CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreJun 17, 2026 Oct 1, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreJun 17, 2026 Oct 1, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than th...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreJun 17, 2026 Oct 1, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulne...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreJun 17, 2026 Oct 1, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more |
2Debian Nette2Application Debian LinuxJun 17, 2026 Oct 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC F...Show more |
3Debian EncodeRedhat3Ceph Storage Debian LinuxDjango Rest FrameworkJun 17, 2026 Sep 30, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in Django REST Framework versions before 3.12.0 and before 3.11.2. When using the browseable API viewer, Django REST Framework fails to properly escape certain strings that can come from user input. This...Show more |
4Debian FedoraprojectLibproxy Project+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Sep 30, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header. |
4Canonical DebianOracle+1 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxUbuntu Linux+2 moreJun 17, 2026 Sep 30, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 urllib3 before 1.25.9 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of putrequest(). NOTE: this is similar to CVE-...Show more |
3Debian OpensuseTigervnc3Debian Linux LeapTigervncJun 17, 2026 Sep 27, 2020 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 In rfb/CSecurityTLS.cxx and rfb/CSecurityTLS.java in TigerVNC before 1.11.0, viewers mishandle TLS certificate exceptions. They store the certificates as authorities, meaning that the owner of a certificate could imperso...Show more |
7Canonical DebianFedoraproject+4 more8Debian Linux FedoraHci Storage Node+5 moreJun 17, 2026 Sep 27, 2020 N/A· v4 7.2 HIGH· v3 6.4 MEDIUM· v2 http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF cont...Show more |
2Debian Qemu2Debian Linux QemuJun 17, 2026 Sep 25, 2020 N/A· v4 5.3 MEDIUM· v3 4.7 MEDIUM· v2 hw/usb/hcd-ohci.c in QEMU 5.0.0 has an infinite loop when a TD list has a loop. |
2Debian Qemu2Debian Linux QemuJun 17, 2026 Sep 25, 2020 N/A· v4 5.0 MEDIUM· v3 4.4 MEDIUM· v2 QEMU 5.0.0 has a heap-based Buffer Overflow in flatview_read_continue in exec.c because hw/sd/sdhci.c mishandles a write operation in the SDHC_BLKSIZE case. |
QEMU 5.0.0 has a use-after-free in hw/usb/hcd-xhci.c because the usb_packet_map return value is not checked. |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Sep 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a. |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Sep 23, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Sep 23, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the port is considered to...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Sep 23, 2020 N/A· v4 6.0 MEDIUM· v3 4.6 MEDIUM· v2 An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to MSR_MISC_ENABLE. When a guest accesses certain Model Specific Registers, Xen first reads the value...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Sep 23, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of event channels active...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Sep 23, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels f...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Sep 23, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the vi...Show more |