CVEs (57)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian OracleWireshark5Debian Linux Enterprise Manager Ops CenterInstantis Enterprisetrack+2 moreJun 17, 2026 Jun 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Infinite loop in DVB-S2-BB dissector in Wireshark 3.4.0 to 3.4.5 allows denial of service via packet injection or crafted capture file |
3Apache DebianOracle12Agile Plm Communications Cloud Native Core PolicyCommunications Cloud Native Core Security Edge Protection Proxy+9 moreJun 17, 2026 Mar 1, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tom...Show more |
3Apache DebianOracle12Agile Plm Communications Cloud Native Core PolicyCommunications Cloud Native Core Security Edge Protection Proxy+9 moreJun 17, 2026 Mar 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to...Show more |
4Apache DebianFedoraproject+1 more22Agile Engineering Data Management Banking ApisBanking Digital Experience+19 moreJun 17, 2026 Feb 24, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the...Show more |
4Apache DebianNetapp+1 more12Blockchain Platform Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Policy+9 moreJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 c...Show more |
2Apache Oracle18Api Gateway BatikBusiness Intelligence+15 moreJun 17, 2026 Nov 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache Batik is vulnerable to server-side request forgery, caused by improper input validation by the "xlink:href" attributes. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause...Show more |
3Apache DebianOracle4Debian Linux Instantis EnterprisetrackSd Wan Edge+1 moreJun 17, 2026 Oct 12, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol...Show more |
7Apache CanonicalDebian+4 more25Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+22 moreJun 17, 2026 Aug 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more |
7Apache CanonicalDebian+4 more13Clustered Data Ontap Communications Element ManagerCommunications Session Report Manager+10 moreJun 17, 2026 Aug 7, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory...Show more |
7Apache CanonicalDebian+4 more13Clustered Data Ontap Communications Element ManagerCommunications Session Report Manager+10 moreJun 17, 2026 Aug 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE |
7Apache CanonicalDebian+4 more18Agile Engineering Data Management Agile PlmBlockchain Platform+15 moreJun 17, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite lo...Show more |
6Apache CanonicalDebian+3 more14Agile Engineering Data Management Agile PlmCommunications Instant Messaging Server+11 moreJun 17, 2026 Jul 14, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were ma...Show more |
7Apache CanonicalDebian+4 more26Agile Engineering Data Management Agile PlmCommunications Cloud Native Core Binding Support Function+23 moreJun 17, 2026 May 20, 2020 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is...Show more |
7Canonical DebianNetapp+4 more18Communications Element Manager Communications Messaging ServerCommunications Network Charging And Control+15 moreJun 17, 2026 Apr 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQLite through 3.31.1 allows attackers to cause a denial of service (segmentation fault) via a malformed window-function query because the AggInfo object's initialization is mishandled. |
8Apache BroadcomCanonical+5 more14Brocade Fabric Operating System Communications Element ManagerCommunications Session Report Manager+11 moreJun 17, 2026 Apr 2, 2020 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request U...Show more |
6Apache CanonicalDebian+3 more11Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+8 moreJun 17, 2026 Apr 1, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server. |
7Apache BlackberryDebian+4 more21Agile Engineering Data Management Agile PlmCommunications Element Manager+18 moreJun 17, 2026 Feb 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If su...Show more |
6Apache CanonicalDebian+3 more20Agile Engineering Data Management Agile Product Lifecycle ManagementCommunications Element Manager+17 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a po...Show more |
5Apache DebianNetapp+2 more16Agile Engineering Data Management Agile PlmCommunications Instant Messaging Server+13 moreJun 17, 2026 Feb 24, 2020 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed...Show more |
2Apache Oracle3Cordova Inappbrowser Instantis EnterprisetrackRetail Xstore Point Of ServiceJun 17, 2026 Jan 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI. |