CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Apache Debian2Debian Linux Traffic ServerJun 17, 2026 Jun 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSane Backends+1 moreJun 17, 2026 Jun 24, 2020 N/A· v4 8.0 HIGH· v3 5.2 MEDIUM· v2 A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSane Backends+1 moreJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSane Backends+1 moreJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds read in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to read important information, such as the ASLR offsets of the program, aka GHSL-2020-08...Show more |
3Canonical DebianGnu3Debian Linux MailmanUbuntu LinuxJun 17, 2026 Jun 24, 2020 N/A· v4 4.3 MEDIUM· v3 2.6 LOW· v2 GNU Mailman before 2.1.33 allows arbitrary content injection via the Cgi/private.py private archive login page. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out of bounds read in RLEDECOMPRESS. All FreeRDP based clients with sessions with color depth < 32 are affected. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out of bounds read in license_read_new_or_upgrade_license_packet. A manipulated license packet can lead to out of bound reads to an internal buffer. This is fixed in version 2...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 In FreeRDP before version 2.1.2, there is an out-of-bound read in glyph_cache_put. This affects all FreeRDP clients with `+glyph-cache` option enabled This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In FreeRDP before version 2.1.2, there is a global OOB read in update_read_cache_bitmap_v3_order. As a workaround, one can disable bitmap cache with -bitmap-cache (default). This is fixed in version 2.1.2. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraFreerdp+2 moreJun 17, 2026 Jun 22, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Jun 21, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Mutt before 1.14.4 and NeoMutt before 2020-06-19 have a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. When a server sends a "begin TLS" response, the client reads additional data (e.g., from a man-in-the-mi...Show more |
3Alpine Project DebianFedoraproject3Alpine Debian LinuxFedoraJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letti...Show more |
2Debian Rubyonrails2Debian Linux RailsJun 17, 2026 Jun 19, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CSRF vulnerability exists in rails <= 6.0.3 rails-ujs module that could allow attackers to send CSRF tokens to wrong domains. |
3Debian OpensuseRubyonrails3Debian Linux LeapRailsJun 17, 2026 Jun 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization of untrusted data vulnernerability exists in rails < 5.2.4.3, rails < 6.0.3.1 that can allow an attacker to unmarshal user-provided objects in MemCacheStore and RedisCacheStore potentially resulting in...Show more |
3Canonical DebianRack Project3Debian Linux RackUbuntu LinuxJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix. |
3Debian OpensuseRubyonrails4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 Jun 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply information can be inadvertently leaked fromStrong Parameters. |