CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianLibexif Project+1 more4Debian Linux LeapLibexif+1 moreJun 17, 2026 May 21, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 An issue was discovered in libexif before 0.6.22. Use of uninitialized memory in EXIF Makernote handling could lead to crashes and potential use-after-free conditions. |
3Canonical Libexif ProjectOpensuse3Leap LibexifUbuntu LinuxJun 17, 2026 May 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in libexif before 0.6.22. An unrestricted size in handling Canon EXIF MakerNote data could lead to consumption of large amounts of compute time for decoding EXIF data. |
4Canonical DebianLibexif Project+1 more4Debian Linux LeapLibexif+1 moreJun 17, 2026 May 21, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in libexif before 0.6.22. Several buffer over-reads in EXIF MakerNote handling could lead to information disclosure and crashes. This is different from CVE-2020-0093. |
5Canonical DebianFedoraproject+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 May 21, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
7Apache CanonicalDebian+4 more26Agile Engineering Data Management Agile PlmCommunications Cloud Native Core Binding Support Function+23 moreJun 17, 2026 May 20, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is...Show more |
3Canonical DpdkFedoraproject3Data Plane Development Kit FedoraUbuntu LinuxJun 17, 2026 May 19, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read. |
5Canonical DpdkFedoraproject+2 more6Communications Session Border Controller Data Plane Development KitEnterprise Communications Broker+3 moreJun 17, 2026 May 19, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a...Show more |
5Canonical DpdkFedoraproject+2 more6Communications Session Border Controller Data Plane Development KitEnterprise Communications Broker+3 moreJun 17, 2026 May 19, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption. |
5Canonical DebianFedoraproject+2 more5Bind Debian LinuxFedora+2 moreJun 17, 2026 May 19, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 May 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 May 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records. |
5Canonical DebianLinux+2 more24A700s Firmware Active Iq Unified ManagerBootstrap Os+21 moreJun 17, 2026 May 18, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c in the Linux kernel 3.16 through 5.6.13 relies on kstrdup without considering the possibility of an internal '\0' value, which allows attackers to trigger an out...Show more |
6Canonical DebianFedoraproject+3 more25A700s Firmware Active Iq Unified ManagerBootstrap Os+22 moreJun 17, 2026 May 15, 2020 N/A· v4 5.3 MEDIUM· v3 4.7 MEDIUM· v2 The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 15, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 libfreerdp/core/update.c in FreeRDP versions > 1.1 through 2.0.0-rc4 has an Out-of-bounds Read. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 15, 2020 N/A· v4 2.2 LOW· v3 3.5 LOW· v2 libfreerdp/cache/bitmap.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out of bounds read. |
3Canonical FreerdpOpensuse3Freerdp LeapUbuntu LinuxJun 17, 2026 May 15, 2020 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 libfreerdp/codec/interleaved.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 15, 2020 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 libfreerdp/gdi/region.c in FreeRDP versions > 1.0 through 2.0.0-rc4 has an Integer Overflow. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 15, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 libfreerdp/gdi/gdi.c in FreeRDP > 1.0 through 2.0.0-rc4 has an Out-of-bounds Read. |
4Canonical DebianFreerdp+1 more4Debian Linux FreerdpLeap+1 moreJun 17, 2026 May 15, 2020 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 libfreerdp/codec/planar.c in FreeRDP version > 1.0 through 2.0.0-rc4 has an Out-of-bounds Write. |
3Canonical DebianFedoraproject4Apt Debian LinuxFedora+1 moreJun 17, 2026 May 15, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files. |