CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Mar 25, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate device names, disclosin...Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Mar 25, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted the command into a te...Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Mar 25, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potentially exploitable crash....Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Mar 25, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a potentially exploitable cr...Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Mar 25, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.6, Firefox <...Show more |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Mar 24, 2020 N/A· v4 5.3 MEDIUM· v3 5.4 MEDIUM· v2 In the Linux kernel before 5.5.8, get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls. |
4Apache CanonicalDebian+1 more6Business Process Management Suite Communications Messaging ServerDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted or corrupt PSD file can cause an infinite loop in Apache Tika's PSDParser in versions 1.0-1.23. |
4Apache CanonicalDebian+1 more6Business Process Management Suite Communications Messaging ServerDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted or corrupt PSD file can cause excessive memory usage in Apache Tika's PSDParser in versions 1.0-1.23. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSquid+1 moreJun 17, 2026 Mar 20, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Squid before 4.9, when certain web browsers are used, mishandles HTML in the host (aka hostname) parameter to cachemgr.cgi. |
3Canonical FedoraprojectGnupg3Fedora GnupgUbuntu LinuxJun 17, 2026 Mar 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the way certificate signatures could be forged using collisions found in the SHA-1 algorithm. An attacker could use this weakness to create forged certificate signatures. This issue affects GnuPG vers...Show more |
4Bluez CanonicalDebian+1 more4Bluez Debian LinuxLeap+1 moreJun 17, 2026 Mar 12, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access |
9Canonical DebianFedoraproject+6 more11Banking Extensibility Workbench ChromeDebian Linux+8 moreJun 17, 2026 Mar 12, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unist...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraTwisted+1 moreJun 17, 2026 Mar 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request b...Show more |
5Canonical DebianFedoraproject+2 more6Debian Linux FedoraSolaris+3 moreJun 17, 2026 Mar 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the re...Show more |
3Canonical DebianUsrsctp Project3Debian Linux Ubuntu LinuxUsrsctpJun 17, 2026 Mar 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapQemu+1 moreJun 17, 2026 Mar 5, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEn...Show more |
3Canonical FedoraprojectTimeshift Project3Fedora TimeshiftUbuntu LinuxJun 17, 2026 Mar 5, 2020 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 init_tmp in TeeJee.FileSystem.vala in Timeshift before 20.03 unsafely reuses a preexisting temporary directory in the predictable location /tmp/timeshift. It follows symlinks in this location or uses directories owned by...Show more |
5Canonical DebianDjangoproject+2 more5Debian Linux DjangoFedora+2 moreJun 17, 2026 Mar 5, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted toleran...Show more |
6Canonical DebianFedoraproject+3 more11Active Iq Unified Manager Cloud BackupDebian Linux+8 moreJun 17, 2026 Mar 4, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The GNU C Library (aka glibc or libc6) before 2.32 could overflow an on-stack buffer during range reduction if an input to an 80-bit long double function contains a non-canonical bit pattern, a seen when passing a 0x5d41...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Mar 2, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 WebKitGTK through 2.26.4 and WPE WebKit through 2.26.4 (which are the versions right before 2.28.0) contains a memory corruption issue (use-after-free) that may lead to arbitrary code execution. This issue has been fixed...Show more |