CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Jasper Project2Fedora JasperJun 17, 2026 Dec 11, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integr...Show more |
3Debian FedoraprojectSympa3Debian Linux FedoraSympaJun 17, 2026 Dec 10, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun. |
3Fedoraproject GnuNetapp3Binutils FedoraOntap Select Deploy Administration UtilityJun 17, 2026 Dec 9, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file. |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Dec 9, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by...Show more |
6Broadcom DebianFedoraproject+3 more128300 Firmware 8700 FirmwareA400 Firmware+9 moreJun 17, 2026 Dec 9, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b. |
5Broadcom DebianFedoraproject+2 more118300 Firmware 8700 FirmwareA400 Firmware+8 moreJun 17, 2026 Dec 9, 2020 N/A· v4 4.4 MEDIUM· v3 2.1 LOW· v2 A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9...Show more |
3Fedoraproject OraclePytest3Fedora PyZfs Storage Appliance KitJun 17, 2026 Dec 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to th...Show more |
4Apple DebianFedoraproject+1 more11Debian Linux FedoraIcloud+8 moreJun 17, 2026 Dec 8, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 fo...Show more |
2Fedoraproject Imagemagick2Fedora ImagemagickJun 17, 2026 Dec 8, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. Th...Show more |
8Debian FedoraprojectNetapp+5 more44Active Iq Unified Manager Aff A250 FirmwareApi Gateway+41 moreJun 17, 2026 Dec 8, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of...Show more |
3Debian FedoraprojectLibpng4Debian Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Dec 8, 2020 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application ava...Show more |
3Awstats DebianFedoraproject3Awstats Debian LinuxFedoraJun 17, 2026 Dec 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete f...Show more |
3Fedoraproject GnuNetapp3E Series Santricity Os Controller FedoraGlibcJun 17, 2026 Dec 4, 2020 N/A· v4 4.8 MEDIUM· v3 2.1 LOW· v2 The iconv function in the GNU C Library (aka glibc or libc6) 2.30 to 2.32, when converting UCS4 text containing an irreversible character, fails an assertion in the code path and aborts the program, potentially resulting...Show more |
6Debian FedoraprojectLxml+3 more8Communications Offline Mediation Controller Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Dec 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could...Show more |
A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can lead to an impact to a...Show more |
6Apache FasterxmlFedoraproject+3 more39Agile Plm Agile Product Lifecycle Management Integration PackBanking Apis+36 moreJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is...Show more |
2Fedoraproject Webkitgtk2Fedora WebkitgtkJun 17, 2026 Dec 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs t...Show more |
3Debian FedoraprojectLinuxfoundation3Containerd Debian LinuxFedoraJun 17, 2026 Dec 1, 2020 N/A· v4 5.2 MEDIUM· v3 3.6 LOW· v2 containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network contai...Show more |
2Audacityteam Fedoraproject2Audacity FedoraJun 17, 2026 Nov 30, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary a...Show more |
3Debian FedoraprojectLibslirp Project3Debian Linux FedoraLibslirpJun 17, 2026 Nov 26, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. |