CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian OracleRedislabs+1 more4Communications Operations Monitor Debian LinuxLinux Enterprise+1 moreJun 17, 2026 Jun 15, 2020 N/A· v4 7.7 HIGH· v3 4.0 MEDIUM· v2 An integer overflow in the getnum function in lua_struct.c in Redis before 6.0.3 allows context-dependent attackers with permission to run Lua code in a Redis session to cause a denial of service (memory corruption and a...Show more |
2Debian Ijg2Debian Linux LibjpegJun 17, 2026 Jun 15, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 In IJG JPEG (aka libjpeg) before 9d, jpeg_mem_available() in jmemnobs.c in djpeg does not honor the max_memory_to_use setting, possibly causing excessive memory consumption. |
4Canonical DebianMutt+1 more4Debian Linux LeapMutt+1 moreJun 17, 2026 Jun 15, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Mutt before 1.14.3 allows an IMAP fcc/postpone man-in-the-middle attack via a PREAUTH response. |
4Debian FasterxmlNetapp+1 more13Active Iq Unified Manager Agile PlmBanking Digital Experience+10 moreJun 17, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2). |
4Debian FasterxmlNetapp+1 more15Active Iq Unified Manager Agile PlmAutovue For Agile Product Lifecycle Management+12 moreJun 17, 2026 Jun 14, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms....Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 3.1 LOW· v3 6.0 MEDIUM· v2 In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once in...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 2.4 LOW· v3 3.5 LOW· v2 In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 5.7 MEDIUM· v3 4.9 MEDIUM· v2 In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in vers...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 6.8 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a hig...Show more |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Jun 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is n...Show more |
2Debian Google2Android Debian LinuxJun 17, 2026 Jun 11, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In exif_entry_get_value of exif-entry.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interact...Show more |
7Canonical DebianFedoraproject+4 more10Active Iq Unified Manager Cloud BackupDebian Linux+7 moreJun 17, 2026 Jun 9, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system. |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Jun 9, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in the Linux kernel 4.4 through 5.7.1. drivers/tty/vt/keyboard.c has an integer overflow if k_ascii is called several times in a row, aka CID-b86dab054059. NOTE: Members in the community argue tha...Show more |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Jun 9, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Jun 9, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object. |
2Debian Videolan2Debian Linux Vlc Media PlayerJun 17, 2026 Jun 8, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application...Show more |
5Canonical DebianFedoraproject+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Jun 8, 2020 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. T...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhpmailer+1 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay process...Show more |
21Asus BroadcomCanon+18 more2175020 Z4a69a 5030 M2u92b5030 Z4a70a+214 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscriptio...Show more |