CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Redhat 2Enterprise Linux LibvirtJun 17, 2026 Apr 28, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in qemuDomainGetStatsIOThread in qemu/qemu_driver.c in libvirt 4.10.0 though 6.x before 6.1.0. A memory leak was found in the virDomainListGetStats libvirt API that is responsible for retrieving d...Show more |
2Freeipa Redhat2Enterprise Linux FreeipaJun 17, 2026 Apr 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.4 MEDIUM· v2 A flaw was found in all ipa versions 4.x.x through 4.8.0. When sending a very long password (>= 1,000,000 characters) to the server, the password hashing process could exhaust memory and CPU leading to a denial of servic...Show more |
3Canonical GnuRedhat3Enterprise Linux GlibcUbuntu LinuxJun 17, 2026 Apr 17, 2020 N/A· v4 7.0 HIGH· v3 5.9 MEDIUM· v2 An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address...Show more |
5Debian NetappNtp+2 more17All Flash Fabric Attached Storage 8300 Firmware All Flash Fabric Attached Storage 8700 FirmwareAll Flash Fabric Attached Storage A400 Firmware+14 moreJun 17, 2026 Apr 17, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ntpd in ntp before 4.2.8p14 and 4.3.x before 4.3.100 allows an off-path attacker to block unauthenticated synchronization via a server mode packet with a spoofed source IP address, because transmissions are rescheduled e...Show more |
6Canonical FedoraprojectLibssh+3 more6Cloud Backup Enterprise LinuxFedora+3 moreJun 17, 2026 Apr 13, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and...Show more |
3Linux OpensuseRedhat3Enterprise Linux LeapLinux KernelJun 17, 2026 Apr 10, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.2 on the powerpc platform. arch/powerpc/kernel/idle_book3s.S does not have save/restore functionality for PNV_POWERSAVE_AMR, PNV_POWERSAVE_UAMOR, and PNV_POWERSAVE_AMO...Show more |
A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing se...Show more |
2Buildah Project Redhat3Buildah Enterprise LinuxOpenshift Container PlatformJun 17, 2026 Mar 31, 2020 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A path traversal flaw was found in Buildah in versions before 1.14.5. This flaw allows an attacker to trick a user into building a malicious container image hosted on an HTTP(s) server and then write files to the user's...Show more |
3Debian RedhatSystemd Project7Ceph Storage Debian LinuxDiscovery+4 moreJun 17, 2026 Mar 31, 2020 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap use-after-free vulnerability was found in systemd before version v245-rc1, where asynchronous Polkit queries are performed while handling dbus messages. A local unprivileged attacker can abuse this flaw to crash s...Show more |
2Dogtagpki Redhat2Dogtagpki Enterprise LinuxJun 17, 2026 Mar 20, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A Reflected Cross Site Scripting vulnerability was found in all pki-core 10.x.x versions, where the pki-ca module from the pki-core server. This flaw is caused by missing sanitization of the GET URL parameters. An attack...Show more |
2Dogtagpki Redhat2Dogtagpki Enterprise LinuxJun 17, 2026 Mar 20, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability was found in all pki-core 10.x.x versions, where the Key Recovery Authority (KRA) Agent Service did not properly sanitize recovery request search page, enabling a Reflected Cross Site Scripting (XSS) vuln...Show more |
2Dogtagpki Redhat2Dogtagpki Enterprise LinuxJun 17, 2026 Mar 18, 2020 N/A· v4 4.7 MEDIUM· v3 2.6 LOW· v2 A Reflected Cross Site Scripting flaw was found in all pki-core 10.x.x versions module from the pki-core server due to the CA Agent Service not properly sanitizing the certificate request page. An attacker could inject a...Show more |
2Postgresql Redhat4Decision Manager Enterprise LinuxPostgresql+1 moreJun 17, 2026 Mar 17, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects...Show more |
2Python Redhat3Enterprise Linux PythonSoftware CollectionsNov 21, 2024 Feb 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal...Show more |
3Fedoraproject RedhatZend3Enterprise Linux FedoraZend FrameworkNov 21, 2024 Feb 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SQL injection vulnerability in Zend Framework before 1.12.9, 2.2.x before 2.2.8, and 2.3.x before 2.3.3, when using the sqlsrv PHP extension, allows remote attackers to execute arbitrary SQL commands via a null byte. |
2Libpod Project Redhat3Enterprise Linux LibpodOpenshift Container PlatformJun 17, 2026 Feb 11, 2020 N/A· v4 5.9 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was discovered in Podman where it incorrectly allows containers when created to overwrite existing files in volumes, even if they are mounted as read-only. When a user runs a malicious container or a container bas...Show more |
4Debian OpensuseQemu+1 more5Debian Linux Enterprise LinuxLeap+2 moreJun 17, 2026 Feb 11, 2020 N/A· v4 6.0 MEDIUM· v3 6.0 MEDIUM· v2 An out-of-bounds heap buffer access flaw was found in the way the iSCSI Block driver in QEMU versions 2.12.0 before 4.2.1 handled a response coming from an iSCSI server while checking the status of a Logical Address Bloc...Show more |
2Linux Redhat2Enterprise Linux Linux KernelNov 21, 2024 Feb 11, 2020 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 Buffer overflow in the auerswald_probe function in the Auerswald Linux USB driver for the Linux kernel before 2.6.27 allows physically proximate attackers to execute arbitrary code, cause a denial of service via a crafte...Show more |
2Golang Redhat3Enterprise Linux GoOpenstackNov 21, 2024 Feb 8, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request that contains Content-Length and...Show more |
2Kde Redhat5Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server Eus+2 moreNov 21, 2024 Feb 8, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The CSS parser (khtml/css/cssparser.cpp) in Konqueror in KDE 4.7.3 allows remote attackers to cause a denial of service (crash) and possibly read memory via a crafted font face source, related to "type confusion." |