CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian GraphicsmagickOpensuse4Backports Sle Debian LinuxGraphicsmagick+1 moreJun 17, 2026 Mar 18, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG. |
3Debian GnomeLinuxmint3Debian Linux GthumbPixJun 17, 2026 Mar 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow in _cairo_image_surface_create_from_jpeg() in extensions/cairo_io/cairo-image-surface-jpeg.c in GNOME gThumb before 3.8.3 and Linux Mint Pix before 2.4.5 allows attackers to cause a crash and...Show more |
4Debian FedoraprojectGolang+1 more4Cloud Insights Telegraf Debian LinuxFedora+1 moreJun 17, 2026 Mar 16, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Go before 1.12.16 and 1.13.x before 1.13.7 (and the crypto/cryptobyte package before 0.0.0-20200124225646-8b5121be2f68 for Go) allows attacks on clients (resulting in a panic) via a malformed X.509 certificate. |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreJun 17, 2026 Mar 16, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a...Show more |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreJun 17, 2026 Mar 16, 2020 N/A· v4 4.6 MEDIUM· v3 3.6 LOW· v2 A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x...Show more |
3Debian FedoraprojectRedhat4Ansible Engine Ansible TowerDebian Linux+1 moreJun 17, 2026 Mar 16, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s mo...Show more |
4Bluez CanonicalDebian+1 more4Bluez Debian LinuxLeap+1 moreJun 17, 2026 Mar 12, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Improper access control in subsystem for BlueZ before version 5.54 may allow an unauthenticated user to potentially enable escalation of privilege and denial of service via adjacent access |
9Canonical DebianFedoraproject+6 more11Banking Extensibility Workbench ChromeDebian Linux+8 moreJun 17, 2026 Mar 12, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() function in common/unist...Show more |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreJun 17, 2026 Mar 12, 2020 N/A· v4 3.9 LOW· v3 3.3 LOW· v2 A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the s...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraTwisted+1 moreJun 17, 2026 Mar 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request b...Show more |
5Canonical DebianFedoraproject+2 more6Debian Linux FedoraSolaris+3 moreJun 17, 2026 Mar 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the re...Show more |
3Debian FedoraprojectRedhat6Ansible Ansible TowerCloudforms Management Engine+3 moreJun 17, 2026 Mar 11, 2020 N/A· v4 5.0 MEDIUM· v3 3.7 LOW· v2 A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temp...Show more |
2Debian Google2Android Debian LinuxJun 17, 2026 Mar 10, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In vp8_decode_frame of decodeframe.c, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure if error correction were turned on, with no additional execu...Show more |
3Debian LinuxfoundationOracle10Communications Application Session Controller Communications Policy ManagementCommunications Pricing Design Center+7 moreJun 17, 2026 Mar 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes,...Show more |
2Debian Gnome2Debian Linux NetworkmanagerNov 21, 2024 Mar 10, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 NetworkManager 0.9 and earlier allows local users to use other users' certificates or private keys when making a connection via the file path when adding a new connection. |
3Debian FedoraprojectSleuthkit3Debian Linux FedoraThe Sleuth KitJun 17, 2026 Mar 9, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c. |
3Canonical DebianUsrsctp Project3Debian Linux Ubuntu LinuxUsrsctpJun 17, 2026 Mar 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init. |
6Arista DebianFedoraproject+3 more6Communications Performance Intelligence Center Debian LinuxEos+3 moreJun 17, 2026 Mar 6, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions. |
4Canonical DebianOpensuse+1 more4Debian Linux LeapQemu+1 moreJun 17, 2026 Mar 5, 2020 N/A· v4 3.5 LOW· v3 2.7 LOW· v2 QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEn...Show more |
5Canonical DebianDjangoproject+2 more5Debian Linux DjangoFedora+2 moreJun 17, 2026 Mar 5, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted toleran...Show more |