Home/Product/opensuse backports sle
Product

opensuse backports sle

326 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2020-6557
all versions
Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoo
6.5MEDIUM
CVE-2020-16011
all versions
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the re
9.6CRITICAL
CVE-2020-16009
all versions
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap c
8.8HIGH
CVE-2020-16008
all versions
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack cor
8.8HIGH
CVE-2020-16007
all versions
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate
7.8HIGH
CVE-2020-16006
all versions
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap c
8.8HIGH
CVE-2020-16005
all versions
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit
8.8HIGH
CVE-2020-16004
all versions
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap cor
8.8HIGH
CVE-2020-16003
all versions
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruptio
8.8HIGH
CVE-2020-16002
all versions
Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption
8.8HIGH
CVE-2020-16001
all versions
Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-16000
all versions
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit hea
8.8HIGH
CVE-2020-15999
all versions
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap cor
9.6CRITICAL
CVE-2020-15992
all versions
Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised
8.8HIGH
CVE-2020-15991
all versions
Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the render
8.8HIGH
CVE-2020-15990
all versions
Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer proce
8.8HIGH
CVE-2020-15989
all versions
Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive info
5.5MEDIUM
CVE-2020-15988
all versions
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convi
6.3MEDIUM
CVE-2020-15987
all versions
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-15986
all versions
Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption
6.5MEDIUM
CVE-2020-15985
all versions
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security UI via a
6.5MEDIUM
CVE-2020-15984
all versions
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the co
6.5MEDIUM
CVE-2020-15983
all versions
Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass conten
7.8HIGH
CVE-2020-15982
all versions
Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensi
6.5MEDIUM
CVE-2020-15981
all versions
Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive infor
6.5MEDIUM
CVE-2020-15980
all versions
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass na
7.8HIGH
CVE-2020-15979
all versions
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap co
8.8HIGH
CVE-2020-15978
all versions
Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had com
8.8HIGH
CVE-2020-15977
all versions
Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potenti
6.5MEDIUM
CVE-2020-15976
all versions
Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap co
8.8HIGH
CVE-2020-15975
all versions
Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corru
8.8HIGH
CVE-2020-15974
all versions
Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted
8.8HIGH
CVE-2020-15973
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to i
6.5MEDIUM
CVE-2020-15972
all versions
Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption vi
8.8HIGH
CVE-2020-15971
all versions
Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer proce
8.8HIGH
CVE-2020-15970
all versions
Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to
8.8HIGH
CVE-2020-15969
all versions
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-15968
all versions
Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption vi
8.8HIGH
CVE-2020-15967
all versions
Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially perform a sandbox escap
8.8HIGH
CVE-2020-25829
all versions
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can caus
7.5HIGH
CVE-2020-15229
all versions
Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of
8.2HIGH
CVE-2020-26935
all versions
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was dis
9.8CRITICAL
CVE-2020-26934
all versions
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
6.1MEDIUM
CVE-2020-26164
all versions
In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use o
5.5MEDIUM
CVE-2020-11800
all versions
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
9.8CRITICAL
CVE-2020-8228
all versions
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
5.3MEDIUM
CVE-2019-11556
all versions
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
6.1MEDIUM
CVE-2020-6576
all versions
Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap c
8.8HIGH
CVE-2020-6575
all versions
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potenti
8.3HIGH
CVE-2020-6574
all versions
Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potential
7.8HIGH
CVE-2020-6573
all versions
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the rende
9.6CRITICAL
CVE-2020-6571
all versions
Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofin
4.3MEDIUM
CVE-2020-6570
all versions
Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive inf
4.3MEDIUM
CVE-2020-6569
all versions
Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer proce
6.3MEDIUM
CVE-2020-6568
all versions
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to
6.5MEDIUM
CVE-2020-6567
all versions
Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a re
6.5MEDIUM
CVE-2020-6566
all versions
Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin dat
6.5MEDIUM
CVE-2020-6565
all versions
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the conte
6.5MEDIUM
CVE-2020-6564
all versions
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents
6.5MEDIUM
CVE-2020-6563
all versions
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to
6.5MEDIUM
CVE-2020-6562
all versions
Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin dat
6.5MEDIUM
CVE-2020-6561
all versions
Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak c
6.5MEDIUM
CVE-2020-6560
all versions
Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin
6.5MEDIUM
CVE-2020-6559
all versions
Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap co
8.8HIGH
CVE-2020-6558
all versions
Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass naviga
6.5MEDIUM
CVE-2020-15966
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to
4.3MEDIUM
CVE-2020-15965
all versions
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory
8.8HIGH
CVE-2020-15964
all versions
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit hea
8.8HIGH
CVE-2020-15963
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to
9.6CRITICAL
CVE-2020-15962
all versions
Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform
8.8HIGH
CVE-2020-15961
all versions
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to i
9.6CRITICAL
CVE-2020-15960
all versions
Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bo
8.8HIGH
CVE-2020-15959
all versions
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user t
4.3MEDIUM
CVE-2020-25032
all versions
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access pr
7.5HIGH
CVE-2020-14352
all versions
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize p
8.0HIGH
CVE-2020-24972
all versions
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because op
8.8HIGH
CVE-2020-24614
all versions
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code.
8.8HIGH
CVE-2020-8233
all versions
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute ar
8.8HIGH
CVE-2020-8026
all versions
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15
8.4HIGH
CVE-2020-17353
all versions
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on
9.8CRITICAL
CVE-2020-16118
all versions
In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client cr
7.5HIGH
CVE-2020-15917
all versions
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
9.8CRITICAL
CVE-2020-6536
all versions
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to insta
4.3MEDIUM
CVE-2020-6535
all versions
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the ren
6.1MEDIUM
CVE-2020-6534
all versions
Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corrup
8.8HIGH
CVE-2020-6533
all versions
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a
8.8HIGH
CVE-2020-6531
all versions
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-
4.3MEDIUM
CVE-2020-6530
all versions
Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to
8.8HIGH
CVE-2020-6529
all versions
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position
4.3MEDIUM
CVE-2020-6528
all versions
Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents
4.3MEDIUM
CVE-2020-6527
all versions
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security
4.3MEDIUM
CVE-2020-6526
all versions
Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigati
6.5MEDIUM
CVE-2020-6525
all versions
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corrupti
8.8HIGH
CVE-2020-6524
all versions
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corr
8.8HIGH
CVE-2020-6523
all versions
Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruptio
8.8HIGH
CVE-2020-6522
all versions
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to pot
9.6CRITICAL
CVE-2020-6521
all versions
Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentiall
6.5MEDIUM
CVE-2020-6520
all versions
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption vi
8.8HIGH
CVE-2020-6519
all versions
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a craf
6.5MEDIUM
CVE-2020-6518
all versions
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to u
8.8HIGH
CVE-2020-6517
all versions
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corru
8.8HIGH
CVE-2020-6516
all versions
Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTM
4.3MEDIUM
CVE-2020-6515
all versions
Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruptio
8.8HIGH
CVE-2020-6514
all versions
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position
6.5MEDIUM
CVE-2020-6513
all versions
Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corrup
8.8HIGH
CVE-2020-6512
all versions
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a
8.8HIGH
CVE-2020-6511
all versions
Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin
6.5MEDIUM
CVE-2020-6510
all versions
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit h
7.8HIGH
CVE-2020-15396
all versions
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning
7.8HIGH
CVE-2020-8164
all versions
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply
7.5HIGH
CVE-2020-14004
all versions
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) execut
7.8HIGH
CVE-2020-13696
all versions
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to
4.4MEDIUM
CVE-2020-6496
all versions
Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sand
8.8HIGH
CVE-2020-6494
all versions
Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the content
6.5MEDIUM
CVE-2020-13379
all versions
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauth
8.2HIGH
CVE-2020-13614
all versions
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
5.9MEDIUM
CVE-2020-6491
all versions
Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof securit
6.5MEDIUM
CVE-2020-6490
all versions
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write
4.3MEDIUM
CVE-2020-6489
all versions
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced
4.3MEDIUM
CVE-2020-6488
all versions
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation
4.3MEDIUM
CVE-2020-6487
all versions
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation
6.5MEDIUM
CVE-2020-6486
all versions
Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigati
6.5MEDIUM
CVE-2020-6485
all versions
Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised
6.5MEDIUM
CVE-2020-6484
all versions
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation
6.5MEDIUM
CVE-2020-6483
all versions
Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation
6.5MEDIUM
CVE-2020-6482
all versions
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user
6.5MEDIUM
CVE-2020-6481
all versions
Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform doma
6.5MEDIUM
CVE-2020-6480
all versions
Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation
6.5MEDIUM
CVE-2020-6479
all versions
Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via
6.5MEDIUM
CVE-2020-6478
all versions
Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI
6.5MEDIUM
CVE-2020-6477
all versions
Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privi
7.8HIGH
CVE-2020-6476
all versions
Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to in
6.5MEDIUM
CVE-2020-6475
all versions
Incorrect implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via
6.5MEDIUM
CVE-2020-6474
all versions
Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption vi
8.8HIGH
CVE-2020-6473
all versions
Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially se
6.5MEDIUM
CVE-2020-6472
all versions
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user
6.5MEDIUM
CVE-2020-6471
all versions
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user
9.6CRITICAL
CVE-2020-6470
all versions
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject
6.1MEDIUM
CVE-2020-6469
all versions
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user
9.6CRITICAL
CVE-2020-6468
all versions
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a
8.8HIGH
CVE-2020-6467
all versions
Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-6466
all versions
Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process
9.6CRITICAL
CVE-2020-6465
all versions
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the
9.6CRITICAL
CVE-2020-6463
all versions
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-10995
all versions
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the
7.5HIGH
CVE-2020-12244
all versions
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lackin
7.5HIGH
CVE-2020-12108
all versions
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
6.5MEDIUM
CVE-2020-12672
all versions
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
7.5HIGH
CVE-2020-12641
all versions
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configu
9.8CRITICAL
CVE-2020-12640
all versions
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name t
9.8CRITICAL
CVE-2020-12625
all versions
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.ph
6.1MEDIUM
CVE-2020-12050
all versions
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalat
7.0HIGH
CVE-2020-12137
all versions
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribu
6.1MEDIUM
CVE-2020-12066
all versions
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
7.5HIGH
CVE-2020-6454
all versions
Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a maliciou
8.8HIGH
CVE-2020-6451
all versions
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruptio
8.8HIGH
CVE-2020-6450
all versions
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruptio
8.8HIGH
CVE-2020-6448
all versions
Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a
8.8HIGH
CVE-2020-6447
all versions
Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced
8.8HIGH
CVE-2020-6444
all versions
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruptio
6.3MEDIUM
CVE-2020-6438
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to i
4.3MEDIUM
CVE-2020-6436
all versions
Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap c
8.8HIGH
CVE-2020-6434
all versions
Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption
8.8HIGH
CVE-2020-6430
all versions
Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a
8.8HIGH
CVE-2020-6423
all versions
Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption vi
8.8HIGH
CVE-2020-11653
all versions
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when co
7.5HIGH
CVE-2019-20637
all versions
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear
7.5HIGH
CVE-2019-14905
all versions
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, wher
5.6MEDIUM
CVE-2020-6095
all versions
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A spec
7.5HIGH
CVE-2020-1772
all versions
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s),
6.5MEDIUM
CVE-2020-1770
all versions
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((O
2.4LOW
CVE-2020-1769
all versions
In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered a
3.5LOW
CVE-2020-6449
all versions
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-6429
all versions
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-6428
all versions
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-6427
all versions
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-6426
all versions
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap c
6.5MEDIUM
CVE-2020-6424
all versions
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-6422
all versions
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2020-10593
all versions
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory
7.5HIGH
CVE-2020-10803
all versions
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be us
5.4MEDIUM
CVE-2020-10802
all versions
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters ar
8.0HIGH
CVE-2020-10804
all versions
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username
8.0HIGH
CVE-2019-12921
all versions
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image b
6.5MEDIUM
CVE-2019-3698
all versions
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE L
5.7MEDIUM
CVE-2020-7043
all versions
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation bec
9.1CRITICAL
CVE-2020-7042
all versions
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation b
5.3MEDIUM
CVE-2020-7041
all versions
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation b
5.3MEDIUM
CVE-2020-9273
all versions
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-f
8.8HIGH
CVE-2020-9272
all versions
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
7.5HIGH
CVE-2020-8955
all versions
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buf
9.8CRITICAL
CVE-2020-6416
all versions
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit he
8.8HIGH
CVE-2020-6415
all versions
Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit
8.8HIGH
CVE-2020-6414
all versions
Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass naviga
8.8HIGH
CVE-2020-6413
all versions
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators v
8.8HIGH
CVE-2020-6412
all versions
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform
5.4MEDIUM
CVE-2020-6408
all versions
Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sens
6.5MEDIUM
CVE-2020-6404
all versions
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap
8.8HIGH
CVE-2020-6403
all versions
Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents
4.3MEDIUM
CVE-2020-6402
all versions
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a us
8.8HIGH
CVE-2020-6401
all versions
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform
6.5MEDIUM
CVE-2020-6400
all versions
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data vi
6.5MEDIUM
CVE-2020-6399
all versions
Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin
6.5MEDIUM
CVE-2020-6398
all versions
Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap c
8.8HIGH
CVE-2020-6397
all versions
Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via
6.5MEDIUM
CVE-2020-6396
all versions
Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the
4.3MEDIUM
CVE-2020-6394
all versions
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content securi
5.4MEDIUM
CVE-2020-6393
all versions
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin dat
6.5MEDIUM
CVE-2020-6392
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to i
4.3MEDIUM
CVE-2020-6391
all versions
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass cont
4.3MEDIUM
CVE-2020-6390
all versions
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit hea
8.8HIGH
CVE-2020-6385
all versions
Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolati
8.8HIGH
CVE-2020-6382
all versions
Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corrupti
8.8HIGH
CVE-2020-6381
all versions
Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potenti
8.8HIGH
CVE-2020-8118
all versions
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a
5.0MEDIUM
CVE-2019-15623
all versions
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Loo
5.3MEDIUM
CVE-2019-3693
all versions
A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12;
7.7HIGH
CVE-2019-3692
all versions
The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user
7.7HIGH
CVE-2020-7040
all versions
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly
8.1HIGH
CVE-2019-18932
all versions
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temp
7.0HIGH
CVE-2020-7106
all versions
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, use
6.1MEDIUM
CVE-2020-6377
all versions
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption v
8.8HIGH
CVE-2019-13767
all versions
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer p
8.8HIGH
CVE-2020-1765
all versions
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicket
3.5LOW
CVE-2020-6615
all versions
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dy
6.5MEDIUM
CVE-2020-6614
all versions
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
8.1HIGH
CVE-2020-6613
all versions
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
8.1HIGH
CVE-2020-6612
all versions
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
8.1HIGH
CVE-2020-6611
all versions
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
6.5MEDIUM
CVE-2020-6609
all versions
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
8.8HIGH
CVE-2019-18179
all versions
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and
4.3MEDIUM
CVE-2019-5846
all versions
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
6.5MEDIUM
CVE-2019-5845
all versions
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
6.5MEDIUM
CVE-2019-5844
all versions
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
6.5MEDIUM
CVE-2019-14864
all versions
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_l
6.5MEDIUM
CVE-2019-20015
all versions
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LW
6.5MEDIUM
CVE-2019-20014
all versions
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
8.8HIGH
CVE-2019-20013
all versions
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode
6.5MEDIUM
CVE-2019-20012
all versions
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HA
6.5MEDIUM
CVE-2019-20011
all versions
An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
8.8HIGH
CVE-2019-20010
all versions
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
8.8HIGH
CVE-2019-20009
all versions
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_de
6.5MEDIUM
CVE-2019-19925
all versions
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
7.5HIGH
CVE-2019-19923
all versions
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-h
7.5HIGH
CVE-2019-19926
all versions
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRew
7.5HIGH
CVE-2019-19918
all versions
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
7.8HIGH
CVE-2019-19917
all versions
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
7.8HIGH
CVE-2019-19880
all versions
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant intege
7.5HIGH
CVE-2019-16779
all versions
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted
5.8MEDIUM
CVE-2019-13764
all versions
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corrupti
8.8HIGH
CVE-2019-13745
all versions
Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin dat
6.5MEDIUM
CVE-2019-13734
all versions
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corrupt
8.8HIGH
CVE-2019-5164
all versions
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network
7.8HIGH
CVE-2019-14856
all versions
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
6.5MEDIUM
CVE-2019-13719
all versions
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via
4.3MEDIUM
CVE-2019-13718
all versions
Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofin
4.3MEDIUM
CVE-2019-13717
all versions
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via
4.3MEDIUM
CVE-2019-13716
all versions
Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navi
4.3MEDIUM
CVE-2019-13715
all versions
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform
4.3MEDIUM
CVE-2019-13714
all versions
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote att
6.1MEDIUM
CVE-2019-13710
all versions
Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass
4.3MEDIUM
CVE-2019-13709
all versions
Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download r
6.5MEDIUM
CVE-2019-13708
all versions
Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the co
4.3MEDIUM
CVE-2019-13706
all versions
Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap
7.8HIGH
CVE-2019-13704
all versions
Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content s
4.3MEDIUM
CVE-2019-13703
all versions
Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoo
4.3MEDIUM
CVE-2019-13702
all versions
Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform pr
7.8HIGH
CVE-2019-13701
all versions
Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of t
4.3MEDIUM
CVE-2019-13700
all versions
Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromise
8.8HIGH
CVE-2019-13699
all versions
Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process
8.8HIGH
CVE-2019-18622
all versions
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack th
9.8CRITICAL
CVE-2019-10206
all versions
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, p
6.5MEDIUM
CVE-2019-17545
all versions
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
9.8CRITICAL
CVE-2019-17455
all versions
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read an
9.8CRITICAL
CVE-2019-14846
all versions
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at
7.8HIGH
CVE-2019-11779
all versions
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consist
6.5MEDIUM
CVE-2019-16159
all versions
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support
7.5HIGH
CVE-2016-10937
all versions
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
7.5HIGH
CVE-2019-14744
all versions
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user
7.8HIGH
CVE-2019-5060
all versions
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XP
8.8HIGH
CVE-2019-5059
all versions
An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially craft
8.8HIGH
CVE-2019-5058
all versions
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially craft
8.8HIGH
CVE-2019-5057
all versions
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially craft
8.8HIGH
CVE-2019-5459
all versions
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
7.1HIGH
CVE-2019-14274
all versions
MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.
5.5MEDIUM
CVE-2019-13962
all versions
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read bec
9.8CRITICAL
CVE-2019-13616
all versions
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_bli
8.1HIGH
CVE-2019-13602
all versions
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote
7.8HIGH
CVE-2019-5052
all versions
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cau
8.8HIGH
CVE-2019-5051
all versions
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing err
8.8HIGH
CVE-2019-5802
all versions
Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform d
6.5MEDIUM
CVE-2019-5796
all versions
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap co
7.5HIGH
CVE-2019-5794
all versions
Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform
6.5MEDIUM
CVE-2019-12221
all versions
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2
6.5MEDIUM
CVE-2019-12098
all versions
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-midd
7.4HIGH
CVE-2019-11506
all versions
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATL
8.8HIGH
CVE-2019-11505
all versions
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBIm
8.8HIGH
CVE-2019-11474
all versions
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application cras
6.5MEDIUM
CVE-2019-11358
all versions
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Objec
6.1MEDIUM
CVE-2019-9499
all versions
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on impo
8.1HIGH
CVE-2019-9498
all versions
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported
8.1HIGH
CVE-2019-9495
all versions
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access pa
3.7LOW
CVE-2019-9494
all versions
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing d
5.9MEDIUM
CVE-2019-11008
all versions
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, w
8.8HIGH
CVE-2019-11007
all versions
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, w
8.1HIGH
CVE-2019-10740
all versions
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within
4.3MEDIUM
CVE-2019-9896
all versions
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the sam
7.8HIGH
CVE-2019-9779
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg
7.5HIGH
CVE-2019-9778
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at
7.5HIGH
CVE-2019-9777
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write
7.5HIGH
CVE-2019-9776
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg
7.5HIGH
CVE-2019-9775
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at
9.1CRITICAL
CVE-2019-9774
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c.
9.1CRITICAL
CVE-2019-9773
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_dat
7.5HIGH
CVE-2019-9772
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dw
7.5HIGH
CVE-2019-9771
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bi
7.5HIGH
CVE-2019-9770
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_dat
7.5HIGH
CVE-2019-9752
all versions
An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attack
5.4MEDIUM
CVE-2019-9215
all versions
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
9.8CRITICAL
CVE-2019-7164
all versions
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
9.8CRITICAL
CVE-2019-5736
all versions
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and
8.6HIGH
CVE-2019-7635
all versions
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_bli
8.1HIGH
CVE-2019-7548
all versions
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
7.8HIGH
CVE-2018-16874
all versions
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the imp
8.1HIGH
CVE-2018-16873
all versions
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -
8.1HIGH
CVE-2018-19052
all versions
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traver
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin