CVE-2020-0006
published 2020-01-08CVE-2020-0006: In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to…
PriorityP431medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.77%
52.0th percentile
In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to remote information disclosure in the NFC server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-139738828
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5w9c-jpgm-qwv4: In rw_i93_send_cmd_write_single_block of rw_i93
ghsa_unreviewed·2022-05-24
CVE-2020-0006 [MEDIUM] CWE-908 GHSA-5w9c-jpgm-qwv4: In rw_i93_send_cmd_write_single_block of rw_i93
In rw_i93_send_cmd_write_single_block of rw_i93.cc, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to remote information disclosure in the NFC server with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-139738828
Android
CVE-2020-0006: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0006
Severity: HIGH
Type: ID
Affected AOSP versions: 8
vendor_android·2020-01-01·CVSS 6.5
CVE-2020-0006 [MEDIUM] CVE-2020-0006: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0006
Severity: HIGH
Type: ID
Affected AOSP versions: 8
Android Security Bulletin 2020-01-01
CVE: CVE-2020-0006
Severity: HIGH
Type: ID
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-139738828
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-9807 webkitgtk: Memory corruption may lead to arbitrary code execution
bugzilla·2020-09-16·CVSS 8.8
CVE-2020-9807 [HIGH] CVE-2020-9807 webkitgtk: Memory corruption may lead to arbitrary code execution
CVE-2020-9807 webkitgtk: Memory corruption may lead to arbitrary code execution
A memory corruption issue was found in webkitgtk. Processing maliciously crafted web content may lead to arbitrary code execution. Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before 2.28.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9807
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycl
Bugzilla
CVE-2020-13753 webkitgtk: Improper access management to CLONE_NEWUSER and the TIOCSTI ioctl
bugzilla·2020-09-16·CVSS 10.0
CVE-2020-13753 [CRITICAL] CVE-2020-13753 webkitgtk: Improper access management to CLONE_NEWUSER and the TIOCSTI ioctl
CVE-2020-13753 webkitgtk: Improper access management to CLONE_NEWUSER and the TIOCSTI ioctl
The bubblewrap sandbox of WebKitGTK and WPE WebKit, prior to 2.28.3, failed to properly block access to CLONE_NEWUSER and the TIOCSTI ioctl. CLONE_NEWUSER could potentially be used to confuse xdg- desktop-portal, which allows access outside the sandbox. TIOCSTI can be used to directly execute commands outside the sandbox by writing to the controlling terminal’s input buffer, similar to CVE-2017-5226. Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before 2.28.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0006.html
---
Note that RHEL 7 and RHEL 8 are both unaffected (because WebKit is not yet sandboxed in RHEL).
---
This bug is now closed. Further updat
Bugzilla
CVE-2020-9806 webkitgtk: Memory corruption may lead to arbitrary code execution
bugzilla·2020-09-16·CVSS 8.8
CVE-2020-9806 [HIGH] CVE-2020-9806 webkitgtk: Memory corruption may lead to arbitrary code execution
CVE-2020-9806 webkitgtk: Memory corruption may lead to arbitrary code execution
A memory corruption issue was found in webkitgtk. Processing maliciously crafted web content may lead to arbitrary code execution. Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before 2.28.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9806
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycl
Bugzilla
CVE-2020-9803 webkitgtk: Memory corruption may lead to arbitrary code execution
bugzilla·2020-09-16·CVSS 8.8
CVE-2020-9803 [HIGH] CVE-2020-9803 webkitgtk: Memory corruption may lead to arbitrary code execution
CVE-2020-9803 webkitgtk: Memory corruption may lead to arbitrary code execution
A memory corruption issue was found in webkitgtk. Processing maliciously crafted web content may lead to arbitrary code execution. Versions affected: WebKitGTK before 2.28.3 and WPE WebKit before 2.28.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9803
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycl
Bugzilla
CVE-2019-8823 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8823 [HIGH] CVE-2019-8823 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8823 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8823
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before 2.26.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8814 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8814 [HIGH] CVE-2019-8814 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8814 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8814
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.2 and WPE WebKit before 2.26.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8821 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8821 [HIGH] CVE-2019-8821 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8821 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8821
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8819 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8819 [HIGH] CVE-2019-8819 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8819 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8819
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before 2.26.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8815 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8815 [HIGH] CVE-2019-8815 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8815 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8815
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8710 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8710 [HIGH] CVE-2019-8710 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8710 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8710
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8766 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8766 [HIGH] CVE-2019-8766 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8766 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8766
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8743 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8743 [HIGH] CVE-2019-8743 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8743 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8743
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.0 and WPE WebKit before 2.26.0.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8811 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8811 [HIGH] CVE-2019-8811 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8811 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8811
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before 2.26.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8820 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8820 [HIGH] CVE-2019-8820 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8820 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8820
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.1 and WPE WebKit before 2.26.1.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2019-8812 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
bugzilla·2020-09-07·CVSS 8.8
CVE-2019-8812 [HIGH] CVE-2019-8812 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
CVE-2019-8812 webkitgtk: Multiple memory corruption issues leading to arbitrary code execution
WebKitGTK Security Advisory WSA-2019-0006 describes the following issue:
CVE-2019-8812
Impact: Processing maliciously crafted web content may lead to arbitrary code execution. Description: Multiple memory corruption issues were addressed with improved memory handling.
Versions affected: WebKitGTK before 2.26.2 and WPE WebKit before 2.26.2.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0006.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https
Bugzilla
CVE-2020-10738 moodle: remote code execution possible via SCORM packages (MSA-20-0006)
bugzilla·2020-05-07·CVSS 7.5
CVE-2020-10738 [HIGH] CVE-2020-10738 moodle: remote code execution possible via SCORM packages (MSA-20-0006)
CVE-2020-10738 moodle: remote code execution possible via SCORM packages (MSA-20-0006)
A flaw was found in Moodle versions 3.8 to 3.8.2, 3.7 to 3.7.5, 3.6 to 3.6.9, 3.5 to 3.5.11 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.
Reference:
https://moodle.org/mod/forum/discuss.php?d=403513
Upstream commit:
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-68410
Discussion:
Created moodle tracking bugs for this issue:
Affects: epel-all [bug 1837583]
Affects: fedora-all [bug 1837582]
---
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commerciall
2020-01-08
Published