CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (...Show more |
4Apache CanonicalDebian+1 more4Camel Debian LinuxHtmlunit+1 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded...Show more |
5Debian FasterxmlHuawei+2 more8Debian Linux Global Lifecycle Management OpatchJackson Databind+5 moreJun 17, 2026 Feb 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FasterXML jackson-databind 2.0.0 through 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter. |
5Debian OpensuseOracle+2 more5Communications Diameter Signaling Router Debian LinuxLeap+2 moreJun 17, 2026 Feb 10, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big...Show more |
5Debian OpensuseOracle+2 more5Communications Diameter Signaling Router Debian LinuxLeap+2 moreJun 17, 2026 Feb 10, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the all...Show more |
5Debian NodejsOpensuse+2 more7Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxEnterprise Linux+4 moreJun 17, 2026 Feb 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons |
6Debian FedoraprojectNodejs+3 more13Debian Linux Enterprise LinuxEnterprise Linux Desktop+10 moreJun 17, 2026 Feb 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed |
5Debian NodejsOpensuse+2 more10Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxEnterprise Linux+7 moreJun 17, 2026 Feb 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate |
3Debian Libslirp ProjectOpensuse3Debian Linux LeapLibslirpJun 17, 2026 Feb 6, 2020 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses snprintf return values, leading to a buffer overflow in later code. |
3Canonical DebianMcabber3Debian Linux McabberUbuntu LinuxNov 21, 2024 Feb 6, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 MCabber before 1.0.4 is vulnerable to roster push attacks, which allows remote attackers to intercept communications, or add themselves as an entity on a 3rd party's roster as another user, which will also garner associa...Show more |
3Debian LinuxOpensuse3Debian Linux LeapLinux KernelJun 17, 2026 Feb 6, 2020 N/A· v4 5.9 MEDIUM· v3 3.6 LOW· v2 There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c. |
6Broadcom CanonicalDebian+3 more9Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+6 moreJun 17, 2026 Feb 6, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the n_tty_receive_buf_common function in drivers/tty/n_tty.c. |
3Debian LinuxOpensuse3Debian Linux LeapLinux KernelJun 17, 2026 Feb 6, 2020 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c. |
3Canonical DebianOpensuse3Cloud Init Debian LinuxLeapJun 17, 2026 Feb 5, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In cloud-init through 19.4, rand_user_password in cloudinit/config/cc_set_passwords.py has a small default pwlen value, which makes it easier for attackers to guess passwords. |
3Canonical DebianOpensuse3Cloud Init Debian LinuxLeapJun 17, 2026 Feb 5, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 cloud-init through 19.4 relies on Mersenne Twister for a random password, which makes it easier for attackers to predict passwords, because rand_str in cloudinit/util.py calls the random.choice function. |