CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Tiny Http Project2Fedora Tiny HttpJun 17, 2026 Dec 31, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header. |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Dec 28, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishand...Show more |
3Debian FedoraprojectWavpack3Debian Linux FedoraWavpackJun 17, 2026 Dec 28, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 WavPack 5.3.0 has an out-of-bounds write in WavpackPackSamples in pack_utils.c because of an integer overflow in a malloc argument. NOTE: some third-parties claim that there are later "unofficial" releases through 5.3.2,...Show more |
2Fedoraproject Xpdfreader2Fedora XpdfJun 17, 2026 Dec 26, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function. |
3Canonical FedoraprojectGnome3Fedora Gdk PixbufUbuntu LinuxJun 17, 2026 Dec 26, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The...Show more |
2Fedoraproject Opensmtpd2Fedora OpensmtpdJun 17, 2026 Dec 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, becaus...Show more |
2Fedoraproject Opensmtpd2Fedora OpensmtpdJun 17, 2026 Dec 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 smtpd/table.c in OpenSMTPD before 6.8.0p1 lacks a certain regfree, which might allow attackers to trigger a "very significant" memory leak via messages to an instance that performs many regex lookups. |
4Fedoraproject GrafanaRedhat+1 more6Enterprise Linux FedoraGrafana+3 moreJun 17, 2026 Dec 21, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A signature verification vulnerability exists in crewjam/saml. This flaw allows an attacker to bypass SAML Authentication. The highest threat from this vulnerability is to confidentiality, integrity, as well as system av...Show more |
2Fedoraproject Redhat5Ceph Ceph StorageFedora+2 moreJun 17, 2026 Dec 18, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 User credentials can be manipulated and stolen by Native CephFS consumers of OpenStack Manila, resulting in potential privilege escalation. An Open Stack Manila user can request access to a share to an arbitrary cephx us...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are h...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki 1.33.0 and later. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibi...Show more |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights,...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Dec 18, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML...Show more |
4Apache DebianFedoraproject+1 more4Debian Linux FedoraStruts+1 moreJun 17, 2026 Dec 16, 2020 N/A· v4 6.8 MEDIUM· v3 6.4 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, is vulnerable to an Arbitrary File Deletion on the local host when unmarshalling. The vulnerability may allow a remo...Show more |
4Apache DebianFedoraproject+1 more4Debian Linux FedoraStruts+1 moreJun 17, 2026 Dec 16, 2020 N/A· v4 7.7 HIGH· v3 5.0 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remot...Show more |
2Fedoraproject Jsonparser Project2Fedora JsonparserJun 17, 2026 Dec 15, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call. |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Dec 15, 2020 N/A· v4 6.0 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Xen through 4.14.x. Nodes in xenstore have an ownership. In oxenstored, a owner could give a node away. However, node ownership has quota implications. Any guest can run another guest out of qu...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Dec 15, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request, not all tracking information is freed. A guest can cause unbounded memory usage in oxenstored. This can lead to a syst...Show more |