CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 May 21, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 May 21, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
3Debian GoogleOpensuse3Chrome Debian LinuxLeapJun 17, 2026 May 21, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in Blink in Google Chrome prior to 81.0.4044.138 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Canonical DebianFedoraproject+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 May 21, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 May 21, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in task scheduling in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 May 21, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in storage in Google Chrome prior to 81.0.4044.129 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 May 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in URL formatting in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to perform domain spoofing via a crafted domain name. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 May 21, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in payments in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 May 21, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out of bounds read and write in PDFium in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. |
2Debian Google2Chrome Debian LinuxJun 17, 2026 May 21, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in speech recognizer in Google Chrome prior to 81.0.4044.113 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
7Apache CanonicalDebian+4 more26Agile Engineering Data Management Agile PlmCommunications Cloud Native Core Binding Support Function+23 moreJun 17, 2026 May 20, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is...Show more |
3Debian FedoraprojectHttplib2 Project3Debian Linux FedoraHttplib2Jun 17, 2026 May 20, 2020 N/A· v4 6.8 MEDIUM· v3 4.3 MEDIUM· v2 In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability imp...Show more |
3Cacti DebianFedoraproject3Cacti Debian LinuxFedoraJun 17, 2026 May 20, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs). |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 May 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory...Show more |
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 May 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to...Show more |
2Debian Opensuse2Debian Linux Open Build ServiceJun 17, 2026 May 19, 2020 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 a Improper Access Control vulnerability in of Open Build Service allows remote attackers to read files of an OBS package where the sourceaccess/access is disabled This issue affects: Open Build Service versions prior to...Show more |
5Canonical DebianFedoraproject+2 more5Bind Debian LinuxFedora+2 moreJun 17, 2026 May 19, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by...Show more |
A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 May 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 May 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records. |