LiveActive security incident?Get immediate response
CVE archive

April 2020

Browse CVE records published in April 2020, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1821 matching CVEs · Page 12 of 37.

Medium · CVSS 6.7

CVE-2020-7273: Autorun registry bypass

Accessing functionality not properly constrained by ACLs vulnerability in the autorun start-up protection in McAfee Endpoint Security (ENS) for Windows Prior to 10.7.0 April 2020 Update allows local users to delete or rename programs in the autorun key via manipulation of some parameters.

Published Apr 15, 2020 · Updated Sep 16, 2024

Medium · CVSS 4.2

CVE-2020-7924: Specific command line parameter might result in accepting invalid certificate

Usage of specific command line parameter in MongoDB Tools which was originally intended to just skip hostname checks, may result in MongoDB skipping all certificate validation. This may result in accepting invalid certificates.This issue affects: MongoDB Inc. MongoDB Database Tools 3.6 versions later than 3.6.5; 3.6 versions prior to 3.6.21; 4.0 versions prior to 4.0.21; 4.2 versions prior to 4.2.11; 100 versions prior to 100.2.0. MongoDB Inc. Mongomirror 0 versions later than 0.6.0.

Published Apr 12, 2021 · Updated Sep 16, 2024

Medium · CVSS 6.5

CVE-2020-8966: Cross Site Scripting (XSS) flaws found in Tiki-Wiki CMS software

There is an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in php webpages of Tiki-Wiki Groupware. Tiki-Wiki CMS all versions through 20.0 allows malicious users to cause the injection of malicious code fragments (scripts) into a legitimate web page.

Published Apr 1, 2020 · Updated Sep 16, 2024

Unknown · CVSS Not scored

CVE-2020-24918: A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticate...

A buffer overflow in the RTSP service of the Ambarella Oryx RTSP Server 2020-01-07 allows an unauthenticated attacker to send a crafted RTSP request, with a long digest authentication header, to execute arbitrary code in parse_authentication_header() in libamprotocol-rtsp.so.1 in rtsp_svc (or cause a crash). This allows remote takeover of a Furbo Dog Camera, for example. NOTE: The vendor states that the RTSP library is used for DEMO only, using it in product is a customer's behavior. Ambarella has emphasized that RTSP is DEMO only library, should NOT be used in product in our document. Because Ambarella's SDK is proprietary, we didn't publish our SDK source code in public network.

Published Apr 30, 2021 · Updated Sep 6, 2024

Unknown · CVSS Not scored

CVE-2020-36326: PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a...

PHPMailer 6.1.8 through 6.4.0 allows object injection through Phar Deserialization via addAttachment with a UNC pathname. NOTE: this is similar to CVE-2018-19296, but arose because 6.1.8 fixed a functionality problem in which UNC pathnames were always considered unreadable by PHPMailer, even in safe contexts. As an unintended side effect, this fix eliminated the code that blocked addAttachment exploitation.

Published Apr 28, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-36325: An issue was discovered in Jansson through 2.13.1.

An issue was discovered in Jansson through 2.13.1. Due to a parsing error in json_loads, there's an out-of-bounds read-access bug. NOTE: the vendor reports that this only occurs when a programmer fails to follow the API specification

Published Apr 26, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-36327: Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the h...

Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not correct to use CVE-2021-24105 for every "Dependency Confusion" issue in every product.

Published Apr 29, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-36322: An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d...

An issue was discovered in the FUSE filesystem implementation in the Linux kernel before 5.10.6, aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950.

Published Apr 14, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-36311: An issue was discovered in the Linux kernel before 5.9.

An issue was discovered in the Linux kernel before 5.9. arch/x86/kvm/svm/sev.c allows attackers to cause a denial of service (soft lockup) by triggering destruction of a large SEV VM (which requires unregistering many encrypted regions), aka CID-7be74942f184.

Published Apr 6, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-36313: An issue was discovered in the Linux kernel before 5.7.

An issue was discovered in the Linux kernel before 5.7. The KVM subsystem allows out-of-range access to memslots after a deletion, aka CID-0774a964ef56. This affects arch/s390/kvm/kvm-s390.c, include/linux/kvm_host.h, and virt/kvm/kvm_main.c.

Published Apr 6, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-36314: fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, all...

fr-archive-libarchive.c in GNOME file-roller through 3.38.0, as used by GNOME Shell and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-11736.

Published Apr 7, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29615: An out-of-bounds read was addressed with improved input validation.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted image may lead to a denial of service.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29611: An out-of-bounds write issue was addressed with improved bounds checking.

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29618: An out-of-bounds read was addressed with improved input validation.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29621: This issue was addressed with improved checks.

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. A malicious application may be able to bypass Privacy preferences.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29633: An authentication issue was addressed with improved state management.

An authentication issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. An attacker in a privileged network position may be able to bypass authentication policy.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29624: A memory corruption issue existed in the processing of font files.

A memory corruption issue existed in the processing of font files. This issue was addressed with improved input validation. This issue is fixed in watchOS 7.2, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. Processing a maliciously crafted font file may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29623: "Clear History and Website Data" did not clear the history.

"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be unable to fully delete browsing history.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29619: An out-of-bounds read was addressed with improved input validation.

An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to heap corruption.

Published Apr 2, 2021 · Updated Aug 4, 2024

Unknown · CVSS Not scored

CVE-2020-29625: This issue was addressed with improved checks.

This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave. Processing a maliciously crafted image may lead to arbitrary code execution.

Published Apr 2, 2021 · Updated Aug 4, 2024