Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.8
CVE-2020-15670
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we pres…
Firefox
78.2 / 80.0+
MEDIUM 5.3
CVE-2020-15194
In Tensorflow before versions 1.15.4, 2.0.3, 2.1.2, 2.2.1 and 2.3.1, the `SparseFillEmptyRowsGrad` implementation has incomplete validation of the sh…
Tensorflow
1.15.4 / 2.0.3+
MEDIUM 6.3
CVE-2020-15197
In Tensorflow before version 2.3.1, the `SparseCountSparseOutput` implementation does not validate that the input arguments form a valid sparse tenso…
Tensorflow
Patch available
HIGH 7.5
CVE-2020-6097
An exploitable denial of service vulnerability exists in the atftpd daemon functionality of atftp 0.7.git20120829-3.1+b1. A specially crafted sequenc…
Debian Linux
No fix yet
HIGH 7.5
CVE-2020-11135
u'Reachable assertion when wrong data size is returned by parser for ape clips' in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IO…
Apq8098 Firmware
Mitigation only
MEDIUM 6.5
CVE-2020-13595
The Bluetooth Low Energy (BLE) controller implementation in Espressif ESP-IDF 4.0 through 4.2 (for ESP32 devices) returns the wrong number of complet…
Esp Idf
after 4.2
HIGH 7.5
CVE-2020-8620
In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who can establish a TCP connection with the server and send data on that connection can explo…
Ubuntu Linux
after 9.17.3
HIGH 7.5
CVE-2020-8621
In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is configured with both QNAME minimization and 'forward first' then an attacker who can send …
Ubuntu Linux
2.2.2-5027+
MEDIUM 6.5
CVE-2020-8622EPSS 6%
In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacke…
Fedora
2.2.2-5028+
HIGH 7.5
CVE-2020-8623EPSS 6%
In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attac…
Fedora
2.2.2-5027+
HIGH 8.8
CVE-2020-12417
Due to confusion about ValueTags on JavaScript Objects, an object may pass through the type barrier, resulting in memory corruption and a potentially…
Firefox
68.10.0 / 78.0+
MEDIUM 5.0
CVE-2020-10761
An assertion failure issue was found in the Network Block Device(NBD) Server in all QEMU versions before QEMU 5.0.1. This flaw occurs when an nbd-cli…
Enterprise Linux
5.0.1+
HIGH 7.5
CVE-2020-3645
Firmware will hit assert in WLAN firmware If encrypted data length in FILS IE of reassoc response is more than 528 bytes in Snapdragon Compute, Snapd…
Ipq6018 Firmware
Mitigation only
CRITICAL 9.8
CVE-2020-3615
Valid deauth/disassoc frames is dropped in case if RMF is enabled and some rouge peer keep on sending rogue deauth/disassoc frames due to improper en…
Apq8009 Firmware
Patch available
MEDIUM 5.5
CVE-2020-3958
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.5.2) and VMware Fusion (11.x be…
Fusion
11.5.2 / 15.5.2+
HIGH 7.5
CVE-2020-13649
parser/js/js-scanner.c in JerryScript 2.2.0 mishandles errors during certain out-of-memory conditions, as demonstrated by a scanner_reverse_info_list…
Jerryscript
Patch available
HIGH 7.5
CVE-2020-13622
JerryScript 2.2.0 allows attackers to cause a denial of service (assertion failure) because a property key query for a Proxy object returns unintende…
Jerryscript
Patch available
MEDIUM 5.9
CVE-2020-8617EPSS 93%
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfu…
Debian Linux
after 9.17.1
HIGH 7.5
CVE-2020-3651
Active command timeout since WM status change cmd is not removed from active queue if peer sends multiple deauth frames. in Snapdragon Auto, Snapdrag…
Apq8009 Firmware
Patch available
HIGH 7.5
CVE-2019-14022
Error occurs While extracting the ipv6_header having an invalid length due to lack of length check in Snapdragon Auto, Snapdragon Compute, Snapdragon…
Apq8096au Firmware
Mitigation only
HIGH 7.5
CVE-2020-11653
An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a …
Debian Linux
6.0.6 / 6.2.3+
HIGH 7.8
CVE-2019-14049
Stage-2 fault will occur while writing to an ION system allocation which has been assigned to non-HLOS memory which is non-standard in Snapdragon Aut…
Apq8017 Firmware
Patch available
HIGH 7.5
CVE-2015-8012
lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet.
Lldpd
0.8.0+
HIGH 8.8
CVE-2020-6617
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_int.
Stb Truetype.h
after 1.22
HIGH 8.8
CVE-2020-6619
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__buf_seek.
Stb Truetype.h
after 1.22
HIGH 8.8
CVE-2020-6623
stb stb_truetype.h through 1.22 has an assertion failure in stbtt__cff_get_index.
Stb Truetype.h
after 1.22
MEDIUM 6.5
CVE-2019-20056
stb_image.h (aka the stb image loader) 2.23, as used in libsixel and other products, has an assertion failure in stbi__shiftsigned.
Stb Image.h
No fix yet
HIGH 7.5
CVE-2011-3596EPSS 11%
Polipo before 1.0.4.1 suffers from a DoD vulnerability via specially-crafted HTTP POST / PUT request.
Debian Linux
1.0.4.1+
MEDIUM 6.5
CVE-2012-5521
quagga (ospf6d) 0.99.21 has a DoS flaw in the way the ospf6d daemon performs routes removal
Debian Linux
Mitigation only
HIGH 7.5
CVE-2019-18844
The Device Model in ACRN before 2019w25.5-140000p relies on assert calls in devicemodel/hw/pci/core.c and devicemodel/include/pci_core.h (instead of …
Acrn
2019w25.5-140000p+