CVE-2020-0002
published 2020-01-08CVE-2020-0002: In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no…
PriorityP346high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.39%
69.2th percentile
In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-142602711
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Tools workaround addresses a local privilege escalation vulnerability (CVE-2020-3941)
vendor_vmware·2020-01-14·CVSS 7.0
CVE-2020-3941 [HIGH] VMware Tools workaround addresses a local privilege escalation vulnerability (CVE-2020-3941)
VMSA-2020-0002: VMware Tools workaround addresses a local privilege escalation vulnerability (CVE-2020-3941)
The repair operation of VMware Tools for Windows has a race condition. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.
CVEs: CVE-2020-3941
Affected products: VMware Tools
Android
CVE-2020-0002: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0002
Severity: MEDIUM
Type: RCE
Affected AOSP versions: 10
References: A-142602711
vendor_android·2020-01-01·CVSS 8.8
CVE-2020-0002 [HIGH] CVE-2020-0002: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0002
Severity: MEDIUM
Type: RCE
Affected AOSP versions: 10
References: A-142602711
Android Security Bulletin 2020-01-01
CVE: CVE-2020-0002
Severity: MEDIUM
Type: RCE
Affected AOSP versions: 10
References: A-142602711
GHSA
GHSA-6658-6g59-7rqj: In ih264d_init_decoder of ih264d_api
ghsa_unreviewed·2022-05-24
CVE-2020-0002 [HIGH] CWE-416 GHSA-6658-6g59-7rqj: In ih264d_init_decoder of ih264d_api
In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-142602711
No detection rules found.
No public exploits indexed.
arXiv
Vulnerability Forecasting: In theory and practice
arxiv_fulltext·2020-12-07
Vulnerability Forecasting: In theory and practice
Vulnerability Forecasting: In theory and practice.
\'Eireann Leverett
Both authors contributed equally to this research.
[email protected]
0000-0001-6586-7359
Matilda Rhode
[1]
[email protected]
Adam Wedgbury
[email protected]
Airbus
Quadrant House, Celtic Springs Business Park, Coedkernew, Duffryn
Newport
U.K.
NP10 8FZ
## Abstract
Why wait for zero-days when you could predict them in advance? It is possible to predict the volume of CVEs released in the NVD as much as a year in advance. This can be done within 3 percent of the actual value, and different predictive algorithms perform well at different lookahead values. It is also possible to estimate the proportions of that total volumn belonging to specific vendors, software, CVSS scores, or vulnerability types
Bugzilla
CVE-2020-27672 xen: x86: race condition in Xen mapping code (XSA-345)
bugzilla·2020-10-23·CVSS 7.0
CVE-2020-27672 [HIGH] CVE-2020-27672 xen: x86: race condition in Xen mapping code (XSA-345)
CVE-2020-27672 xen: x86: race condition in Xen mapping code (XSA-345)
An issue was discovered in versions of Xen from at least 3.2 onward, allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1891097]
---
Acknowledgments:
Name: the Xen project
---
External References:
https://xenbits.xen.org/xsa/advisory-345.html
---
Upstream fix:
https://xenbits.xen.org/xsa/xsa345/0001-x86-mm-Refactor-map_pages_to_xen-to-have-only-a-sing.patch
https://xenbits.xen.org/xsa/xsa345/0002-x86-mm-Refactor-modify_xen_mappings-to-have-one-exit.patch
https://xenbit
Bugzilla
CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
bugzilla·2020-10-23·CVSS 5.3
CVE-2020-27674 [MEDIUM] CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
CVE-2020-27674 xen: x86 PV guest INVLPG-like flushes may leave stale TLB entries (XSA-286)
An issue was discovered in all versions of Xen allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
Discussion:
Created xen tracking bugs for this issue:
Affects: fedora-all [bug 1891092]
---
Acknowledgments:
Name: the Xen project
---
External References:
https://xenbits.xen.org/xsa/advisory-286.html
---
Upstream fix:
https://xenbits.xen.org/xsa/xsa286-unstable/0001-x86-pv-Drop-FLUSH_TLB_GLOBAL-in-do_mmu_update-for-XP.patch
https://xenbits.xen.org/xsa/xsa286-unstable/0002-x86-pv-Flush-TLB-in-response-to-paging-structure-cha.patch
---
This bug is now
Bugzilla
CVE-2020-16121 PackageKit: local attacker could use this issue to learn the MIME type of any file on the system
bugzilla·2020-10-02·CVSS 3.3
CVE-2020-16121 [LOW] CVE-2020-16121 PackageKit: local attacker could use this issue to learn the MIME type of any file on the system
CVE-2020-16121 PackageKit: local attacker could use this issue to learn the MIME type of any file on the system
PackageKit incorrectly handled certain
methods. A local attacker could use this issue to learn the MIME type of
any file on the system.
Reference:
https://packetstormsecurity.com/files/159284/USN-4538-1.txt
Discussion:
Created PackageKit tracking bugs for this issue:
Affects: fedora-all [bug 1884561]
---
External References:
More details:
https://bugs.launchpad.net/ubuntu/%2Bsource/packagekit/%2Bbug/1888887
https://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-16121.html?_ga=2.191526435.887932068.1602011173-1206535791.1586737989
---
Patch: https://launchpadlibrarian.net/498537855/0002-Information-disclosure-in-InstallFiles-GetFilesLocal.patch
Bugzilla
CVE-2020-3865 webkitgtk: Incorrect security check for a top-level DOM object context
bugzilla·2020-09-07·CVSS 8.8
CVE-2020-3865 [HIGH] CVE-2020-3865 webkitgtk: Incorrect security check for a top-level DOM object context
CVE-2020-3865 webkitgtk: Incorrect security check for a top-level DOM object context
WebKitGTK Security Advisory WSA-2020-0002 describes the following issue:
CVE-2020-3865
Impact: A top-level DOM object context may have incorrectly been considered secure. Description: A logic issue was addressed with improved validation.
Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before 2.26.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0002.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-202
Bugzilla
CVE-2020-3864 webkitgtk: Non-unique security origin for DOM object contexts
bugzilla·2020-09-07·CVSS 7.8
CVE-2020-3864 [HIGH] CVE-2020-3864 webkitgtk: Non-unique security origin for DOM object contexts
CVE-2020-3864 webkitgtk: Non-unique security origin for DOM object contexts
WebKitGTK Security Advisory WSA-2020-0002 describes the following issue:
CVE-2020-3864
Impact: A DOM object context may not have had a unique security origin. Description: A logic issue was addressed with improved validation.
Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before 2.26.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0002.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-3864
---
This iss
Bugzilla
CVE-2020-3868 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2020-3868 [HIGH] CVE-2020-3868 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2020-3868 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2020-0002 describes the following issue:
CVE-2020-3868
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before 2.26.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0002.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2020-3867 webkitgtk: Incorrect state management leading to universal cross-site scripting
bugzilla·2020-09-07·CVSS 6.1
CVE-2020-3867 [MEDIUM] CVE-2020-3867 webkitgtk: Incorrect state management leading to universal cross-site scripting
CVE-2020-3867 webkitgtk: Incorrect state management leading to universal cross-site scripting
WebKitGTK Security Advisory WSA-2020-0002 describes the following issue:
CVE-2020-3867
Impact: Processing maliciously crafted web content may lead to universal cross site scripting. Description: A logic issue was addressed with improved state management.
Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before 2.26.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0002.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redha
Bugzilla
CVE-2020-3862 webkitgtk: Denial of service via incorrect memory handling
bugzilla·2020-09-07·CVSS 6.5
CVE-2020-3862 [MEDIUM] CVE-2020-3862 webkitgtk: Denial of service via incorrect memory handling
CVE-2020-3862 webkitgtk: Denial of service via incorrect memory handling
WebKitGTK Security Advisory WSA-2020-0002 describes the following issue:
CVE-2020-3862
Impact: A malicious website may be able to cause a denial of service. Description: A denial of service issue was addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.4 and WPE WebKit before 2.26.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0002.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-3862
-
Bugzilla
CVE-2019-18823 htcondor: Incorrect access control in condor_startd
bugzilla·2020-04-27·CVSS 9.8
CVE-2019-18823 [CRITICAL] CVE-2019-18823 htcondor: Incorrect access control in condor_startd
CVE-2019-18823 htcondor: Incorrect access control in condor_startd
HTCondor up to and including stable series 8.8.6 and development series 8.9.4 has Incorrect Access Control. It is possible to use a different authentication method to submit a job than the administrator has specified. If the administrator has configured the READ or WRITE methods to include CLAIMTOBE, then it is possible to impersonate another user to the condor_schedd. (For example to submit or remove jobs)
https://research.cs.wisc.edu/htcondor/
https://research.cs.wisc.edu/htcondor/new.html
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2020-0001.html
https://research.cs.wisc.edu/htcondor/security/vulnerabilities/HTCONDOR-2020-0002.html
https://research.cs.wisc.edu/htcondor/security/vulnerabiliti
Bugzilla
CVE-2019-8551 webkitgtk: malicious web content leads to cross site scripting
bugzilla·2019-06-11·CVSS 6.1
CVE-2019-8551 [MEDIUM] CVE-2019-8551 webkitgtk: malicious web content leads to cross site scripting
CVE-2019-8551 webkitgtk: malicious web content leads to cross site scripting
Processing maliciously crafted web content may lead to universal cross site scripting. A logic issue was addressed with improved validation.
Reference:
https://webkitgtk.org/security/WSA-2019-0002.html
https://wpewebkit.org/security/WSA-2019-0002.html
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2019-8551
2020-01-08
Published