Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-1909 | A use-after-free in a logging library in WhatsApp for iOS prior to v2.20.111 and WhatsApp Business for iOS prior to v2.… | Critical (9.8) | 2020-11-03 | Environment Specific |
| CVE-2020-1908 | Improper authorization of the Screen Lock feature in WhatsApp and WhatsApp Business for iOS prior to v2.20.100 could ha… | Medium (4.6) | 2020-11-03 | Environment Specific |
| CVE-2020-15984 | Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to s… | Medium (6.5) | 2020-11-03 | Environment Specific |
| CVE-2020-15980 | Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker t… | High (7.8) | 2020-11-03 | Environment Specific |
| CVE-2020-23989 | NeDi 1.9C allows pwsec.php oid XSS. | Medium (5.4) | 2020-11-02 | Environment Specific |