CVEs (129)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Canonical DebianGnu+5 more15Active Iq Unified Manager Debian LinuxEnterprise Linux+12 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream),...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitra...Show more |
7Canonical DebianGnu+4 more14Debian Linux Enterprise LinuxEnterprise Linux Atomic Host+11 moreJun 17, 2026 Jul 29, 2020 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure b...Show more |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Nextcloud OpensuseSuse3Backports Nextcloud ServerSuse Linux Enterprise ServerJun 17, 2026 Feb 4, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. |
3Opensuse SuseYast2 Rmt Project3Leap Suse Linux Enterprise ServerYast2 RmtNov 21, 2024 Jan 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A Inclusion of Sensitive Information in Log Files vulnerability in yast2-rmt of SUSE Linux Enterprise Server 15; openSUSE Leap allows local attackers to learn the password if they can access the log file. This issue affe...Show more |
3Debian PhpmyadminSuse3Debian Linux PhpmyadminSuse Linux Enterprise ServerJun 17, 2026 Jan 9, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In phpMyAdmin 4 before 4.9.4 and 5 before 5.0.1, SQL injection exists in the user accounts page. A malicious user could inject custom SQL in place of their own username when creating queries to this page. An attacker mus...Show more |
1Suse 1Suse Linux Enterprise Server Jun 17, 2026 Oct 7, 2019 N/A· v4 7.1 HIGH· v3 6.6 MEDIUM· v2 The /usr/sbin/pinger binary packaged with squid in SUSE Linux Enterprise Server 15 before and including version 4.8-5.8.1 and in SUSE Linux Enterprise Server 12 before and including 3.5.21-26.17.1 had squid:root, 0750 pe...Show more |
2Dcraw Project Suse3Dcraw Suse Linux Enterprise DesktopSuse Linux Enterprise ServerNov 21, 2024 Nov 29, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecif...Show more |
2Nodejs Suse4Node.js Suse Enterprise StorageSuse Linux Enterprise Server+1 moreDec 13, 2024 Nov 28, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very slowly keeping HTTP or HTTPS connection...Show more |
2Nodejs Suse4Node.js Suse Enterprise StorageSuse Linux Enterprise Server+1 moreNov 21, 2024 Nov 28, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicode data for the `path` option of an HTTP request, then data can be provi...Show more |
3Libwpd Project RedhatSuse3Enterprise Linux LibwpdSuse Linux Enterprise ServerNov 21, 2024 Nov 12, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h. |
4Debian LighttpdOpensuse+1 more5Backports Sle Debian LinuxLeap+2 moreNov 21, 2024 Nov 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration w...Show more |
4Canonical LinuxcontainersOpensuse+1 more6Caas Platform LeapLxc+3 moreJun 17, 2026 Aug 10, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise...Show more |