CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Arista DebianQualcomm13Access Point Apq8053 FirmwareDebian Linux+10 moreJun 17, 2026 Sep 8, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 u'Specifically timed and handcrafted traffic can cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure over the air for a discrete s...Show more |
4Debian OpensuseOracle+1 more5Communications Cloud Native Core Network Function Cloud Native Environment Communications Cloud Native Core PolicyDebian Linux+2 moreJun 17, 2026 Sep 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwriting the /root/.ssh/...Show more |
6Debian FedoraprojectNetapp+3 more18Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+15 moreJun 17, 2026 Sep 4, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e. |
3Canonical DebianGruntjs3Debian Linux GruntUbuntu LinuxJun 17, 2026 Sep 3, 2020 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML. |
5Canonical DebianFedoraproject+2 more5Ark Debian LinuxFedora+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Splitting attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 2, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Squid before 4.13 and 5.x before 5.0.4. Due to incorrect data validation, HTTP Request Smuggling attacks may succeed against HTTP and HTTPS traffic. This leads to cache poisoning. This allows a...Show more |
3Arm DebianFedoraproject3Debian Linux FedoraMbed TlsJun 17, 2026 Sep 2, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed...Show more |
6Canonical DebianFedoraproject+3 more7Debian Linux Enterprise LinuxFedora+4 moreJun 17, 2026 Aug 31, 2020 N/A· v4 5.0 MEDIUM· v3 4.4 MEDIUM· v2 An out-of-bounds read/write access flaw was found in the USB emulator of the QEMU in versions before 5.2.0. This issue occurs while processing USB packets from a guest when USBDevice 'setup_len' exceeds its 'data_buf[409...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxJun 17, 2026 Aug 31, 2020 N/A· v4 3.8 LOW· v3 2.1 LOW· v2 In QEMU through 5.0.0, an integer overflow was found in the SM501 display driver implementation. This flaw occurs in the COPY_AREA macro while handling MMIO write operations through the sm501_2d_engine_write() callback....Show more |
3Debian Flask Cors ProjectOpensuse4Backports Sle Debian LinuxFlask Cors+1 moreJun 17, 2026 Aug 31, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access private resources because resource matching does not ensure that pathnames are in a canonica...Show more |
2Bufferlist Project Debian2Bufferlist Debian LinuxJun 17, 2026 Aug 30, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A buffer over-read vulnerability exists in bl <4.0.3, <3.0.1, <2.2.1, and <1.2.3 which could allow an attacker to supply user input (even typed) that if it ends up in consume() argument and can become negative, the Buffe...Show more |
2Debian Redhat2Ansible Debian LinuxJun 17, 2026 Aug 26, 2020 N/A· v4 7.3 HIGH· v3 6.1 MEDIUM· v2 A flaw was found in the solaris_zone module from the Ansible Community modules. When setting the name for the zone on the Solaris host, the zone name is checked by listing the process with the 'ps' bare command on the re...Show more |
4Debian FasterxmlNetapp+1 more25Active Iq Unified Manager Agile PlmApplication Testing Suite+22 moreJun 17, 2026 Aug 25, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP). |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Aug 24, 2020 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapPostgresql+1 moreJun 17, 2026 Aug 24, 2020 N/A· v4 7.3 HIGH· v3 4.4 MEDIUM· v2 It was found that some PostgreSQL extensions did not use search_path safely in their installation script. An attacker with sufficient privileges could use this flaw to trick an administrator into executing a specially cr...Show more |
6Canonical DebianFedoraproject+3 more6Bind Debian LinuxFedora+3 moreJun 17, 2026 Aug 21, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has...Show more |
7Canonical DebianFedoraproject+4 more7Bind Debian LinuxDns Server+4 moreJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query p...Show more |
8Canonical DebianFedoraproject+5 more8Bind Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Aug 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the serve...Show more |
3Debian IcingaSuse3Debian Linux Icinga Web 2Package HubJun 17, 2026 Aug 19, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixe...Show more |