CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectLibslirp Project3Debian Linux FedoraLibslirpJun 17, 2026 Nov 26, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 6.3 MEDIUM· v3 5.4 MEDIUM· v2 A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly r...Show more |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local gu...Show more |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 6.4 MEDIUM· v3 3.3 LOW· v2 A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from othe...Show more |
3Debian FedoraprojectX11vnc Project3Debian Linux FedoraX11vncJun 17, 2026 Nov 25, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 25, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/...Show more |
4Debian FedoraprojectMusl Libc+1 more4Debian Linux FedoraGraalvm+1 moreJun 17, 2026 Nov 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow). |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Nov 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federa...Show more |
2Fedoraproject Redhat4Ceph Ceph StorageFedora+1 moreJun 17, 2026 Nov 23, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows a...Show more |
2Fedoraproject Xpdfreader2Fedora XpdfJun 17, 2026 Nov 21, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested...Show more |
3Debian FedoraprojectPdfresurrect Project3Debian Linux FedoraPdfresurrectJun 17, 2026 Nov 20, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version(). |
3Debian FedoraprojectLibvips3Debian Linux FedoraLibvipsJun 17, 2026 Nov 20, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address. |
2Drupal Fedoraproject2Drupal FedoraJun 17, 2026 Nov 20, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting co...Show more |
3Fedoraproject IbmOracle6Aix Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+3 moreJun 17, 2026 Nov 20, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296. |
2Fedoraproject Rclone2Fedora RcloneJun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords...Show more |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed. |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Nov 19, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Nov 19, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d4122754442...Show more |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Nov 19, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in mood...Show more |
2Fedoraproject Moodle2Fedora MoodleJun 17, 2026 Nov 19, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10. |