CVEs (1,898)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject Openfortivpn ProjectOpensuse4Backports Sle FedoraLeap+1 moreNov 21, 2024 Feb 27, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.examp...Show more |
3Fedoraproject Openfortivpn ProjectOpensuse4Backports Sle FedoraLeap+1 moreNov 21, 2024 Feb 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid ce...Show more |
3Fedoraproject Openfortivpn ProjectOpensuse4Backports Sle FedoraLeap+1 moreNov 21, 2024 Feb 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value. |
5Canonical DebianLinux+2 more12Active Iq Unified Manager Cloud BackupData Availability Services+9 moreNov 21, 2024 Feb 25, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An issue was discovered in the Linux kernel 3.16 through 5.5.6. set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it, aka CID-...Show more |
7Apache BlackberryDebian+4 more21Agile Engineering Data Management Agile PlmCommunications Element Manager+18 moreOct 27, 2025 Feb 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If su...Show more |
6Apache CanonicalDebian+3 more20Agile Engineering Data Management Agile Product Lifecycle ManagementCommunications Element Manager+17 moreNov 21, 2024 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a po...Show more |
5Apache DebianNetapp+2 more16Agile Engineering Data Management Agile PlmCommunications Instant Messaging Server+13 moreNov 21, 2024 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Feb 24, 2020 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 There is an OS command injection vulnerability in Ruby Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character `|`. |
5Debian FedoraprojectOpensuse+2 more7Backports Sle Debian LinuxFedora+4 moreNov 21, 2024 Feb 20, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution. |
3Opensuse ProftpdSiemens5Backports Sle LeapProftpd+2 moreNov 21, 2024 Feb 20, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function. |
4Debian FedoraprojectOpenidc+1 more4Debian Linux FedoraLeap+1 moreNov 21, 2024 Feb 20, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning. |
4Canonical LinuxNetapp+1 more10Active Iq Unified Manager Cloud BackupData Availability Services+7 moreNov 21, 2024 Feb 14, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 ext4_protect_reserved_inode in fs/ext4/block_validity.c in the Linux kernel through 5.5.3 allows attackers to cause a denial of service (soft lockup) via a crafted journal size. |
2Intel Opensuse3Backports LeapSoftware Guard Extensions SdkNov 21, 2024 Feb 13, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Improper initialization in the Intel(R) SGX SDK before v2.6.100.1 may allow an authenticated user to potentially enable escalation of privilege via local access. |
4Debian FedoraprojectOpensuse+1 more5Backports Sle Debian LinuxFedora+2 moreNov 21, 2024 Feb 12, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malfor...Show more |
5Canonical DebianLinuxfoundation+2 more5Debian Linux LeapOpenshift Container Platform+2 moreNov 21, 2024 Feb 12, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 runc through 1.0.0-rc9 has Incorrect Access Control leading to Escalation of Privileges, related to libcontainer/rootfs_linux.go. To exploit this, an attacker must be able to spawn two containers with custom volume-mount...Show more |
4Debian OpensuseQemu+1 more5Debian Linux Enterprise LinuxLeap+2 moreNov 21, 2024 Feb 11, 2020 N/A· v4 6.0 MEDIUM· v3 6.0 MEDIUM· v2 An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Bloc...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Feb 11, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (...Show more |
5Debian OpensuseOracle+2 more5Communications Diameter Signaling Router Debian LinuxLeap+2 moreNov 21, 2024 Feb 10, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When using certain mbstring functions to convert multibyte encodings, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause function mbfl_filt_conv_big...Show more |
5Debian OpensuseOracle+2 more5Communications Diameter Signaling Router Debian LinuxLeap+2 moreNov 21, 2024 Feb 10, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 When using fgetss() function to read data with stripping tags, in PHP versions 7.2.x below 7.2.27, 7.3.x below 7.3.14 and 7.4.x below 7.4.2 it is possible to supply data that will cause this function to read past the all...Show more |
4Canonical CephOpensuse+1 more4Ceph LeapOpenshift Container Storage+1 moreNov 21, 2024 Feb 7, 2020 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in the way the Ceph RGW Beast front-end handles unexpected disconnects. An authenticated attacker can abuse this flaw by making multiple disconnect attempts resulting in a permanent leak of a socket conn...Show more |