threat
engine
.sh
Back
·
··:··
Home
/
Product
/
opensuse backports sle
Product
opensuse backports sle
326 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
Sort
Newest first
Oldest first
Highest CVSS
Lowest CVSS
Min CVSS
Any
4.0+
7.0+ (High)
9.0+ (Critical)
Published since
Reset
CVE-2020-6557
all versions
Inappropriate implementation in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to perform domain spoo
6.5
MEDIUM
CVE-2020-16011
all versions
Heap buffer overflow in UI in Google Chrome on Windows prior to 86.0.4240.183 allowed a remote attacker who had compromised the re
9.6
CRITICAL
CVE-2020-16009
all versions
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap c
8.8
HIGH
CVE-2020-16008
all versions
Stack buffer overflow in WebRTC in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit stack cor
8.8
HIGH
CVE-2020-16007
all versions
Insufficient data validation in installer in Google Chrome prior to 86.0.4240.183 allowed a local attacker to potentially elevate
7.8
HIGH
CVE-2020-16006
all versions
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap c
8.8
HIGH
CVE-2020-16005
all versions
Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit
8.8
HIGH
CVE-2020-16004
all versions
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap cor
8.8
HIGH
CVE-2020-16003
all versions
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruptio
8.8
HIGH
CVE-2020-16002
all versions
Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption
8.8
HIGH
CVE-2020-16001
all versions
Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-16000
all versions
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit hea
8.8
HIGH
CVE-2020-15999
all versions
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap cor
9.6
CRITICAL
CVE-2020-15992
all versions
Insufficient policy enforcement in networking in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised
8.8
HIGH
CVE-2020-15991
all versions
Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the render
8.8
HIGH
CVE-2020-15990
all versions
Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer proce
8.8
HIGH
CVE-2020-15989
all versions
Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive info
5.5
MEDIUM
CVE-2020-15988
all versions
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 86.0.4240.75 allowed a remote attacker who convi
6.3
MEDIUM
CVE-2020-15987
all versions
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-15986
all versions
Integer overflow in media in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption
6.5
MEDIUM
CVE-2020-15985
all versions
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security UI via a
6.5
MEDIUM
CVE-2020-15984
all versions
Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the co
6.5
MEDIUM
CVE-2020-15983
all versions
Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass conten
7.8
HIGH
CVE-2020-15982
all versions
Inappropriate implementation in cache in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensi
6.5
MEDIUM
CVE-2020-15981
all versions
Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive infor
6.5
MEDIUM
CVE-2020-15980
all versions
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 86.0.4240.75 allowed a local attacker to bypass na
7.8
HIGH
CVE-2020-15979
all versions
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap co
8.8
HIGH
CVE-2020-15978
all versions
Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had com
8.8
HIGH
CVE-2020-15977
all versions
Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potenti
6.5
MEDIUM
CVE-2020-15976
all versions
Use after free in WebXR in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap co
8.8
HIGH
CVE-2020-15975
all versions
Integer overflow in SwiftShader in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corru
8.8
HIGH
CVE-2020-15974
all versions
Integer overflow in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to bypass site isolation via a crafted
8.8
HIGH
CVE-2020-15973
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to i
6.5
MEDIUM
CVE-2020-15972
all versions
Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption vi
8.8
HIGH
CVE-2020-15971
all versions
Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer proce
8.8
HIGH
CVE-2020-15970
all versions
Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to
8.8
HIGH
CVE-2020-15969
all versions
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-15968
all versions
Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption vi
8.8
HIGH
CVE-2020-15967
all versions
Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially perform a sandbox escap
8.8
HIGH
CVE-2020-25829
all versions
An issue has been found in PowerDNS Recursor before 4.1.18, 4.2.x before 4.2.5, and 4.3.x before 4.3.5. A remote attacker can caus
7.5
HIGH
CVE-2020-15229
all versions
Singularity (an open source container platform) from version 3.1.1 through 3.6.3 has a vulnerability. Due to insecure handling of
8.2
HIGH
CVE-2020-26935
all versions
An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was dis
9.8
CRITICAL
CVE-2020-26934
all versions
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
6.1
MEDIUM
CVE-2020-26164
all versions
In kdeconnect-kde (aka KDE Connect) before 20.08.2, an attacker on the local network could send crafted packets that trigger use o
5.5
MEDIUM
CVE-2020-11800
all versions
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
9.8
CRITICAL
CVE-2020-8228
all versions
A missing rate limit in the Preferred Providers app 1.7.0 allowed an attacker to set the password an uncontrolled amount of times.
5.3
MEDIUM
CVE-2019-11556
all versions
Pagure before 5.6 allows XSS via the templates/blame.html blame view.
6.1
MEDIUM
CVE-2020-6576
all versions
Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap c
8.8
HIGH
CVE-2020-6575
all versions
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potenti
8.3
HIGH
CVE-2020-6574
all versions
Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potential
7.8
HIGH
CVE-2020-6573
all versions
Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the rende
9.6
CRITICAL
CVE-2020-6571
all versions
Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofin
4.3
MEDIUM
CVE-2020-6570
all versions
Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive inf
4.3
MEDIUM
CVE-2020-6569
all versions
Integer overflow in WebUSB in Google Chrome prior to 85.0.4183.83 allowed a remote attacker who had compromised the renderer proce
6.3
MEDIUM
CVE-2020-6568
all versions
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to
6.5
MEDIUM
CVE-2020-6567
all versions
Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a re
6.5
MEDIUM
CVE-2020-6566
all versions
Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin dat
6.5
MEDIUM
CVE-2020-6565
all versions
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to spoof the conte
6.5
MEDIUM
CVE-2020-6564
all versions
Inappropriate implementation in permissions in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to spoof the contents
6.5
MEDIUM
CVE-2020-6563
all versions
Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to
6.5
MEDIUM
CVE-2020-6562
all versions
Insufficient policy enforcement in Blink in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin dat
6.5
MEDIUM
CVE-2020-6561
all versions
Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak c
6.5
MEDIUM
CVE-2020-6560
all versions
Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin
6.5
MEDIUM
CVE-2020-6559
all versions
Use after free in presentation API in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to potentially exploit heap co
8.8
HIGH
CVE-2020-6558
all versions
Insufficient policy enforcement in iOSWeb in Google Chrome on iOS prior to 85.0.4183.83 allowed a remote attacker to bypass naviga
6.5
MEDIUM
CVE-2020-15966
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to
4.3
MEDIUM
CVE-2020-15965
all versions
Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory
8.8
HIGH
CVE-2020-15964
all versions
Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit hea
8.8
HIGH
CVE-2020-15963
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to
9.6
CRITICAL
CVE-2020-15962
all versions
Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform
8.8
HIGH
CVE-2020-15961
all versions
Insufficient policy validation in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to i
9.6
CRITICAL
CVE-2020-15960
all versions
Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bo
8.8
HIGH
CVE-2020-15959
all versions
Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user t
4.3
MEDIUM
CVE-2020-25032
all versions
An issue was discovered in Flask-CORS (aka CORS Middleware for Flask) before 3.0.9. It allows ../ directory traversal to access pr
7.5
HIGH
CVE-2020-14352
all versions
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize p
8.0
HIGH
CVE-2020-24972
all versions
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because op
8.8
HIGH
CVE-2020-24614
all versions
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code.
8.8
HIGH
CVE-2020-8233
all versions
A command injection vulnerability exists in EdgeSwitch firmware <v1.9.0 that allowed an authenticated read-only user to execute ar
8.8
HIGH
CVE-2020-8026
all versions
A Incorrect Default Permissions vulnerability in the packaging of inn in openSUSE Leap 15.2, openSUSE Tumbleweed, openSUSE Leap 15
8.4
HIGH
CVE-2020-17353
all versions
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on
9.8
CRITICAL
CVE-2020-16118
all versions
In GNOME Balsa before 2.6.0, a malicious server operator or man in the middle can trigger a NULL pointer dereference and client cr
7.5
HIGH
CVE-2020-15917
all versions
common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.
9.8
CRITICAL
CVE-2020-6536
all versions
Incorrect security UI in PWAs in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had persuaded the user to insta
4.3
MEDIUM
CVE-2020-6535
all versions
Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the ren
6.1
MEDIUM
CVE-2020-6534
all versions
Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corrup
8.8
HIGH
CVE-2020-6533
all versions
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a
8.8
HIGH
CVE-2020-6531
all versions
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-
4.3
MEDIUM
CVE-2020-6530
all versions
Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to
8.8
HIGH
CVE-2020-6529
all versions
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position
4.3
MEDIUM
CVE-2020-6528
all versions
Incorrect security UI in basic auth in Google Chrome on iOS prior to 84.0.4147.89 allowed a remote attacker to spoof the contents
4.3
MEDIUM
CVE-2020-6527
all versions
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security
4.3
MEDIUM
CVE-2020-6526
all versions
Inappropriate implementation in iframe sandbox in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass navigati
6.5
MEDIUM
CVE-2020-6525
all versions
Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corrupti
8.8
HIGH
CVE-2020-6524
all versions
Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corr
8.8
HIGH
CVE-2020-6523
all versions
Out of bounds write in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruptio
8.8
HIGH
CVE-2020-6522
all versions
Inappropriate implementation in external protocol handlers in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to pot
9.6
CRITICAL
CVE-2020-6521
all versions
Side-channel information leakage in autofill in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to obtain potentiall
6.5
MEDIUM
CVE-2020-6520
all versions
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption vi
8.8
HIGH
CVE-2020-6519
all versions
Policy bypass in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a craf
6.5
MEDIUM
CVE-2020-6518
all versions
Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to u
8.8
HIGH
CVE-2020-6517
all versions
Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corru
8.8
HIGH
CVE-2020-6516
all versions
Policy bypass in CORS in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTM
4.3
MEDIUM
CVE-2020-6515
all versions
Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruptio
8.8
HIGH
CVE-2020-6514
all versions
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position
6.5
MEDIUM
CVE-2020-6513
all versions
Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corrup
8.8
HIGH
CVE-2020-6512
all versions
Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a
8.8
HIGH
CVE-2020-6511
all versions
Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin
6.5
MEDIUM
CVE-2020-6510
all versions
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit h
7.8
HIGH
CVE-2020-15396
all versions
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning
7.8
HIGH
CVE-2020-8164
all versions
A deserialization of untrusted data vulnerability exists in rails < 5.2.4.3, rails < 6.0.3.1 which can allow an attacker to supply
7.5
HIGH
CVE-2020-14004
all versions
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) execut
7.8
HIGH
CVE-2020-13696
all versions
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to
4.4
MEDIUM
CVE-2020-6496
all versions
Use after free in payments in Google Chrome on MacOS prior to 83.0.4103.97 allowed a remote attacker to potentially perform a sand
8.8
HIGH
CVE-2020-6494
all versions
Incorrect security UI in payments in Google Chrome on Android prior to 83.0.4103.97 allowed a remote attacker to spoof the content
6.5
MEDIUM
CVE-2020-13379
all versions
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauth
8.2
HIGH
CVE-2020-13614
all versions
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
5.9
MEDIUM
CVE-2020-6491
all versions
Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof securit
6.5
MEDIUM
CVE-2020-6490
all versions
Insufficient data validation in loader in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had been able to write
4.3
MEDIUM
CVE-2020-6489
all versions
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced
4.3
MEDIUM
CVE-2020-6488
all versions
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation
4.3
MEDIUM
CVE-2020-6487
all versions
Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation
6.5
MEDIUM
CVE-2020-6486
all versions
Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigati
6.5
MEDIUM
CVE-2020-6485
all versions
Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised
6.5
MEDIUM
CVE-2020-6484
all versions
Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation
6.5
MEDIUM
CVE-2020-6483
all versions
Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation
6.5
MEDIUM
CVE-2020-6482
all versions
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user
6.5
MEDIUM
CVE-2020-6481
all versions
Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform doma
6.5
MEDIUM
CVE-2020-6480
all versions
Insufficient policy enforcement in enterprise in Google Chrome prior to 83.0.4103.61 allowed a local attacker to bypass navigation
6.5
MEDIUM
CVE-2020-6479
all versions
Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via
6.5
MEDIUM
CVE-2020-6478
all versions
Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI
6.5
MEDIUM
CVE-2020-6477
all versions
Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privi
7.8
HIGH
CVE-2020-6476
all versions
Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to in
6.5
MEDIUM
CVE-2020-6475
all versions
Incorrect implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via
6.5
MEDIUM
CVE-2020-6474
all versions
Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption vi
8.8
HIGH
CVE-2020-6473
all versions
Insufficient policy enforcement in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to obtain potentially se
6.5
MEDIUM
CVE-2020-6472
all versions
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user
6.5
MEDIUM
CVE-2020-6471
all versions
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user
9.6
CRITICAL
CVE-2020-6470
all versions
Insufficient validation of untrusted input in clipboard in Google Chrome prior to 83.0.4103.61 allowed a local attacker to inject
6.1
MEDIUM
CVE-2020-6469
all versions
Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user
9.6
CRITICAL
CVE-2020-6468
all versions
Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a
8.8
HIGH
CVE-2020-6467
all versions
Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-6466
all versions
Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process
9.6
CRITICAL
CVE-2020-6465
all versions
Use after free in reader mode in Google Chrome on Android prior to 83.0.4103.61 allowed a remote attacker who had compromised the
9.6
CRITICAL
CVE-2020-6463
all versions
Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-10995
all versions
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the
7.5
HIGH
CVE-2020-12244
all versions
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lackin
7.5
HIGH
CVE-2020-12108
all versions
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
6.5
MEDIUM
CVE-2020-12672
all versions
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
7.5
HIGH
CVE-2020-12641
all versions
rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configu
9.8
CRITICAL
CVE-2020-12640
all versions
Roundcube Webmail before 1.4.4 allows attackers to include local files and execute code via directory traversal in a plugin name t
9.8
CRITICAL
CVE-2020-12625
all versions
An issue was discovered in Roundcube Webmail before 1.4.4. There is a cross-site scripting (XSS) vulnerability in rcube_washtml.ph
6.1
MEDIUM
CVE-2020-12050
all versions
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalat
7.0
HIGH
CVE-2020-12137
all versions
GNU Mailman 2.x before 2.1.30 uses the .obj extension for scrubbed application/octet-stream MIME parts. This behavior may contribu
6.1
MEDIUM
CVE-2020-12066
all versions
CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
7.5
HIGH
CVE-2020-6454
all versions
Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a maliciou
8.8
HIGH
CVE-2020-6451
all versions
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruptio
8.8
HIGH
CVE-2020-6450
all versions
Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruptio
8.8
HIGH
CVE-2020-6448
all versions
Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a
8.8
HIGH
CVE-2020-6447
all versions
Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced
8.8
HIGH
CVE-2020-6444
all versions
Uninitialized use in WebRTC in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruptio
6.3
MEDIUM
CVE-2020-6438
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to i
4.3
MEDIUM
CVE-2020-6436
all versions
Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap c
8.8
HIGH
CVE-2020-6434
all versions
Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption
8.8
HIGH
CVE-2020-6430
all versions
Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a
8.8
HIGH
CVE-2020-6423
all versions
Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption vi
8.8
HIGH
CVE-2020-11653
all versions
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when co
7.5
HIGH
CVE-2019-20637
all versions
An issue was discovered in Varnish Cache before 6.0.5 LTS, 6.1.x and 6.2.x before 6.2.2, and 6.3.x before 6.3.1. It does not clear
7.5
HIGH
CVE-2019-14905
all versions
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, wher
5.6
MEDIUM
CVE-2020-6095
all versions
An exploitable denial of service vulnerability exists in the GstRTSPAuth functionality of GStreamer/gst-rtsp-server 1.14.5. A spec
7.5
HIGH
CVE-2020-1772
all versions
It's possible to craft Lost Password requests with wildcards in the Token value, which allows attacker to retrieve valid Token(s),
6.5
MEDIUM
CVE-2020-1770
all versions
Support bundle generated files could contain sensitive information that might be unwanted to be disclosed. This issue affects: ((O
2.4
LOW
CVE-2020-1769
all versions
In the login screens (in agent and customer interface), Username and Password fields use autocomplete, which might be considered a
3.5
LOW
CVE-2020-6449
all versions
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-6429
all versions
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-6428
all versions
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-6427
all versions
Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-6426
all versions
Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap c
6.5
MEDIUM
CVE-2020-6424
all versions
Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-6422
all versions
Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2020-10593
all versions
Tor before 0.3.5.10, 0.4.x before 0.4.1.9, and 0.4.2.x before 0.4.2.7 allows remote attackers to cause a Denial of Service (memory
7.5
HIGH
CVE-2020-10803
all versions
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be us
5.4
MEDIUM
CVE-2020-10802
all versions
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters ar
8.0
HIGH
CVE-2020-10804
all versions
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username
8.0
HIGH
CVE-2019-12921
all versions
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image b
6.5
MEDIUM
CVE-2019-3698
all versions
UNIX Symbolic Link (Symlink) Following vulnerability in the cronjob shipped with nagios of SUSE Linux Enterprise Server 12, SUSE L
5.7
MEDIUM
CVE-2020-7043
all versions
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation bec
9.1
CRITICAL
CVE-2020-7042
all versions
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation b
5.3
MEDIUM
CVE-2020-7041
all versions
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation b
5.3
MEDIUM
CVE-2020-9273
all versions
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-f
8.8
HIGH
CVE-2020-9272
all versions
ProFTPD 1.3.7 has an out-of-bounds (OOB) read vulnerability in mod_cap via the cap_text.c cap_to_text function.
7.5
HIGH
CVE-2020-8955
all versions
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buf
9.8
CRITICAL
CVE-2020-6416
all versions
Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit he
8.8
HIGH
CVE-2020-6415
all versions
Inappropriate implementation in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit
8.8
HIGH
CVE-2020-6414
all versions
Insufficient policy enforcement in Safe Browsing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass naviga
8.8
HIGH
CVE-2020-6413
all versions
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass HTML validators v
8.8
HIGH
CVE-2020-6412
all versions
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform
5.4
MEDIUM
CVE-2020-6408
all versions
Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sens
6.5
MEDIUM
CVE-2020-6404
all versions
Inappropriate implementation in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap
8.8
HIGH
CVE-2020-6403
all versions
Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents
4.3
MEDIUM
CVE-2020-6402
all versions
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a us
8.8
HIGH
CVE-2020-6401
all versions
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to perform
6.5
MEDIUM
CVE-2020-6400
all versions
Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data vi
6.5
MEDIUM
CVE-2020-6399
all versions
Insufficient policy enforcement in AppCache in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin
6.5
MEDIUM
CVE-2020-6398
all versions
Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap c
8.8
HIGH
CVE-2020-6397
all versions
Inappropriate implementation in sharing in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof security UI via
6.5
MEDIUM
CVE-2020-6396
all versions
Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the
4.3
MEDIUM
CVE-2020-6394
all versions
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content securi
5.4
MEDIUM
CVE-2020-6393
all versions
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin dat
6.5
MEDIUM
CVE-2020-6392
all versions
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to i
4.3
MEDIUM
CVE-2020-6391
all versions
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass cont
4.3
MEDIUM
CVE-2020-6390
all versions
Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit hea
8.8
HIGH
CVE-2020-6385
all versions
Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolati
8.8
HIGH
CVE-2020-6382
all versions
Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corrupti
8.8
HIGH
CVE-2020-6381
all versions
Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potenti
8.8
HIGH
CVE-2020-8118
all versions
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a
5.0
MEDIUM
CVE-2019-15623
all versions
Exposure of Private Information in Nextcloud Server 16.0.1 causes the server to send it's domain and user IDs to the Nextcloud Loo
5.3
MEDIUM
CVE-2019-3693
all versions
A symlink following vulnerability in the packaging of mailman in SUSE Linux Enterprise Server 11, SUSE Linux Enterprise Server 12;
7.7
HIGH
CVE-2019-3692
all versions
The packaging of inn on SUSE Linux Enterprise Server 11; openSUSE Factory, Leap 15.1 allows local attackers to escalate from user
7.7
HIGH
CVE-2020-7040
all versions
storeBackup.pl in storeBackup through 3.5 relies on the /tmp/storeBackup.lock pathname, which allows symlink attacks that possibly
8.1
HIGH
CVE-2019-18932
all versions
log.c in Squid Analysis Report Generator (sarg) through 2.3.11 allows local privilege escalation. By default, it uses a fixed temp
7.0
HIGH
CVE-2020-7106
all versions
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, use
6.1
MEDIUM
CVE-2020-6377
all versions
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption v
8.8
HIGH
CVE-2019-13767
all versions
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer p
8.8
HIGH
CVE-2020-1765
all versions
An improper control of parameters allows the spoofing of the from fields of the following screens: AgentTicketCompose, AgentTicket
3.5
LOW
CVE-2020-6615
all versions
GNU LibreDWG 0.9.3.2564 has an invalid pointer dereference in dwg_dynapi_entity_value in dynapi.c (dynapi.c is generated by gen-dy
6.5
MEDIUM
CVE-2020-6614
all versions
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bfr_read in decode.c.
8.1
HIGH
CVE-2020-6613
all versions
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in bit_search_sentinel in bits.c.
8.1
HIGH
CVE-2020-6612
all versions
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in copy_compressed_bytes in decode_r2007.c.
8.1
HIGH
CVE-2020-6611
all versions
GNU LibreDWG 0.9.3.2564 has a NULL pointer dereference in get_next_owned_entity in dwg.c.
6.5
MEDIUM
CVE-2020-6609
all versions
GNU LibreDWG 0.9.3.2564 has a heap-based buffer over-read in read_pages_map in decode_r2007.c.
8.8
HIGH
CVE-2019-18179
all versions
An issue was discovered in Open Ticket Request System (OTRS) 7.0.x through 7.0.12, and Community Edition 5.0.x through 5.0.38 and
4.3
MEDIUM
CVE-2019-5846
all versions
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
6.5
MEDIUM
CVE-2019-5845
all versions
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
6.5
MEDIUM
CVE-2019-5844
all versions
Out of bounds access in SwiftShader in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap c
6.5
MEDIUM
CVE-2019-14864
all versions
Ansible, versions 2.9.x before 2.9.1, 2.8.x before 2.8.7 and Ansible versions 2.7.x before 2.7.15, is not respecting the flag no_l
6.5
MEDIUM
CVE-2019-20015
all versions
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_LW
6.5
MEDIUM
CVE-2019-20014
all versions
An issue was discovered in GNU LibreDWG before 0.93. There is a double-free in dwg_free in free.c.
8.8
HIGH
CVE-2019-20013
all versions
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in decode
6.5
MEDIUM
CVE-2019-20012
all versions
An issue was discovered in GNU LibreDWG 0.92. Crafted input will lead to an attempted excessive memory allocation in dwg_decode_HA
6.5
MEDIUM
CVE-2019-20011
all versions
An issue was discovered in GNU LibreDWG 0.92. There is a heap-based buffer over-read in decode_R13_R2000 in decode.c.
8.8
HIGH
CVE-2019-20010
all versions
An issue was discovered in GNU LibreDWG 0.92. There is a use-after-free in resolve_objectref_vector in decode.c.
8.8
HIGH
CVE-2019-20009
all versions
An issue was discovered in GNU LibreDWG before 0.93. Crafted input will lead to an attempted excessive memory allocation in dwg_de
6.5
MEDIUM
CVE-2019-19925
all versions
zipfileUpdate in ext/misc/zipfile.c in SQLite 3.30.1 mishandles a NULL pathname during an update of a ZIP archive.
7.5
HIGH
CVE-2019-19923
all versions
flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-h
7.5
HIGH
CVE-2019-19926
all versions
multiSelect in select.c in SQLite 3.30.1 mishandles certain errors during parsing, as demonstrated by errors from sqlite3WindowRew
7.5
HIGH
CVE-2019-19918
all versions
Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
7.8
HIGH
CVE-2019-19917
all versions
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
7.8
HIGH
CVE-2019-19880
all versions
exprListAppendList in window.c in SQLite 3.30.1 allows attackers to trigger an invalid pointer dereference because constant intege
7.5
HIGH
CVE-2019-16779
all versions
In RubyGem excon before 0.71.0, there was a race condition around persistent connections, where a connection which is interrupted
5.8
MEDIUM
CVE-2019-13764
all versions
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corrupti
8.8
HIGH
CVE-2019-13745
all versions
Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin dat
6.5
MEDIUM
CVE-2019-13734
all versions
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corrupt
8.8
HIGH
CVE-2019-5164
all versions
An exploitable code execution vulnerability exists in the ss-manager binary of Shadowsocks-libev 3.3.2. Specially crafted network
7.8
HIGH
CVE-2019-14856
all versions
ansible before versions 2.8.6, 2.7.14, 2.6.20 is vulnerable to a None
6.5
MEDIUM
CVE-2019-13719
all versions
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via
4.3
MEDIUM
CVE-2019-13718
all versions
Insufficient data validation in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform domain spoofin
4.3
MEDIUM
CVE-2019-13717
all versions
Incorrect security UI in full screen mode in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to hide security UI via
4.3
MEDIUM
CVE-2019-13716
all versions
Insufficient policy enforcement in service workers in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass navi
4.3
MEDIUM
CVE-2019-13715
all versions
Insufficient validation of untrusted input in Omnibox in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to perform
4.3
MEDIUM
CVE-2019-13714
all versions
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote att
6.1
MEDIUM
CVE-2019-13710
all versions
Insufficient validation of untrusted input in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass
4.3
MEDIUM
CVE-2019-13709
all versions
Insufficient policy enforcement in downloads in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass download r
6.5
MEDIUM
CVE-2019-13708
all versions
Inappropriate implementation in navigation in Google Chrome on iOS prior to 78.0.3904.70 allowed a remote attacker to spoof the co
4.3
MEDIUM
CVE-2019-13706
all versions
Out of bounds memory access in PDFium in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to potentially exploit heap
7.8
HIGH
CVE-2019-13704
all versions
Insufficient policy enforcement in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to bypass content s
4.3
MEDIUM
CVE-2019-13703
all versions
Insufficient policy enforcement in the Omnibox in Google Chrome on Android prior to 78.0.3904.70 allowed a remote attacker to spoo
4.3
MEDIUM
CVE-2019-13702
all versions
Inappropriate implementation in installer in Google Chrome on Windows prior to 78.0.3904.70 allowed a local attacker to perform pr
7.8
HIGH
CVE-2019-13701
all versions
Incorrect implementation in navigation in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to spoof the contents of t
4.3
MEDIUM
CVE-2019-13700
all versions
Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromise
8.8
HIGH
CVE-2019-13699
all versions
Use after free in media in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process
8.8
HIGH
CVE-2019-18622
all versions
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack th
9.8
CRITICAL
CVE-2019-10206
all versions
ansible-playbook -k and ansible cli tools, all versions 2.8.x before 2.8.4, all 2.7.x before 2.7.13 and all 2.6.x before 2.6.19, p
6.5
MEDIUM
CVE-2019-17545
all versions
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
9.8
CRITICAL
CVE-2019-17455
all versions
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read an
9.8
CRITICAL
CVE-2019-14846
all versions
In Ansible, all Ansible Engine versions up to ansible-engine 2.8.5, ansible-engine 2.7.13, ansible-engine 2.6.19, were logging at
7.8
HIGH
CVE-2019-11779
all versions
In Eclipse Mosquitto 1.5.0 to 1.6.5 inclusive, if a malicious MQTT client sends a SUBSCRIBE packet containing a topic that consist
6.5
MEDIUM
CVE-2019-16159
all versions
BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support
7.5
HIGH
CVE-2016-10937
all versions
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
7.5
HIGH
CVE-2019-14744
all versions
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user
7.8
HIGH
CVE-2019-5060
all versions
An exploitable code execution vulnerability exists in the XPM image rendering function of SDL2_image 2.0.4. A specially crafted XP
8.8
HIGH
CVE-2019-5059
all versions
An exploitable code execution vulnerability exists in the XPM image rendering functionality of SDL2_image 2.0.4. A specially craft
8.8
HIGH
CVE-2019-5058
all versions
An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image 2.0.4. A specially craft
8.8
HIGH
CVE-2019-5057
all versions
An exploitable code execution vulnerability exists in the PCX image-rendering functionality of SDL2_image 2.0.4. A specially craft
8.8
HIGH
CVE-2019-5459
all versions
An Integer underflow in VLC Media Player versions < 3.0.7 leads to an out-of-band read.
7.1
HIGH
CVE-2019-14274
all versions
MCPP 2.7.2 has a heap-based buffer overflow in the do_msg() function in support.c.
5.5
MEDIUM
CVE-2019-13962
all versions
lavc_CopyPicture in modules/codec/avcodec/video.c in VideoLAN VLC media player through 3.0.7 has a heap-based buffer over-read bec
9.8
CRITICAL
CVE-2019-13616
all versions
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in BlitNtoN in video/SDL_bli
8.1
HIGH
CVE-2019-13602
all versions
An Integer Underflow in MP4_EIA608_Convert() in modules/demux/mp4/mp4.c in VideoLAN VLC media player through 3.0.7.1 allows remote
7.8
HIGH
CVE-2019-5052
all versions
An exploitable integer overflow vulnerability exists when loading a PCX file in SDL2_image 2.0.4. A specially crafted file can cau
8.8
HIGH
CVE-2019-5051
all versions
An exploitable heap-based buffer overflow vulnerability exists when loading a PCX file in SDL2_image, version 2.0.4. A missing err
8.8
HIGH
CVE-2019-5802
all versions
Incorrect handling of download origins in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform d
6.5
MEDIUM
CVE-2019-5796
all versions
Data race in extensions guest view in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap co
7.5
HIGH
CVE-2019-5794
all versions
Incorrect handling of cancelled requests in Navigation in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to perform
6.5
MEDIUM
CVE-2019-12221
all versions
An issue was discovered in libSDL2.a in Simple DirectMedia Layer (SDL) 2.0.9 when used in conjunction with libSDL2_image.a in SDL2
6.5
MEDIUM
CVE-2019-12098
all versions
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-midd
7.4
HIGH
CVE-2019-11506
all versions
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATL
8.8
HIGH
CVE-2019-11505
all versions
In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBIm
8.8
HIGH
CVE-2019-11474
all versions
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application cras
6.5
MEDIUM
CVE-2019-11358
all versions
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Objec
6.1
MEDIUM
CVE-2019-9499
all versions
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on impo
8.1
HIGH
CVE-2019-9498
all versions
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported
8.1
HIGH
CVE-2019-9495
all versions
The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access pa
3.7
LOW
CVE-2019-9494
all versions
The implementations of SAE in hostapd and wpa_supplicant are vulnerable to side channel attacks as a result of observable timing d
5.9
MEDIUM
CVE-2019-11008
all versions
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, w
8.8
HIGH
CVE-2019-11007
all versions
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, w
8.1
HIGH
CVE-2019-10740
all versions
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within
4.3
MEDIUM
CVE-2019-9896
all versions
In PuTTY versions before 0.71 on Windows, local attackers could hijack the application by putting a malicious help file in the sam
7.8
HIGH
CVE-2019-9779
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg
7.5
HIGH
CVE-2019-9778
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dwg_dxf_LTYPE at
7.5
HIGH
CVE-2019-9777
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer over-read in the function dxf_header_write
7.5
HIGH
CVE-2019-9776
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LTYPE at dwg
7.5
HIGH
CVE-2019-9775
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function dwg_dxf_BLOCK_CONTROL at
9.1
CRITICAL
CVE-2019-9774
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is an out-of-bounds read in the function bit_read_B at bits.c.
9.1
CRITICAL
CVE-2019-9773
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_dat
7.5
HIGH
CVE-2019-9772
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function dwg_dxf_LEADER at dw
7.5
HIGH
CVE-2019-9771
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a NULL pointer dereference in the function bit_convert_TU at bi
7.5
HIGH
CVE-2019-9770
all versions
An issue was discovered in GNU LibreDWG 0.7 and 0.7.1645. There is a heap-based buffer overflow in the function dwg_decode_eed_dat
7.5
HIGH
CVE-2019-9752
all versions
An issue was discovered in Open Ticket Request System (OTRS) 5.x before 5.0.34, 6.x before 6.0.16, and 7.x before 7.0.4. An attack
5.4
MEDIUM
CVE-2019-9215
all versions
In Live555 before 2019.02.27, malformed headers lead to invalid memory access in the parseAuthorizationHeader function.
9.8
CRITICAL
CVE-2019-7164
all versions
SQLAlchemy through 1.2.17 and 1.3.x through 1.3.0b2 allows SQL Injection via the order_by parameter.
9.8
CRITICAL
CVE-2019-5736
all versions
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary (and
8.6
HIGH
CVE-2019-7635
all versions
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Blit1to4 in video/SDL_bli
8.1
HIGH
CVE-2019-7548
all versions
SQLAlchemy 1.2.17 has SQL Injection when the group_by parameter can be controlled.
7.8
HIGH
CVE-2018-16874
all versions
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to directory traversal when executed with the imp
8.1
HIGH
CVE-2018-16873
all versions
In Go before 1.10.6 and 1.11.x before 1.11.3, the "go get" command is vulnerable to remote code execution when executed with the -
8.1
HIGH
CVE-2018-19052
all versions
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traver
7.5
HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh · Open-source threat intelligence platform · 100+ authoritative sources · Every fact traces to its origin