CVEs (137)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Postgresql Redhat4Enterprise Linux Jboss Enterprise Application PlatformPostgresql+1 moreJun 17, 2026 Jun 1, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A flaw was found in postgresql in versions before 13.3, before 12.7, before 11.12, before 10.17 and before 9.6.22. While modifying certain SQL array values, missing bounds checks let authenticated database users write ar...Show more |
6Debian FedoraprojectNetapp+3 more10Cloud Backup Communications Cloud Native Core Binding Support FunctionDebian Linux+7 moreJun 17, 2026 May 20, 2021 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive inform...Show more |
2Postgresql Redhat3Enterprise Linux PostgresqlSoftware CollectionsJun 17, 2026 Apr 1, 2021 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 An information leak was discovered in postgresql in versions before 13.2, before 12.6 and before 11.11. A user having UPDATE permission but not SELECT permission to a particular column could craft queries which, under so...Show more |
4Debian FedoraprojectPygments+1 more7Debian Linux Enterprise LinuxFedora+4 moreJun 17, 2026 Mar 23, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "except...Show more |
3Fedoraproject Http Proxy Agent ProjectRedhat4Enterprise Linux FedoraHttp Proxy Agent+1 moreJun 17, 2026 Mar 19, 2021 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service throu...Show more |
3Fedoraproject PostgresqlRedhat4Enterprise Linux FedoraPostgresql+1 moreJun 17, 2026 Feb 23, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerabili...Show more |
6Debian FedoraprojectLxml+3 more8Communications Offline Mediation Controller Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Dec 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A XSS vulnerability was discovered in python-lxml's clean module. The module's parser didn't properly imitate browsers, which caused different behaviors between the sanitizer and the user's page. A remote attacker could...Show more |
7Apache CanonicalDebian+4 more25Communications Element Manager Communications Session Report ManagerCommunications Session Route Manager+22 moreJun 17, 2026 Aug 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more |
2Postgresql Redhat4Decision Manager Enterprise LinuxPostgresql+1 moreJun 17, 2026 Mar 17, 2020 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A flaw was found in PostgreSQL's "ALTER ... DEPENDS ON EXTENSION", where sub-commands did not perform authorization checks. An authenticated attacker could use this flaw in certain configurations to perform drop objects...Show more |
2Python Redhat3Enterprise Linux PythonSoftware CollectionsNov 21, 2024 Feb 20, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal...Show more |
6Debian FedoraprojectNodejs+3 more13Debian Linux Enterprise LinuxEnterprise Linux Desktop+10 moreJun 17, 2026 Feb 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed |
5Debian NodejsOpensuse+2 more10Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxEnterprise Linux+7 moreJun 17, 2026 Feb 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate |
5Apache CanonicalDebian+2 more5Debian Linux FedoraSoftware Collections+2 moreJun 17, 2026 Jan 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it...Show more |
5Debian FedoraprojectPypa+2 more6Debian Linux FedoraOpenshift+3 moreNov 21, 2024 Nov 5, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. |
6Canonical DebianFedoraproject+3 more23Debian Linux Enterprise LinuxEnterprise Linux Desktop+20 moreJun 17, 2026 Oct 28, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI pro...Show more |
7Canonical DebianFedoraproject+4 more10Communications Operations Monitor Debian LinuxFedora+7 moreJun 17, 2026 Sep 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that u...Show more |
11Apache AppleCanonical+8 more18Debian Linux Diskstation ManagerEnterprise Linux+15 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-stream flag. These fra...Show more |
12Apache AppleCanonical+9 more23Clustered Data Ontap Communications Element ManagerDebian Linux+20 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without constraint; however, they...Show more |
12Apache AppleCanonical+9 more19Debian Linux Diskstation ManagerEnterprise Linux+16 moreJun 17, 2026 Aug 13, 2019 N/A· v4 6.5 MEDIUM· v3 6.8 MEDIUM· v2 Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, optionally Huffman en...Show more |
12Apache AppleCanonical+9 more22Big Ip Local Traffic Manager Debian LinuxDiskstation Manager+19 moreJun 17, 2026 Aug 13, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RFC requires that the peer reply with one...Show more |