CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FasterxmlNetapp+1 more21Active Iq Unified Manager Agile PlmBanking Platform+18 moreJun 17, 2026 Apr 7, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop). |
5Debian FedoraprojectNetapp+2 more13Communications Brm Elastic Charging Engine Communications Cloud Native Core Service Communication ProxyCommunications Design Studio+10 moreJun 17, 2026 Apr 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraGnutls+2 moreJun 17, 2026 Apr 3, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a rand...Show more |
4Canonical DebianLinux+1 more4Debian Linux LeapLinux Kernel+1 moreJun 17, 2026 Apr 2, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in slc_bump in drivers/net/can/slcan.c in the Linux kernel 3.16 through 5.6.2. It allows attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel st...Show more |
3Apple DebianKsh Project3Debian Linux KshMac Os XJun 17, 2026 Apr 2, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In ksh version 20120801, a flaw was found in the way it evaluates certain environment variables. An attacker could use this flaw to override or bypass environment restrictions to execute shell commands. Services and appl...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraHaproxy+3 moreJun 17, 2026 Apr 2, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly ca...Show more |
8Apache BroadcomCanonical+5 more14Brocade Fabric Operating System Communications Element ManagerCommunications Session Report Manager+11 moreJun 17, 2026 Apr 2, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request U...Show more |
3Debian FedoraprojectGnu3Debian Linux FedoraGlibcJun 17, 2026 Apr 1, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for t...Show more |
6Apache CanonicalDebian+3 more11Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+8 moreJun 17, 2026 Apr 1, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. |
4Debian OpensusePhp+1 more4Debian Linux LeapPhp+1 moreJun 17, 2026 Apr 1, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 In PHP versions 7.2.x below 7.2.29, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using get_headers() with user-supplied URL, if the URL contains zero (\0) character, the URL will be silently truncated at it. This may...Show more |
4Canonical DebianPhp+1 more4Debian Linux PhpTenable.sc+1 moreJun 17, 2026 Apr 1, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In PHP versions 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while using mb_strtolower() function with UTF-32LE encoding, certain invalid strings could cause PHP to overwrite stack-allocated buffer. This could lead to memor...Show more |
5Canonical DebianOpensuse+2 more5Debian Linux LeapPhp+2 moreJun 17, 2026 Apr 1, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 In PHP versions 7.2.x below 7.2.9, 7.3.x below 7.3.16 and 7.4.x below 7.4.4, while parsing EXIF data with exif_read_data() function, it is possible for malicious data to cause PHP to read one byte of uninitialized memory...Show more |
4Archlinux CentosDebian+1 more4Arch Linux BubblewrapCentos+1 moreJun 17, 2026 Mar 31, 2020 N/A· v4 7.8 HIGH· v3 8.5 HIGH· v2 Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root whi...Show more |
3Debian RedhatSystemd Project7Ceph Storage Debian LinuxDiscovery+4 moreJun 17, 2026 Mar 31, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash s...Show more |
2Debian Pam Krb5 Project2Debian Linux Pam Krb5Jun 17, 2026 Mar 31, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 pam-krb5 before 4.9 has a buffer overflow that might cause remote code execution in situations involving supplemental prompting by a Kerberos library. It may overflow a buffer provided by the underlying Kerberos library...Show more |
4Debian FasterxmlNetapp+1 more32Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+29 moreJun 17, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa). |
4Debian FasterxmlNetapp+1 more31Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+28 moreJun 17, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy). |
4Debian FasterxmlNetapp+1 more25Agile Plm Autovue For Agile Product Lifecycle ManagementBanking Digital Experience+22 moreJun 17, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms)...Show more |
2Debian Gitlab2Debian Linux GitlabJun 17, 2026 Mar 27, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders. |
3Debian OpensuseOtrs4Backports Sle Debian LinuxLeap+1 moreJun 17, 2026 Mar 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s), generated by users which already requested new passwords. This issue affects: ((OTRS)) Co...Show more |