CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Cisofy Fedoraproject2Fedora LynisJun 17, 2026 Jun 18, 2020 N/A· v4 4.2 MEDIUM· v3 3.7 LOW· v2 CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of th...Show more |
3Cisofy DebianFedoraproject3Debian Linux FedoraLynisJun 17, 2026 Jun 18, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 In CISOfy Lynis 2.x through 2.7.5, the license key can be obtained by looking at the process list when a data upload is being performed. This license can be used to upload data to a central Lynis server. Although no data...Show more |
3Fedoraproject GnuOpensuse3Adns FedoraLeapNov 21, 2024 Jun 18, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered. |
3Fedoraproject GnuOpensuse3Adns FedoraLeapNov 21, 2024 Jun 18, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. Depending on the circum...Show more |
4Fedoraproject OpensuseOracle+1 more4Enterprise Manager Ops Center FedoraLeap+1 moreJun 17, 2026 Jun 18, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by t...Show more |
3Fedoraproject GnuOpensuse3Adns FedoraLeapNov 21, 2024 Jun 18, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise,...Show more |
3Fedoraproject GnuOpensuse3Adns FedoraLeapNov 21, 2024 Jun 18, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is incremented according to r, later. Rather one s...Show more |
An issue was discovered in adns before 1.5.2. It overruns reading a buffer if a domain ends with backslash. If the query domain ended with \, and adns_qf_quoteok_query was specified, qdparselabel would read additional by...Show more |
An issue was discovered in adns before 1.5.2. adns_rr_info mishandles a bogus *datap. The general pattern for formatting integers is to sprintf into a fixed-size buffer. This is correct if the input is in the right range...Show more |
An issue was discovered in adns before 1.5.2. It corrupts a pointer when a nameserver speaks first because of a wrong number of pointer dereferences. This bug may well be exploitable as a remote code execution. |
4Canonical CiscoDebian+1 more5Advanced Malware Protection For Endpoints Clam AntivirusDebian Linux+2 moreJun 17, 2026 Jun 18, 2020 N/A· v4 6.3 MEDIUM· v3 3.3 LOW· v2 A vulnerability in the endpoint software of Cisco AMP for Endpoints and Clam AntiVirus could allow an authenticated, local attacker to cause the running software to delete arbitrary files on the system. The vulnerability...Show more |
6Canonical DebianFedoraproject+3 more6Bind Debian LinuxFedora+3 moreJun 17, 2026 Jun 17, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or mor...Show more |
2Fedoraproject Golang2Fedora TextJun 17, 2026 Jun 17, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide...Show more |
2Cacti Fedoraproject2Cacti FedoraJun 17, 2026 Jun 17, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries. |
3Barton DebianFedoraproject3Debian Linux FedoraNgircdJun 17, 2026 Jun 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. |
2Fedoraproject Libemf Project2Fedora LibemfJun 17, 2026 Jun 15, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file. |
6Canonical FedoraprojectIntel+3 more694Celeron 1000m Celeron 1005mCeleron 1007u+691 moreJun 17, 2026 Jun 15, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 3.1 LOW· v3 6.0 MEDIUM· v2 In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once in...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 2.4 LOW· v3 3.5 LOW· v2 In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 5.7 MEDIUM· v3 4.9 MEDIUM· v2 In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in vers...Show more |