CVE-2020-0134
published 2020-06-11CVE-2020-0134: In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.14%
3.8th percentile
In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146052771
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-44pj-x46h-89qw: In BnDrm::onTransact of IDrm
ghsa_unreviewed·2022-05-24
CVE-2020-0134 [LOW] CWE-200 GHSA-44pj-x46h-89qw: In BnDrm::onTransact of IDrm
In BnDrm::onTransact of IDrm.cpp, there is a possible information disclosure due to uninitialized data. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146052771
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-0603 dotnet: Memory Corruption in SignalR
bugzilla·2020-01-09·CVSS 8.8
CVE-2020-0603 [HIGH] CVE-2020-0603 dotnet: Memory Corruption in SignalR
CVE-2020-0603 dotnet: Memory Corruption in SignalR
A vulnerability related to handling objects in memory has been reported in ASP.NET Core. An unauthenticated remote attacker could exploit this vulnerability to execute arbitrary code by sending specially crafted requests to an ASP.NET Core application.
Discussion:
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0603
https://github.com/aspnet/Announcements/issues/403
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:0130 https://access.redhat.com/errata/RHSA-2020:0130
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2020:0134 https://access.redhat.com/errata/RHSA-2020:013
Bugzilla
CVE-2020-0602 dotnet: Denial of service via backpressure issue
bugzilla·2020-01-09·CVSS 7.5
CVE-2020-0602 [HIGH] CVE-2020-0602 dotnet: Denial of service via backpressure issue
CVE-2020-0602 dotnet: Denial of service via backpressure issue
A vulnerability related to the processing of web requests has been reported in ASP.NET Core. An unauthenticated remote attacker could exploit this vulnerability to cause a Denial of Service by sending specially crafted requests to an ASP.NET Core application.
Discussion:
External References:
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0602
https://github.com/aspnet/Announcements/issues/402
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2020:0130 https://access.redhat.com/errata/RHSA-2020:0130
---
This issue has been addressed in the following products:
.NET Core on Red Hat Enterprise Linux
Via RHSA-2020:0134 https://access.redhat.com/e
2020-06-11
Published