CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FedoraprojectGnu+1 more4Fedora GnutlsLeap+1 moreJun 17, 2026 Sep 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is sent with unexpected timing, and then an invalid second handshake occurs...Show more |
3Canonical DebianGruntjs3Debian Linux GruntUbuntu LinuxJun 17, 2026 Sep 3, 2020 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML. |
5Canonical DebianFedoraproject+2 more5Ark Debian LinuxFedora+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows a...Show more |
4Canonical DjangoprojectFedoraproject+1 more4Django FedoraUbuntu Linux+1 moreJun 17, 2026 Sep 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather t...Show more |
4Canonical DjangoprojectFedoraproject+1 more4Django FedoraUbuntu Linux+1 moreJun 17, 2026 Sep 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in...Show more |
6Canonical DebianFedoraproject+3 more7Debian Linux Enterprise LinuxFedora+4 moreJun 17, 2026 Aug 31, 2020 N/A· v4 5.0 MEDIUM· v3 4.4 MEDIUM· v2 An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[409...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxJun 17, 2026 Aug 31, 2020 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback....Show more |
oss_write in audio/ossaudio.c in QEMU before 5.0.0 mishandles a buffer position. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Aug 24, 2020 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer...Show more |
3Canonical FedoraprojectTuxfamily3Chrony FedoraUbuntu LinuxJun 17, 2026 Aug 24, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writ...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapPostgresql+1 moreJun 17, 2026 Aug 24, 2020 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially cr...Show more |
6Canonical DebianFedoraproject+3 more6Bind Debian LinuxFedora+3 moreJun 17, 2026 Aug 21, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has...Show more |
7Canonical DebianFedoraproject+4 more7Bind Debian LinuxDns Server+4 moreJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query p...Show more |
8Canonical DebianFedoraproject+5 more8Bind Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Aug 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the serve...Show more |
5Canonical IscNetapp+2 more5Bind Dns ServerLeap+2 moreJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send queries to it may be able to trigger the condition that will cause the...Show more |
4Canonical IscNetapp+1 more4Bind LeapSteelstore Cloud Integrated Storage+1 moreJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can exploit this to trigger the assertion failure, causing the server to exit. |
3Canonical Net SnmpNetapp6Cloud Backup Hci Management NodeNet Snmp+3 moreJun 17, 2026 Aug 20, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Net-SNMP through 5.8 has Improper Privilege Management because SNMP WRITE access to the EXTEND MIB provides the ability to run arbitrary commands as root. |
3Canonical Net SnmpNetapp5Cloud Backup Net SnmpSmi S Provider+2 moreJun 17, 2026 Aug 20, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Net-SNMP through 5.7.3 allows Escalation of Privileges because of UNIX symbolic link (symlink) following. |