CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectOracle+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreJun 17, 2026 Jan 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. |
5Debian FedoraprojectGoogle+2 more7Backports Sle ChromeDebian Linux+4 moreJun 17, 2026 Jan 10, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more4Backports Sle ChromeDebian Linux+1 moreJun 17, 2026 Jan 10, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Gnome2Fedora GlibJun 17, 2026 Jan 9, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is...Show more |
6Canonical DebianE2fsprogs Project+3 more7Debian Linux E2fsprogsFedora+4 moreJun 17, 2026 Jan 8, 2020 N/A· v4 6.7 MEDIUM· v3 4.4 MEDIUM· v2 A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An...Show more |
2Fedoraproject Thekelleys2Dnsmasq FedoraJun 17, 2026 Jan 7, 2020 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jan 5, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results...Show more |
3Fedoraproject FontforgeOpensuse3Fedora FontforgeLeapJun 17, 2026 Jan 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c. |
3Fedoraproject RedhatZend3Enterprise Linux FedoraZend FrameworkNov 21, 2024 Jan 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Fo...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPillow+1 moreJun 17, 2026 Jan 3, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow. |
3Canonical FedoraprojectPython3Fedora PillowUbuntu LinuxJun 17, 2026 Jan 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc. |
2Fedoraproject Sensiolabs2Fedora SymfonyNov 21, 2024 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generati...Show more |
5Canonical DebianEglibc+2 more5Debian Linux EglibcFedora+2 moreNov 21, 2024 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. |
2Fedoraproject Gksu Polkit Project2Fedora Gksu PolkitNov 21, 2024 Dec 31, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue. |
2Fedoraproject Pureftpd2Fedora Pure FtpdJun 17, 2026 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c. |
2Fedoraproject Freeciv2Fedora FreecivNov 21, 2024 Dec 30, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exha...Show more |
4Debian FedoraprojectOpenstack+1 more4Debian Linux FedoraHorizon+1 moreNov 21, 2024 Dec 30, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value. |
2Fedoraproject Podofo Project2Fedora PodofoJun 17, 2026 Dec 30, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp. |