CVEs (4,120)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Canonical Linux2Linux Kernel Ubuntu LinuxNov 21, 2024 Feb 19, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 OverlayFS in the Linux kernel before 3.0.0-16.28, as used in Ubuntu 10.0.4 LTS and 11.10, is missing inode security checks which could allow attackers to bypass security restrictions and perform unauthorized actions. |
3Canonical DebianO Dyn3Collabtive Debian LinuxUbuntu LinuxNov 21, 2024 Feb 17, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3,...Show more |
4Canonical LinuxNetapp+1 more10Active Iq Unified Manager Cloud BackupData Availability Services+7 moreJun 17, 2026 Feb 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size. |
5Canonical DebianLinuxfoundation+2 more5Debian Linux LeapOpenshift Container Platform+2 moreJun 17, 2026 Feb 12, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (...Show more |
4Apache CanonicalDebian+1 more4Camel Debian LinuxHtmlunit+1 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded...Show more |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Sander Bos discovered Apport's lock file was in a world-writable directory which allowed all users to prevent crash handling. |
2Canonical Whoopsie Project2Ubuntu Linux WhoopsieJun 17, 2026 Feb 8, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie. |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Sander Bos discovered Apport mishandled crash dumps originating from containers. This could be used by a local attacker to generate a crash report for a privileged process that is readable by an unprivileged user. |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 Sander Bos discovered a time of check to time of use (TOCTTOU) vulnerability in apport that allowed a user to cause core files to be written in arbitrary directories. |
2Apport Project Canonical2Apport Ubuntu LinuxJun 17, 2026 Feb 8, 2020 N/A· v4 7.8 HIGH· v3 6.1 MEDIUM· v2 Kevin Backhouse discovered that apport would read a user-supplied configuration file with elevated privileges. By replacing the file with a symbolic link, a user could get apport to read any file on the system as root, w...Show more |
4Canonical CephOpensuse+1 more4Ceph LeapOpenshift Container Storage+1 moreJun 17, 2026 Feb 7, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket conn...Show more |
3Canonical ImagemagickOpensuse3Imagemagick OpensuseUbuntu LinuxNov 21, 2024 Feb 6, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted P...Show more |
3Canonical ImagemagickOpensuse3Imagemagick OpensuseUbuntu LinuxNov 21, 2024 Feb 6, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in the DecodePSDPixels function in coders/psd.c in ImageMagick before 6.8.8-5 might allow remote attackers to execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulne...Show more |
3Canonical DebianMcabber3Debian Linux McabberUbuntu LinuxNov 21, 2024 Feb 6, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associa...Show more |
6Broadcom CanonicalDebian+3 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+6 moreJun 17, 2026 Feb 6, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c. |
2Canonical Clamav2Clamav Ubuntu LinuxJun 17, 2026 Feb 5, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A vulnerability in the Data-Loss-Prevention (DLP) module in Clam AntiVirus (ClamAV) Software versions 0.102.1 and 0.102.0 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affec...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid before 4.10. It allows a crafted FTP server to trigger disclosure of sensitive information from heap memory, such as information associated with other users' sessions or non-Squid process...Show more |
3Canonical OpensuseSquid Cache3Leap SquidUbuntu LinuxJun 17, 2026 Feb 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid before 4.10. Due to incorrect input validation, the NTLM authentication credentials parser in ext_lm_group_acl may write to memory outside the credentials buffer. On systems with memory a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 4, 2020 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 An issue was discovered in Squid before 4.10. Due to incorrect buffer management, a remote client can cause a buffer overflow in a Squid instance acting as a reverse proxy. |