CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 Oct 10, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link. |
3Debian FedoraprojectSympa3Debian Linux FedoraSympaJun 17, 2026 Oct 7, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraWireshark+1 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement. |
4Fedoraproject OpensuseOracle+1 more4Fedora LeapWireshark+1 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/pac...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts. |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum. |
2Fedoraproject Ruby Lang3Fedora RubyWebrickJun 17, 2026 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not checked the transfer-encoding header value rigorously. An attacker may...Show more |
3Debian FedoraprojectOpensc Project3Debian Linux FedoraOpenscJun 17, 2026 Oct 6, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher. |
3Debian FedoraprojectOpensc Project3Debian Linux FedoraOpenscJun 17, 2026 Oct 6, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init. |
3Debian FedoraprojectOpensc Project3Debian Linux FedoraOpenscJun 17, 2026 Oct 6, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Oct 5, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves. |
7Canonical DebianFedoraproject+4 more7Clustered Data Ontap Debian LinuxFedora+4 moreJun 17, 2026 Oct 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host conf...Show more |
8Canonical DebianFedoraproject+5 more8Clustered Data Ontap Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Oct 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to b...Show more |
3Artifex DebianFedoraproject3Debian Linux FedoraMupdfJun 17, 2026 Oct 2, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Artifex MuPDF before 1.18.0 has a heap based buffer over-write when parsing JBIG2 files allowing attackers to cause a denial of service. |
4Apache FedoraprojectGradle+1 more37Agile Engineering Data Management AntApi Gateway+34 moreJun 17, 2026 Oct 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file...Show more |
4Debian FedoraprojectLibproxy Project+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Sep 30, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header. |
2Fedoraproject Goxmldsig Project2Fedora GoxmldsigJun 17, 2026 Sep 29, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypass signature validation and pass off an altered file as a signed one. A...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Sep 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to creat...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Sep 27, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from PageGateway. Using crafted HTML, an attacker can elicit an XSS attack v...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Sep 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki. |