CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 Sep 21, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 Sep 21, 2020 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome...Show more |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 Sep 21, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more5Backports Sle ChromeDebian Linux+2 moreJun 17, 2026 Sep 21, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via socia...Show more |
3Fedoraproject NodejsOpensuse3Fedora LeapNode.jsJun 17, 2026 Sep 18, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes. |
2Fedoraproject Nodejs2Fedora Node.jsJun 17, 2026 Sep 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js < 14.11.0 is vulnerable to HTTP denial of service (DoS) attacks based on delayed requests submission which can make the server unable to accept new connections. |
3Fedoraproject NodejsOpensuse3Fedora LeapNode.jsJun 17, 2026 Sep 18, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perf...Show more |
5Canonical DebianFedoraproject+2 more5Dbi Debian LinuxFedora+2 moreJun 17, 2026 Sep 17, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer der...Show more |
4Canonical Cryptsetup ProjectFedoraproject+1 more4Cryptsetup Enterprise LinuxFedora+1 moreJun 17, 2026 Sep 16, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in s...Show more |
4Debian FedoraprojectOpensuse+1 more4Database Interface Debian LinuxFedora+1 moreJun 17, 2026 Sep 16, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A buffer overflow was found in perl-DBI < 1.643 in DBI.xs. A local attacker who is able to supply a string longer than 300 characters could cause an out-of-bounds write, affecting the availability of the service or integ...Show more |
5Canonical DebianFedoraproject+2 more5Database Interface Debian LinuxFedora+2 moreJun 17, 2026 Sep 16, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An untrusted pointer dereference flaw was found in Perl-DBI < 1.643. A local attacker who is able to manipulate calls to dbd_db_login6_sv() could cause memory corruption, affecting the service's availability. |
4Debian FedoraprojectLinux+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Sep 16, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integ...Show more |
6Canonical DebianFedoraproject+3 more10.net .net CoreBrotli+7 moreJun 17, 2026 Sep 15, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A buffer overflow exists in the Brotli library versions prior to 1.0.8 where an attacker controlling the input length of a "one-shot" decompression request to a script can trigger a crash, which happens when copying over...Show more |
2Fedoraproject X.org2Fedora Libx11Jun 17, 2026 Sep 11, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application compiled with libX11 to crash, or in some cases, result in arbitrary co...Show more |
3Fedoraproject MicrosoftRedhat6Asp.net Core Enterprise LinuxEnterprise Linux Aus+3 moreJun 17, 2026 Sep 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 <p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parser decodes entire cookie strings which could allow a malicious attacker...Show more |
3Action View Project DebianFedoraproject3Action View Debian LinuxFedoraJun 17, 2026 Sep 11, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Action View before versions 5.2.4.4 and 6.0.3.3 there is a potential Cross-Site Scripting (XSS) vulnerability in Action View's translation helpers. Views that allow the user to control the default (not found) value of...Show more |
3Debian FedoraprojectZeromq3Debian Linux FedoraLibzmqJun 17, 2026 Sep 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, are impacted. If a raw TCP socket is opened and connected to an endpoint...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack ex...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Sep 9, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 In the Linux kernel through 5.8.7, local attackers able to inject conntrack netlink configuration could overflow a local buffer, causing crashes or triggering use of incorrect protocol numbers in ctnetlink_parse_tuple_fi...Show more |
3Fedoraproject OpensuseSamba3Cifs Utils FedoraLeapJun 17, 2026 Sep 9, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. An attacker able to invoke mount.cifs with special permission, such as v...Show more |