LiveActive security incident?Get immediate response
CVE archive

March 2020

Browse CVE records published in March 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1453 matching CVEs · Page 9 of 30.

High · CVSS 8.8

CVE-2020-13554: An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech W...

An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege.

Published Mar 3, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11414: An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330.

An issue was discovered in Progress Telerik UI for Silverlight before 2020.1.330. The RadUploadHandler class in RadUpload for Silverlight expects a web request that provides the file location of the uploading file along with a few other parameters. The uploading file location should be inside the directory where the upload handler class is defined. Before 2020.1.330, a crafted web request could result in uploads to arbitrary locations.

Published Mar 31, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11221: Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear t...

Usage of syscall by non-secure entity can allow extraction of secure QTEE diagnostic information in clear text form due to insufficient checks in the syscall handler and leads to information disclosure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wired Infrastructure and Networking

Published Mar 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11188: Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP...

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Published Mar 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11220: While processing storage SCM commands there is a time of check or time of use window where a pointer used c...

While processing storage SCM commands there is a time of check or time of use window where a pointer used could be invalid at a specific time while executing the storage SCM call in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking

Published Mar 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11190: Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP...

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Published Mar 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11189: Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP...

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Published Mar 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11227: Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying...

Out of bound write while parsing RTT/TTY packet parsing due to lack of check of buffer size before copying into buffer in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Published Mar 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11199: HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to...

HLOS to access EL3 stack canary by just mapping imem region due to Improper access control and can lead to information exposure in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking

Published Mar 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11171: Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP...

Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Published Mar 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11166: Potential out of bound read exception when UE receives unusually large number of padding octets in the begi...

Potential out of bound read exception when UE receives unusually large number of padding octets in the beginning of ROHC header in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables

Published Mar 17, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11106: An issue was discovered in Responsive Filemanager through 9.14.0.

An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one opens ajax_calls.php and uses the "view" action and places a payload in the type parameter, and then returns to the dialog.php page. This occurs because ajax_calls.php was also able to set the $_SESSION['RF']["view_type"] variable, but there it wasn't sanitized.

Published Mar 30, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11105: An issue was discovered in USC iLab cereal through 1.3.0.

An issue was discovered in USC iLab cereal through 1.3.0. It employs caching of std::shared_ptr values, using the raw pointer address as a unique identifier. This becomes problematic if an std::shared_ptr variable goes out of scope and is freed, and a new std::shared_ptr is allocated at the same address. Serialization fidelity thereby becomes dependent upon memory layout. In short, serialized std::shared_ptr variables cannot always be expected to serialize back into their original values. This can have any number of consequences, depending on the context within which this manifests.

Published Mar 30, 2020 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-11104: An issue was discovered in USC iLab cereal through 1.3.0.

An issue was discovered in USC iLab cereal through 1.3.0. Serialization of an (initialized) C/C++ long double variable into a BinaryArchive or PortableBinaryArchive leaks several bytes of stack or heap memory, from which sensitive information (such as memory layout or private keys) can be gleaned if the archive is distributed outside of a trusted context.

Published Mar 30, 2020 · Updated Aug 4, 2024