CVE-2020-0007
published 2020-01-08CVE-2020-0007: In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.17%
6.5th percentile
In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141890807
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware vRealize Log Insight addresses Cross Site Scripting (XSS) and Open Redirect vulnerabilities (CVE-2020-3953, CVE-2020-3954)
vendor_vmware·2020-04-14·CVSS 4.8
CVE-2020-3953 [MEDIUM] VMware vRealize Log Insight addresses Cross Site Scripting (XSS) and Open Redirect vulnerabilities (CVE-2020-3953, CVE-2020-3954)
VMSA-2020-0007: VMware vRealize Log Insight addresses Cross Site Scripting (XSS) and Open Redirect vulnerabilities (CVE-2020-3953, CVE-2020-3954)
vRealize Log Insight does not properly validate user input, resulting in XSS vulnerabilities. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 8.4.
CVEs: CVE-2020-3953, CVE-2020-3954
Affected products: VMware Aria, VMware vRealize
Android
CVE-2020-0007: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0007
Severity: HIGH
Type: ID
Affected AOSP versions: 8
vendor_android·2020-01-01·CVSS 5.5
CVE-2020-0007 [MEDIUM] CVE-2020-0007: Android Security Bulletin 2020-01-01
CVE: CVE-2020-0007
Severity: HIGH
Type: ID
Affected AOSP versions: 8
Android Security Bulletin 2020-01-01
CVE: CVE-2020-0007
Severity: HIGH
Type: ID
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-141890807
[2]
GHSA
GHSA-vvr2-3qvq-f857: In flattenString8 of Sensor
ghsa_unreviewed·2022-05-24
CVE-2020-0007 [LOW] CWE-908 GHSA-vvr2-3qvq-f857: In flattenString8 of Sensor
In flattenString8 of Sensor.cpp, there is a possible information disclosure of heap memory due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0, Android-8.1, Android-9, and Android-10 Android ID: A-141890807
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-9895 webkitgtk: Use-after-free may lead to application termination or arbitrary code execution
bugzilla·2020-09-16·CVSS 9.8
CVE-2020-9895 [CRITICAL] CVE-2020-9895 webkitgtk: Use-after-free may lead to application termination or arbitrary code execution
CVE-2020-9895 webkitgtk: Use-after-free may lead to application termination or arbitrary code execution
An use-after-free issue was found in webkitgtk. A remote attacker may be able to cause unexpected application termination or arbitrary code execution.
Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0007.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9895
---
This issue has been addressed in the following products:
Bugzilla
CVE-2020-9925 webkitgtk: A logic issue may lead to cross site scripting
bugzilla·2020-09-16·CVSS 6.1
CVE-2020-9925 [MEDIUM] CVE-2020-9925 webkitgtk: A logic issue may lead to cross site scripting
CVE-2020-9925 webkitgtk: A logic issue may lead to cross site scripting
A logic issue was found in webkitgtk. Processing maliciously crafted web content may lead to universal cross site scripting. Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0007.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9925
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Lifecycle Support
Via
Bugzilla
CVE-2020-9894 webkitgtk: Out-of-bounds read may lead to unexpected application termination or arbitrary code execution
bugzilla·2020-09-16·CVSS 4.3
CVE-2020-9894 [MEDIUM] CVE-2020-9894 webkitgtk: Out-of-bounds read may lead to unexpected application termination or arbitrary code execution
CVE-2020-9894 webkitgtk: Out-of-bounds read may lead to unexpected application termination or arbitrary code execution
An out-of-bounds read was found in webkitgtk. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0007.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9894
---
This issue has been addressed in the followin
Bugzilla
CVE-2020-9862 webkitgtk: Command injection in web inspector
bugzilla·2020-09-16·CVSS 7.8
CVE-2020-9862 [HIGH] CVE-2020-9862 webkitgtk: Command injection in web inspector
CVE-2020-9862 webkitgtk: Command injection in web inspector
A command injection issue existed in Web Inspector. Copying a URL from Web Inspector may lead to command injection. Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28.4.
References:
https://webkitgtk.org/security/WSA-2020-0007.html
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0007.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9862
---
This issue has been addressed in the following products:
Red Hat Enterpr
Bugzilla
CVE-2020-9915 webkitgtk: Access issue in content security policy
bugzilla·2020-09-16·CVSS 6.5
CVE-2020-9915 [MEDIUM] CVE-2020-9915 webkitgtk: Access issue in content security policy
CVE-2020-9915 webkitgtk: Access issue in content security policy
An access issue existed in Content Security Policy. Processing maliciously crafted web content may prevent Content Security Policy from being enforced. Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0007.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9915
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7 Extended Li
Bugzilla
CVE-2020-9893 webkitgtk: Use-after-free may lead to application termination or arbitrary code execution
bugzilla·2020-09-16·CVSS 8.8
CVE-2020-9893 [HIGH] CVE-2020-9893 webkitgtk: Use-after-free may lead to application termination or arbitrary code execution
CVE-2020-9893 webkitgtk: Use-after-free may lead to application termination or arbitrary code execution
An use-after-free issue was found in webkitgtk. A remote attacker may be able to cause unexpected application termination or arbitrary code execution. Versions affected: WebKitGTK before 2.28.4 and WPE WebKit before 2.28.4.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2020-0007.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:4451 https://access.redhat.com/errata/RHSA-2020:4451
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-9893
---
This issue has been addressed in the following products:
2020-01-08
Published