CVEs (10,001)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Debian Postgresql2Debian Linux PostgresqlNov 21, 2024 Jan 27, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The to_char function in PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to cause a denial of service (crash) or possibly ex...Show more |
2Debian Postgresql2Debian Linux PostgresqlNov 21, 2024 Jan 27, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 PostgreSQL before 9.0.19, 9.1.x before 9.1.15, 9.2.x before 9.2.10, 9.3.x before 9.3.6, and 9.4.x before 9.4.1 allows remote authenticated users to obtain sensitive column values by triggering constraint violation and th...Show more |
2Debian Virglrenderer Project2Debian Linux VirglrendererJun 17, 2026 Jan 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A double-free vulnerability in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service by triggering texture allocation failure, because vrend_renderer_resource_allocated_texture is...Show more |
2Debian Virglrenderer Project2Debian Linux VirglrendererJun 17, 2026 Jan 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A NULL pointer dereference in vrend_renderer.c in virglrenderer through 0.8.1 allows attackers to cause a denial of service via commands that attempt to launch a grid without previously providing a Compute Shader (CS). |
3Canonical DebianExiv23Debian Linux Exiv2Ubuntu LinuxJun 17, 2026 Jan 27, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Jp2Image::readMetadata() in jp2image.cpp in Exiv2 0.27.2, an input file can result in an infinite loop and hang, with high CPU consumption. Remote attackers could leverage this vulnerability to cause a denial of servi...Show more |
3Apereo DebianFedoraproject5.net Cas Client Debian LinuxFedora+2 moreNov 21, 2024 Jan 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow rem...Show more |
5Apache CanonicalDebian+2 more5Debian Linux FedoraSoftware Collections+2 moreJun 17, 2026 Jan 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it...Show more |
3Arm DebianFedoraproject4Debian Linux FedoraMbed Crypto+1 moreJun 17, 2026 Jan 23, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key v...Show more |
3Agendaless DebianOracle3Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxWaitressJun 17, 2026 Jan 22, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress through version 1.3.1 allows request smuggling by sending the Content-Length header twice. Waitress would header fold a double Content-Length header and due to being unable to cast the now comma separated value...Show more |
7Canonical DebianFedoraproject+4 more24Clustered Data Ontap Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian Linux+21 moreJun 17, 2026 Jan 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. |
6Debian FedoraprojectNetapp+3 more24Cloud Backup Clustered Data OntapCommunications Cloud Native Core Network Function Cloud Native Environment+21 moreJun 17, 2026 Jan 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. |
2Debian Opensuse2Debian Linux LibsolvJun 17, 2026 Jan 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 repodata_schema2id in repodata.c in libsolv before 0.7.6 has a heap-based buffer over-read via a last schema whose length is less than the length of the input schema. |
4Canonical DebianOpensuse+1 more5Backports Sle Debian LinuxLeap+2 moreJun 17, 2026 Jan 21, 2020 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly lead to privilege escalation. (Local users can also create a plain file named /tmp/storeB...Show more |
3Apt Cacher Ng Project DebianOpensuse4Apt Cacher Ng BackportsDebian Linux+1 moreJun 17, 2026 Jan 21, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 apt-cacher-ng through 3.3 allows local users to obtain sensitive information by hijacking the hardcoded TCP port. The /usr/lib/apt-cacher-ng/acngtool program attempts to connect to apt-cacher-ng via TCP on localhost port...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux Directory ServerDiskstation Manager+7 moreJun 17, 2026 Jan 21, 2020 N/A· v4 6.5 MEDIUM· v3 2.6 LOW· v2 All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character c...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSamba+1 moreJun 17, 2026 Jan 21, 2020 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 There is an issue in all samba 4.11.x versions before 4.11.5, all samba 4.10.x versions before 4.10.12 and all samba 4.9.x versions before 4.9.18, where the removal of the right to create or modify a subtree would not au...Show more |
4Canonical DebianOpensuse+1 more4Debian Linux LeapSalt+1 moreJun 17, 2026 Jan 17, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 In SaltStack Salt through 2019.2.0, the salt-api NET API with the ssh client enabled is vulnerable to command injection. This allows an unauthenticated attacker with network access to the API endpoint to execute arbitrar...Show more |
4Debian Libslirp ProjectOpensuse+1 more4Debian Linux LeapLibslirp+1 moreJun 17, 2026 Jan 16, 2020 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 tcp_emu in tcp_subr.c in libslirp 4.1.0, as used in QEMU 4.2.0, mismanages memory, as demonstrated by IRC DCC commands in EMU_IRC. This can cause a heap-based buffer overflow or other out-of-bounds access which can lead...Show more |
3Debian LinuxNetapp148300 Firmware 8700 FirmwareA400 Firmware+11 moreJun 17, 2026 Jan 16, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The flow_dissector feature in the Linux kernel 4.3 through 5.x before 5.3.10 has a device tracking vulnerability, aka CID-55667441c84f. This occurs because the auto flowlabel of a UDP IPv6 packet relies on a 32-bit hashr...Show more |
5Cacti DebianFedoraproject+2 more7Backports Sle CactiDebian Linux+4 moreJun 17, 2026 Jan 16, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in dat...Show more |