CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Canonical DebianFfmpeg3Debian Linux FfmpegUbuntu LinuxJun 17, 2026 Jun 7, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 FFmpeg 2.8 and 4.2.3 has a use-after-free via a crafted EXTINF duration in an m3u8 file because parse_playlist in libavformat/hls.c frees a pointer, and later that pointer is accessed in av_probe_input_format3 in libavfo...Show more |
4Arista CanonicalDebian+1 more4Cloudvision Portal Debian LinuxPam Tacplus+1 moreJun 17, 2026 Jun 6, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In support.c in pam_tacplus 1.3.8 through 1.5.1, the TACACS+ shared secret gets logged via syslog if the DEBUG loglevel and journald are used. |
6Debian FedoraprojectNetapp+3 more12Cloud Backup Communications Messaging ServerCommunications Network Charging And Control+9 moreJun 17, 2026 Jun 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. |
2Debian Libupnp Project2Debian Linux LibupnpJun 17, 2026 Jun 4, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServiceControlURLPath and...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxJun 17, 2026 Jun 4, 2020 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 rom_copy() in hw/core/loader.c in QEMU 4.0 and 4.1.0 does not validate the relationship between two addresses, which allows attackers to trigger an invalid memory copy operation. |
5Debian FedoraprojectNetapp+2 more5Debian Linux FedoraPostgresql Jdbc Driver+2 moreJun 17, 2026 Jun 4, 2020 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraGnutls+1 moreJun 17, 2026 Jun 4, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24)...Show more |
2Debian Google2Chrome Debian LinuxJun 17, 2026 Jun 3, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect implementation in user interface in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 Jun 3, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 83.0.4103.88 allowed a remote attacker to perform domain spoofing via a crafted URI. |
3Debian GoogleOpensuse4Backports Sle ChromeDebian Linux+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
3Debian GoogleOpensuse4Backports ChromeDebian Linux+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.97 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Ch...Show more |
3Debian GoogleOpensuse4Backports Sle ChromeDebian Linux+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. |
3Debian GoogleOpensuse4Backports ChromeDebian Linux+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in WebAuthentication in Google Chrome prior to 83.0.4103.97 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
6Debian FedoraprojectNghttp2+3 more10Banking Extensibility Workbench Blockchain PlatformDebian Linux+7 moreJun 17, 2026 Jun 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 byt...Show more |
6Canonical DebianDjangoproject+3 more7Debian Linux DjangoFedora+4 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack. |
6Canonical DebianDjangoproject+3 more7Debian Linux DjangoFedora+4 moreJun 17, 2026 Jun 3, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential da...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxJun 17, 2026 Jun 3, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.0.6. In rx_queue_add_kobject() and netdev_queue_add_kobject() in net/core/net-sysfs.c, a reference count is mishandled, aka CID-a3e23f719f5c. |
3Canonical DebianWebsocket Extensions Project3Debian Linux Ubuntu LinuxWebsocket ExtensionsJun 17, 2026 Jun 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 websocket-extensions ruby module prior to 0.1.5 allows Denial of Service (DoS) via Regex Backtracking. The extension parser may take quadratic time when parsing a header containing an unclosed string parameter value whos...Show more |
3Canonical DebianQemu3Debian Linux QemuUbuntu LinuxJun 17, 2026 Jun 2, 2020 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 hw/pci/msix.c in QEMU 4.2.0 allows guest OS users to trigger an out-of-bounds access via a crafted address in an msi-x mmio operation. |
4Broadcom DebianDocker+1 more4Debian Linux EngineFedora+1 moreJun 17, 2026 Jun 2, 2020 N/A· v4 6.0 MEDIUM· v3 6.0 MEDIUM· v2 An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive in...Show more |