CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianLinux+2 more12Active Iq Unified Manager Cloud BackupData Availability Services+9 moreJun 17, 2026 Feb 25, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-...Show more |
7Apache BlackberryDebian+4 more21Agile Engineering Data Management Agile PlmCommunications Element Manager+18 moreJun 17, 2026 Feb 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If su...Show more |
6Apache CanonicalDebian+3 more20Agile Engineering Data Management Agile Product Lifecycle ManagementCommunications Element Manager+17 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a po...Show more |
5Apache DebianNetapp+2 more16Agile Engineering Data Management Agile PlmCommunications Instant Messaging Server+13 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed...Show more |
3Debian FedoraprojectSympa3Debian Linux FedoraSympaJun 17, 2026 Feb 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Feb 24, 2020 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`. |
3Canonical DebianFreeradius3Debian Linux Pam RadiusUbuntu LinuxNov 21, 2024 Feb 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 add_password in pam_radius_auth.c in pam_radius 1.4.0 does not correctly check the length of the input password, and is vulnerable to a stack-based buffer overflow during memcpy(). An attacker could send a crafted passwo...Show more |
4Apple DebianFedoraproject+1 more8Debian Linux FedoraIpados+5 moreJun 17, 2026 Feb 24, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH...Show more |
2Debian Networkmanager Ssh Project2Debian Linux Networkmanager SshJun 17, 2026 Feb 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 danfruehauf NetworkManager-ssh before 1.2.11 allows privilege escalation because extra options are mishandled. |
5Cacti DebianFedoraproject+2 more5Cacti Debian LinuxFedora+2 moreJun 17, 2026 Feb 22, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege. |
1Debian 2Debian Linux X11 CommonNov 21, 2024 Feb 21, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 The init script in the Debian x11-common package before 1:7.6+12 is vulnerable to a symlink attack that can lead to a privilege escalation during package installation. |
2Debian Netsurf Browser2Debian Linux NetsurfNov 21, 2024 Feb 21, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Information-disclosure vulnerability in Netsurf through 2.8 due to a world-readable cookie jar. |
2Debian Golang2Debian Linux Package SshJun 17, 2026 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 golang.org/x/crypto before v0.0.0-20200220183623-bac4c82f6975 for Go allows a panic during signature verification in the golang.org/x/crypto/ssh package. A client can attack an SSH server that accepts public keys. Also,...Show more |
3Canonical DebianLinux3Debian Linux Linux KernelUbuntu LinuxNov 21, 2024 Feb 20, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 fs/proc/base.c in the Linux kernel through 3.1 allows local users to obtain sensitive keystroke information via access to /proc/interrupts. |
5Debian FedoraprojectOpensuse+2 more7Backports Sle Debian LinuxFedora+4 moreJun 17, 2026 Feb 20, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution. |
4Debian FedoraprojectOpenidc+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Feb 20, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning. |
2Debian Redhat2Ansible Debian LinuxNov 21, 2024 Feb 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The safe_eval function in Ansible before 1.6.4 does not properly restrict the code subset, which allows remote attackers to execute arbitrary code via crafted instructions. NOTE: this vulnerability exists because of an i...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacke...Show more |
3Canonical DebianO Dyn3Collabtive Debian LinuxUbuntu LinuxNov 21, 2024 Feb 17, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Multiple incomplete blacklist vulnerabilities in the avatar upload functionality in manageuser.php in Collabtive before 2.1 allow remote authenticated users to execute arbitrary code by uploading a file with a (1) .php3,...Show more |