CVE-2020-0130
published 2020-09-17CVE-2020-0130: In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with…
PriorityP341high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.5th percentile
In screencap, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege in a system process with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123230379
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-0603 dotnet: Memory Corruption in SignalR
bugzilla·2020-01-09·CVSS 8.8
CVE-2020-0603 [HIGH] CVE-2020-0603 dotnet: Memory Corruption in SignalR
CVE-2020-0603 dotnet: Memory Corruption in SignalR
A vulnerability related to handling objects in memory has been reported in ASP.NET Core. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code by sending specially crafted requests to an ASP.NET Core application.
Discussion:
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603
https://github.com/aspnet/Announcements/issues/403
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:0130 https://access.redhat.com/errata/RHSA-2020:0130
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2020:0134 https://access.redhat.com/errata/RHSA-2020:013
Bugzilla
CVE-2020-0602 dotnet: Denial of service via backpressure issue
bugzilla·2020-01-09·CVSS 7.5
CVE-2020-0602 [HIGH] CVE-2020-0602 dotnet: Denial of service via backpressure issue
CVE-2020-0602 dotnet: Denial of service via backpressure issue
A vulnerability related to the processing of web requests has been reported in ASP.NET Core. An unauthenticated remote attacker could exploit this vulnerability to cause a Denial of Service by sending specially crafted requests to an ASP.NET Core application.
Discussion:
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602
https://github.com/aspnet/Announcements/issues/402
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:0130 https://access.redhat.com/errata/RHSA-2020:0130
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2020:0134 https://access.redhat.com/e
2020-09-17
Published