CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Milkytracker Project2Debian Linux MilkytrackerJun 17, 2026 Jul 6, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 PlayerGeneric.cpp in MilkyTracker through 1.02.00 has a use-after-free in the PlayerGeneric destructor. |
2Debian Roundcube2Debian Linux WebmailJun 17, 2026 Jul 6, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.2.11, 1.3.x before 1.3.14, and 1.4.x before 1.4.7. It allows XSS via a crafted HTML e-mail message, as demonstrated by a JavaScript payload in the xmlns (aka XML name...Show more |
3Debian OpensuseWireshark3Debian Linux LeapWiresharkJun 17, 2026 Jul 5, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.4, the GVCP dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-gvcp.c by ensuring that an offset increases in all situations. |
In QEMU 4.2.0, a MemoryRegionOps object may lack read/write callback methods, leading to a NULL pointer dereference. |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jul 2, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF forgery vulnerability exists in rails < 5.2.5, rails < 6.0.4 that makes it possible for an attacker to, given a global CSRF token such as the one present in the authenticity_token meta tag, forge a per-form CSRF t...Show more |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jul 2, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE. |
3Canonical DebianRack Project3Debian Linux RackUbuntu LinuxJun 17, 2026 Jul 2, 2020 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosu...Show more |
3Debian FedoraprojectLibraw3Debian Linux FedoraLibrawJun 17, 2026 Jul 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength)...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraGuacamoleJun 17, 2026 Jul 2, 2020 N/A· v4 6.7 MEDIUM· v3 6.2 MEDIUM· v2 Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs c...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraGuacamoleJun 17, 2026 Jul 2, 2020 N/A· v4 4.4 MEDIUM· v3 1.2 LOW· v2 Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in discl...Show more |
In nDPI through 3.2, the Oracle protocol dissector has a heap-based buffer over-read in ndpi_search_oracle in lib/protocols/oracle.c. |
2Debian Ntop2Debian Linux NdpiJun 17, 2026 Jul 1, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 In nDPI through 3.2, the H.323 dissector is vulnerable to a heap-based buffer over-read in ndpi_search_h323 in lib/protocols/h323.c, as demonstrated by a payload packet length that is too short. |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Jun 29, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770. |
3Debian OracleUclouvain3Debian Linux OpenjpegOutside In TechnologyJun 17, 2026 Jun 29, 2020 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor. Triggering a double-free may also be...Show more |
5Canonical Coturn ProjectDebian+2 more5Coturn Debian LinuxFedora+2 moreJun 17, 2026 Jun 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use t...Show more |
6Apache CanonicalDebian+3 more8Debian Linux LeapMysql Enterprise Monitor+5 moreJun 17, 2026 Jun 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such reques...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jun 26, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in OpenEXR before 2.5.2. Invalid input could cause a use-after-free in DeepScanLineInputFile::DeepScanLineInputFile() in IlmImf/ImfDeepScanLineInputFile.cpp. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jun 25, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Jun 24, 2020 N/A· v4 3.1 LOW· v3 2.6 LOW· v2 In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached pub...Show more |