug 1850133]
Created j
Bugzilla
CVE-2020-12689 openstack-keystone: EC2 and credential endpoints are not protected from a scoped context
bugzilla·2020-05-01·CVSS 8.8
CVE-2020-12689 [HIGH] CVE-2020-12689 openstack-keystone: EC2 and credential endpoints are not protected from a scoped context
CVE-2020-12689 openstack-keystone: EC2 and credential endpoints are not protected from a scoped context
A vulnerability was found Keystone's EC2 credentials API. Any user authenticated within a limited scope (trust/oauth/application credential) can create an EC2 credential with an escalated permission, such as obtaining "admin" while the user is on a limited "viewer" role.
Discussion:
Created attachment 1683826
propossed patch
Created attachment 1683826 [details]
0001-Respect-token-roles-when-creating-EC2-credentials.patch-master
---
References:
https://launchpad.net/bugs/1872735
---
Created openstack-keystone tracking bugs for this issue:
Affects: openstack-rdo [bug 1832399]
---
External References:
https://security.openstack.org/ossa/OSSA-2020-004.html
---
Acknowledgments:
Bugzilla
CVE-2019-18823 htcondor: Incorrect access control in condor_startd
bugzilla·2020-04-27·CVSS 9.8
CVE-2019-18823 [CRITICAL] CVE-2019-18823 htcondor: Incorrect access control in condor_startd
CVE-2019-18823 htcondor: Incorrect access control in condor_startd
HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs)
https://research.cs.wisc.edu/htcondor/
https://research.cs.wisc.edu/htcondor/new.html
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2020-0001.html
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2020-0002.html
https://research.cs.wisc.edu/htcondor/security/vulnerabiliti
Bugzilla
CVE-2020-6582 nrpe: heap-based buffer overflow due to a wrong integer type conversion
bugzilla·2020-03-24·CVSS 7.5
CVE-2020-6582 [HIGH] CVE-2020-6582 nrpe: heap-based buffer overflow due to a wrong integer type conversion
CVE-2020-6582 nrpe: heap-based buffer overflow due to a wrong integer type conversion
Nagios NRPE 3.2.1 has a Heap-Based Buffer Overflow, as demonstrated by interpretation of a small negative number as a large positive number during a bzero call.
Reference:
https://herolab.usd.de/security-advisories/usd-2020-0001/
Discussion:
Created nrpe tracking bugs for this issue:
Affects: epel-all [bug 1816816]
Affects: fedora-all [bug 1816814]
---
Statement:
Nagios is considered deprecated. Nagios plugins and Nagios server are no longer maintained or supported. Refer following release notes for details: "https://access.redhat.com/documentation/en-us/red_hat_gluster_storage/3.5/html-single/3.5_release_notes/index". The older version of nrpe which was shipped with Red Hat Gluster Storage does n
Bugzilla
CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
bugzilla·2020-03-24·CVSS 8.8
CVE-2019-8835 [HIGH] CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
CVE-2019-8835 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2
https://webkitgtk.org/security/WSA-2020-0001.html
Discussion:
Created webkit2gtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1816685]
---
External References:
https://webkitgtk.org/security/WSA-2020-0001.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
ht
Bugzilla
CVE-2019-8846 webkitgtk: Use after free issue may lead to remote code execution
bugzilla·2020-03-24·CVSS 8.8
CVE-2019-8846 [HIGH] CVE-2019-8846 webkitgtk: Use after free issue may lead to remote code execution
CVE-2019-8846 webkitgtk: Use after free issue may lead to remote code execution
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2
https://webkitgtk.org/security/WSA-2020-0001.html
Discussion:
Created webkit2gtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1816679]
---
External References:
https://webkitgtk.org/security/WSA-2020-0001.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/s
Bugzilla
CVE-2019-8844 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
bugzilla·2020-03-24·CVSS 8.8
CVE-2019-8844 [HIGH] CVE-2019-8844 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
CVE-2019-8844 webkitgtk: Processing maliciously crafted web content may lead to arbitrary code execution
A flaw was found in WebKitGTK before 2.26.3. Processing maliciously crafted web content may lead to arbitrary code execution.
References:
https://www.openwall.com/lists/oss-security/2020/01/23/2
https://webkitgtk.org/security/WSA-2020-0001.html
Discussion:
Created webkit2gtk3 tracking bugs for this issue:
Affects: fedora-all [bug 1816687]
---
External References:
https://webkitgtk.org/security/WSA-2020-0001.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
ht
2020-01-08
Published