CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianOpensuse+1 more4Debian Linux LeapQemu+1 moreJun 17, 2026 May 28, 2020 N/A· v4 3.2 LOW· v3 2.1 LOW· v2 In QEMU 5.0.0 and earlier, megasas_lookup_frame in hw/scsi/megasas.c has an out-of-bounds read via a crafted reply_queue_head field from a guest OS user. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapQemu+1 moreJun 17, 2026 May 28, 2020 N/A· v4 3.9 LOW· v3 3.3 LOW· v2 In QEMU 5.0.0 and earlier, es1370_transfer_audio in hw/audio/es1370.c does not properly validate the frame count, which allows guest OS users to trigger an out-of-bounds access during an es1370_write() operation. |
6Apple CanonicalDebian+3 more7Command Center Debian LinuxLeap+4 moreJun 17, 2026 May 28, 2020 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 In Vim before 8.1.0881, users can circumvent the rvim restricted mode and execute arbitrary OS commands via scripting interfaces (e.g., Python, Ruby, or Lua). |
5Broadcom CanonicalFedoraproject+2 more6Balsa Cloud BackupFabric Operating System+3 moreJun 17, 2026 May 28, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraSympa+1 moreJun 17, 2026 May 27, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sympa before 6.2.56 allows privilege escalation. |
8Brocade CanonicalDebian+5 more12Cloud Backup Communications Network Charging And ControlDebian Linux+9 moreJun 17, 2026 May 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 ext/fts3/fts3_snippet.c in SQLite before 3.32.0 has a NULL pointer dereference via a crafted matchinfo() query. |
8Apple BrocadeCanonical+5 more18Cloud Backup Communications Network Charging And ControlFabric Operating System+15 moreJun 17, 2026 May 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c. |
9Apple BrocadeCanonical+6 more19Cloud Backup Communications Network Charging And ControlDebian Linux+16 moreJun 17, 2026 May 27, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature. |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxJun 17, 2026 May 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 sd_wp_addr in hw/sd/sd.c in QEMU 4.2.0 uses an unvalidated address, which leads to an out-of-bounds read during sdhci_write() operations. A guest OS user can crash the QEMU process. |
4Canonical DebianMozilla+1 more6Debian Linux FirefoxFirefox Esr+3 moreJun 17, 2026 May 26, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Firefox < 76,...Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 May 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and pasted the command into a...Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 May 26, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of thes...Show more |
3Canonical DebianNetqmail3Debian Linux NetqmailUbuntu LinuxJun 17, 2026 May 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 qmail-verify as used in netqmail 1.06 is prone to an information disclosure vulnerability. A local attacker can test for the existence of files and directories anywhere in the filesystem because qmail-verify runs as root...Show more |
3Canonical DebianNetqmail3Debian Linux NetqmailUbuntu LinuxJun 17, 2026 May 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 qmail-verify as used in netqmail 1.06 is prone to a mail-address verification bypass vulnerability. |
7Apple CanonicalDebian+4 more15Communications Cloud Native Core Policy Communications Network Charging And ControlDebian Linux+12 moreJun 17, 2026 May 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 SQLite through 3.32.0 has an integer overflow in sqlite3_str_vappendf in printf.c. |
2Canonical Mozilla2Thunderbird Ubuntu LinuxJun 17, 2026 May 22, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 By encoding Unicode whitespace characters within the From email header, an attacker can spoof the sender email address that Thunderbird displays. This vulnerability affects Thunderbird < 68.8.0. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 22, 2020 N/A· v4 8.3 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) write vulnerability has been detected in crypto_rsa_common in libfreerdp/crypto/crypto.c. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 22, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in security_fips_decrypt in libfreerdp/core/security.c due to an uninitialized value. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 22, 2020 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 An issue was discovered in FreeRDP before 2.1.1. An out-of-bounds (OOB) read vulnerability has been detected in ntlm_read_ChallengeMessage in winpr/libwinpr/sspi/NTLM/ntlm_message.c. |
5Canonical DebianLinux+2 more113scale Debian LinuxEnterprise Linux+8 moreJun 17, 2026 May 22, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference flaw was found in the Linux kernel's SELinux subsystem in versions before 5.7. This flaw occurs while importing the Commercial IP Security Option (CIPSO) protocol's category bitmap into the SEL...Show more |