CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jul 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A NULL pointer dereference, or possible use-after-free flaw was found in Samba AD LDAP server in versions before 4.10.17, before 4.11.11 and before 4.12.4. Although some versions of Samba shipped with Red Hat Enterprise...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Jul 7, 2020 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) ta...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Jul 7, 2020 N/A· v4 8.8 HIGH· v3 6.1 MEDIUM· v2 An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jul 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in Xen through 4.13.x, allowing Arm guest OS users to cause a hypervisor crash because of a missing alignment check in VCPUOP_register_vcpu_info. The hypercall VCPUOP_register_vcpu_info is used by...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Jul 7, 2020 N/A· v4 6.5 MEDIUM· v3 4.7 MEDIUM· v2 An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-refer...Show more |
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapSamba+1 moreJun 17, 2026 Jul 6, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A use-after-free flaw was found in all samba LDAP server versions before 4.10.17, before 4.11.11, before 4.12.4 used in a AC DC configuration. A Samba LDAP user could use this flaw to crash samba. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jul 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash. |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Jul 2, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production. |
3Debian FedoraprojectLibraw3Debian Linux FedoraLibrawJun 17, 2026 Jul 2, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength)...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraGuacamoleJun 17, 2026 Jul 2, 2020 N/A· v4 6.7 MEDIUM· v3 6.2 MEDIUM· v2 Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs c...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraGuacamoleJun 17, 2026 Jul 2, 2020 N/A· v4 4.4 MEDIUM· v3 1.2 LOW· v2 Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in discl...Show more |
2Fedoraproject Github Flavored Markdown Project2Fedora Github Flavored MarkdownJun 17, 2026 Jul 1, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, cau...Show more |
3Fedoraproject NetappSquid Cache3Cloud Manager FedoraSquidJun 17, 2026 Jun 30, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a...Show more |
2Fedoraproject Squid Cache2Fedora SquidJun 17, 2026 Jun 30, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a...Show more |
4Fedoraproject Hylafax+ ProjectIfax+1 more5Backports Sle FedoraHylafax++2 moreJun 17, 2026 Jun 30, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root. |
2Fedoraproject Mediaarea2Fedora MediainfoJun 17, 2026 Jun 30, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing). |
5Canonical FedoraprojectLibvncserver Project+2 more10Fedora LeapLibvncserver+7 moreNov 21, 2024 Jun 30, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, cau...Show more |
5Canonical Coturn ProjectDebian+2 more5Coturn Debian LinuxFedora+2 moreJun 17, 2026 Jun 29, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use t...Show more |
3Fedoraproject NetappPutty3Fedora Oncommand Unified Manager Core PackagePuttyJun 17, 2026 Jun 29, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 PuTTY 0.68 through 0.73 has an Observable Discrepancy leading to an information leak in the algorithm negotiation. This allows man-in-the-middle attackers to target initial connection attempts (where no host key for the...Show more |
5Canonical FedoraprojectLinuxfoundation+2 more6Ceph Ceph StorageFedora+3 moreJun 17, 2026 Jun 26, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway). The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the...Show more |