CVEs (1,898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreNov 21, 2024 Oct 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpMyAdmin processes SQL statements in the search feature. An attacker coul...Show more |
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreNov 21, 2024 Oct 10, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link. |
2Kde Opensuse3Backports Sle KdeconnectLeapNov 21, 2024 Oct 7, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use of large amounts of CPU, memory, or network connection slots, aka a Denial of Service attac...Show more |
3Debian OpensuseZabbix4Backports Sle Debian LinuxLeap+1 moreNov 21, 2024 Oct 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code. |
5Canonical DebianOpensuse+2 more10Debian Linux Enterprise LinuxEnterprise Linux Aus+7 moreNov 21, 2024 Oct 7, 2020 N/A· v4 6.6 MEDIUM· v3 6.5 MEDIUM· v2 Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws....Show more |
4Fedoraproject OpensuseOracle+1 more4Fedora LeapWireshark+1 moreNov 21, 2024 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/pac...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts. |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Oct 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum. |
6Debian LinuxNetapp+3 more6Debian Linux Enterprise LinuxH410c Firmware+3 moreNov 21, 2024 Oct 6, 2020 N/A· v4 7.2 HIGH· v3 7.5 HIGH· v2 A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the sys...Show more |
5Canonical DebianLinux+2 more5Debian Linux Enterprise LinuxLeap+2 moreNov 21, 2024 Oct 6, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial o...Show more |
A double free memory issue was found to occur in the libvirt API, in versions before 6.8.0, responsible for requesting information about network interfaces of a running QEMU domain. This flaw affects the polkit access co...Show more |
2Nextcloud Opensuse3Backports Sle LeapPreferred ProvidersNov 21, 2024 Oct 5, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times. |
7Canonical DebianFedoraproject+4 more7Clustered Data Ontap Debian LinuxFedora+4 moreNov 21, 2024 Oct 2, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when PHP is processing incoming HTTP cookie values, the cookie names are url-decoded. This may lead to cookies with prefixes like __Host conf...Show more |
8Canonical DebianFedoraproject+5 more8Clustered Data Ontap Communications Diameter Signaling RouterDebian Linux+5 moreNov 21, 2024 Oct 2, 2020 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 In PHP versions 7.2.x below 7.2.34, 7.3.x below 7.3.23 and 7.4.x below 7.4.11, when AES-CCM mode is used with openssl_encrypt() function with 12 bytes IV, only first 7 bytes of the IV is actually used. This can lead to b...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreNov 21, 2024 Oct 1, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 When recursing through graphical layers while scrolling, an iterator may have become invalid, resulting in a potential use-after-free. This occurs because the function APZCTreeManager::ComputeClippedCompositionBounds did...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreNov 21, 2024 Oct 1, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open redirect) rather than th...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreNov 21, 2024 Oct 1, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditable element. This vulne...Show more |
3Debian MozillaOpensuse5Debian Linux FirefoxFirefox Esr+2 moreNov 21, 2024 Oct 1, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl...Show more |
3Canonical DpdkOpensuse3Data Plane Development Kit LeapUbuntu LinuxNov 21, 2024 Sep 30, 2020 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in dpdk in versions before 18.11.10 and before 19.11.5. A flawed bounds checking in the copy_data function leads to a buffer overflow allowing an attacker in a virtual machine to write arbitrary data to...Show more |
3Canonical DpdkOpensuse3Data Plane Development Kit LeapUbuntu LinuxNov 21, 2024 Sep 30, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 An integer underflow in dpdk versions before 18.11.10 and before 19.11.5 in the `move_desc` function can lead to large amounts of CPU cycles being eaten up in a long running loop. An attacker could cause `move_desc` to g...Show more |