CVE-2020-0017
published 2020-02-13CVE-2020-0017: In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information…
PriorityP415medium4.4CVSS 3.1
AVLACLPRNUIRSUCLILAN
EPSS
0.18%
7.3th percentile
In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-123232892
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-263w-3fx9-r885: In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users
ghsa_unreviewed·2022-05-24
CVE-2020-0017 [LOW] CWE-200 GHSA-263w-3fx9-r885: In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users
In multiple places, it was possible for the primary user’s dictionary to be visible to and modifiable by secondary users. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-123232892
VMware
VMware Fusion, VMware Remote Console and Horizon Client updates address a privilege escalation vulnerability (CVE-2020-3974)
vendor_vmware·2020-07-09·CVSS 7.8
CVE-2020-3974 [HIGH] VMware Fusion, VMware Remote Console and Horizon Client updates address a privilege escalation vulnerability (CVE-2020-3974)
VMSA-2020-0017: VMware Fusion, VMware Remote Console and Horizon Client updates address a privilege escalation vulnerability (CVE-2020-3974)
VMware Fusion, VMRC for Mac and Horizon Client for Mac contain a privilege escalation vulnerability due to improper XPC Client validation. VMware has evaluated the severity of this issue to be in the Important severity range with a maximum CVSSv3 base score of 7.8.
CVEs: CVE-2020-3974
Affected products: ESXi, Fusion Pro, Horizon Client, VMware Fusion, VMware Horizon, VMware vSphere
Android
CVE-2020-0017: Android Security Bulletin 2020-02-01
CVE: CVE-2020-0017
Severity: HIGH
Type: ID
Affected AOSP versions: 8
vendor_android·2020-02-01·CVSS 4.4
CVE-2020-0017 [MEDIUM] CVE-2020-0017: Android Security Bulletin 2020-02-01
CVE: CVE-2020-0017
Severity: HIGH
Type: ID
Affected AOSP versions: 8
Android Security Bulletin 2020-02-01
CVE: CVE-2020-0017
Severity: HIGH
Type: ID
Affected AOSP versions: 8.0, 8.1, 9, 10
References: A-123232892
[2]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-02-13
Published