CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Mozilla2Firefox Ubuntu LinuxJun 17, 2026 Mar 2, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 72. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrar...Show more |
2Canonical Mozilla4Firefox Firefox EsrThunderbird+1 moreJun 17, 2026 Mar 2, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of thes...Show more |
2Canonical Mozilla2Thunderbird Ubuntu LinuxJun 17, 2026 Mar 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 If a user saved passwords before Thunderbird 60 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the da...Show more |
2Canonical Mozilla2Thunderbird Ubuntu LinuxJun 17, 2026 Mar 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 When deriving an identifier for an email message, uninitialized memory was used in addition to the message contents. This vulnerability affects Thunderbird < 68.5. |
2Canonical Mozilla3Firefox ThunderbirdUbuntu LinuxJun 17, 2026 Mar 2, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw. This vulnerability affects Firefox ESR < 68...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapPhp+1 moreJun 17, 2026 Feb 27, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In PHP versions 7.2.x below 7.2.28, 7.3.x below 7.3.15 and 7.4.x below 7.4.3, when using file upload functionality, if upload progress tracking is enabled, but session.upload_progress.cleanup is set to 0 (disabled), and...Show more |
4Canonical DebianFedoraproject+1 more5Debian Linux Extra Packages For Enterprise LinuxFedora+2 moreJun 17, 2026 Feb 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Pure-FTPd 1.0.49. An uninitialized pointer vulnerability has been detected in the diraliases linked list. When the *lookup_alias(const char alias) or print_aliases(void) function is called, the...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraOpensmtpd+1 moreJun 17, 2026 Feb 25, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 OpenSMTPD before 6.6.4 allows remote code execution because of an out-of-bounds read in mta_io in mta_session.c for multi-line replies. Although this vulnerability affects the client side of OpenSMTPD, it is possible to...Show more |
3Canonical FedoraprojectOpensmtpd3Fedora OpensmtpdUbuntu LinuxJun 17, 2026 Feb 25, 2020 N/A· v4 4.7 MEDIUM· v3 4.7 MEDIUM· v2 OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in...Show more |
5Canonical DebianLinux+2 more12Active Iq Unified Manager Cloud BackupData Availability Services+9 moreJun 17, 2026 Feb 25, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-...Show more |
6Apache CanonicalDebian+3 more20Agile Engineering Data Management Agile Product Lifecycle ManagementCommunications Element Manager+17 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a po...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 24, 2020 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`. |
3Canonical DebianFreeradius3Debian Linux Pam RadiusUbuntu LinuxNov 21, 2024 Feb 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted passwo...Show more |
5Canonical NetappOracle+2 more11Cloud Backup Communications Messaging ServerCommunications Network Charging And Control+8 moreJun 17, 2026 Feb 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In SQLite 3.31.1, isAuxiliaryVtabOperator allows attackers to trigger a NULL pointer dereference and segmentation fault because of generated column optimizations. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Feb 20, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts. |
3Canonical FedoraprojectLibarchive3Fedora LibarchiveUbuntu LinuxJun 17, 2026 Feb 20, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact. |
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Feb 20, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 The Linux kernel from v2.3.36 before v2.6.39 allows local unprivileged users to cause a denial of service (memory consumption) by triggering creation of PTE pages. |
3Audiofile CanonicalFedoraproject3Audiofile FedoraUbuntu LinuxAug 13, 2025 Feb 19, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code vi...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacke...Show more |