Embedded System Vulnerabilities
A focused list of vulnerabilities relevant to embedded and IoT devices.
| CVE ID | Description | Severity | Published | Type |
|---|---|---|---|---|
| CVE-2020-0422 | In constructImportFailureNotification of NotificationImportExportListener.java, there is a possible permissions bypass … | Low (3.3) | 2020-10-14 | Environment Specific |
| CVE-2020-0421 | In appendFormatV of String8.cpp, there is a possible out of bounds write due to incorrect error handling. This could le… | High (7.8) | 2020-10-14 | Environment Specific |
| CVE-2020-0420 | In setUpdatableDriverPath of GpuService.cpp, there is a possible memory corruption due to a missing permission check. T… | High (7.8) | 2020-10-14 | Environment Specific |
| CVE-2020-0419 | In generateInfo of PackageInstallerSession.java, there is a possible leak of cross-profile URI data during app installa… | Medium (5.5) | 2020-10-14 | Environment Specific |
| CVE-2020-0416 | In multiple settings screens, there are possible tapjacking attacks due to an insecure default value. This could lead t… | High (8.8) | 2020-10-14 | Environment Specific |