CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apple DebianFedoraproject+1 more8Debian Linux FedoraIpados+5 moreJun 17, 2026 Feb 24, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH...Show more |
5Cacti DebianFedoraproject+2 more5Cacti Debian LinuxFedora+2 moreJun 17, 2026 Feb 22, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege. |
2Fedoraproject Mongodb2Bson FedoraNov 21, 2024 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted string. NOTE: This issue...Show more |
2Fedoraproject Moped Project2Fedora MopedNov 21, 2024 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or perform a cross-site sc...Show more |
5Debian FedoraprojectOpensuse+2 more7Backports Sle Debian LinuxFedora+4 moreJun 17, 2026 Feb 20, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution. |
3Canonical FedoraprojectLibarchive3Fedora LibarchiveUbuntu LinuxJun 17, 2026 Feb 20, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 archive_read_support_format_rar5.c in libarchive before 3.4.2 attempts to unpack a RAR5 file with an invalid or corrupted header (such as a header size of zero), leading to a SIGSEGV or possibly unspecified other impact. |
4Debian FedoraprojectOpenidc+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Feb 20, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning. |
3Audiofile CanonicalFedoraproject3Audiofile FedoraUbuntu LinuxAug 13, 2025 Feb 19, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code vi...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An exploitable denial-of-service vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to server crash and denial of service. An attacker needs to...Show more |
4Canonical Coturn ProjectDebian+1 more4Coturn Debian LinuxFedora+1 moreJun 17, 2026 Feb 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An exploitable heap out-of-bounds read vulnerability exists in the way CoTURN 4.5.1.1 web server parses POST requests. A specially crafted HTTP POST request can lead to information leaks and other misbehavior. An attacke...Show more |
2Fedoraproject Pyyaml2Fedora PyyamlJun 17, 2026 Feb 19, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PyYAML 5.1 through 5.1.2 has insufficient restrictions on the load and load_all functions because of a class deserialization issue, e.g., Popen is a class in the subprocess module. NOTE: this issue exists because of an i...Show more |
3Fedoraproject RedhatZend3Enterprise Linux FedoraZend FrameworkNov 21, 2024 Feb 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte. |
3Debian FedoraprojectHorde3Debian Linux FedoraGroupwareJun 17, 2026 Feb 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. |
3Fedoraproject PcreSplunk3Fedora Pcre2Universal ForwarderJun 17, 2026 Feb 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulne...Show more |
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreJun 17, 2026 Feb 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malfor...Show more |
3Fedoraproject Gpgme ProjectRedhat9Enterprise Linux For Ibm Z Systems Enterprise Linux For Power Little EndianEnterprise Linux Server+6 moreJun 17, 2026 Feb 12, 2020 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 The proglottis Go wrapper before 0.1.1 for the GPGME library has a use-after-free, as demonstrated by use for container image pulls by Docker or CRI-O. This leads to a crash or potential code execution during GPG signatu...Show more |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Feb 12, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in whi...Show more |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Feb 12, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 lib-smtp in submission-login and lmtp in Dovecot 2.3.9 before 2.3.9.3 mishandles truncated UTF-8 data in command parameters, as demonstrated by the unauthenticated triggering of a submission-login infinite loop. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6Debian FedoraprojectGoogle+3 more8Backports Sle ChromeDebian Linux+5 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |