CVE-2020-0314
published 2020-09-17CVE-2020-0314: In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execution…
PriorityP422medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.14%
3.7th percentile
In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934920
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| android | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c8fh-jgqg-54pp: In AudioService, there are missing permission checks
ghsa_unreviewed·2022-05-24
CVE-2020-0314 [MEDIUM] GHSA-c8fh-jgqg-54pp: In AudioService, there are missing permission checks
In AudioService, there are missing permission checks. This could lead to local information disclosure of audio configuration with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-154934920
SonicWall
CVE-2020-5145: SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation co
vendor_sonicwall·2020-10-28·CVSS 8.6
CVE-2020-5145 [HIGH] CWE-427 CVE-2020-5145: SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation co
CVE-2020-5145: SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execution in the target system.
SonicWall
CVE-2020-5144: SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hi
vendor_sonicwall·2020-10-28·CVSS 7.8
CVE-2020-5144 [HIGH] CWE-426 CVE-2020-5144: SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hi
CVE-2020-5144: SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2020-09-17
Published