Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora MEDIUM 6.1
CVE-2020-35478

MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via Log…

Fix: 1.35.1+
Fix from $1,600 2020-12-18
Fedora HIGH 7.5
CVE-2020-35381

jsonparser 1.0.0 allows attackers to cause a denial of service (panic: runtime error: slice bounds out of range) via a GET call.

Patch available
Fix from $1,950 2020-12-15
Fedora MEDIUM 6.2
CVE-2020-29567

An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated an…

Fix: after 4.14.0
Fix from $1,600 2020-12-15
Fedora HIGH 7.5
CVE-2020-8286

curl 7.41.0 through 7.73.0 is vulnerable to an improper check for certificate revocation due to insufficient verification of the OCSP response.

Fix: 7.74.0+
Fix from $1,950 2020-12-14
Fedora MEDIUM 5.4
CVE-2020-35132

An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a …

Fix: 1.2.6.2+
Fix from $1,600 2020-12-11
Fedora HIGH 7.8
CVE-2020-27828

There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-b…

Fix: 2.0.23+
Fix from $1,950 2020-12-11
Fedora MEDIUM 5.5
CVE-2020-16592

A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm…

No fix yet
Fix from $1,600 2020-12-09
Fedora MEDIUM 6.5
CVE-2020-26257

Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or po…

Fix: 1.23.1+
Fix from $1,600 2020-12-09
Fedora HIGH 7.5
CVE-2020-29651

A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a c…

Fix: after 1.9.0
Fix from $1,950 2020-12-09
Fedora MEDIUM 6.1
CVE-2020-25664

In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write lat…

Fix: 6.9.10-68 / 7.0.8-68+
Fix from $1,600 2020-12-08
Fedora HIGH 8.8
CVE-2020-13584

An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-f…

No fix yet
Fix from $1,950 2020-12-03
Fedora HIGH 8.1
CVE-2020-25693

A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially…

Fix: 2.9.3+
Fix from $1,950 2020-12-03
Fedora HIGH 7.5
CVE-2020-25649EPSS 18%

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML extern…

Fix: 0.12.0 / 2.6.7.4+
Fix from $1,950 2020-12-03
Fedora MEDIUM 5.2
CVE-2020-15257

containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.…

Fix: 1.3.9 / 1.4.3+
Fix from $1,600 2020-12-01
Fedora HIGH 8.8
CVE-2020-29074

scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.

Patch available
Fix from $1,950 2020-11-25
Fedora HIGH 7.5
CVE-2020-26890

Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing re…

Fix: 1.20.0+
Fix from $1,950 2020-11-24
Fedora MEDIUM 5.5
CVE-2020-25725

In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes a…

No fix yet
Fix from $1,600 2020-11-21
Fedora HIGH 7.5
CVE-2020-28924

An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak pas…

Fix: 1.53.3+
Fix from $1,950 2020-11-19
Fedora MEDIUM 5.5
CVE-2020-8695

Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure vi…

Mitigation only
Fix from $1,600 2020-11-12
Fedora MEDIUM 5.5
CVE-2020-8696

Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enabl…

Mitigation only
Fix from $1,600 2020-11-12
Fedora MEDIUM 5.5
CVE-2020-8698

Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via l…

Fix: 22.01.08+
Fix from $1,600 2020-11-12
Fedora CRITICAL 9.8
CVE-2020-0452

In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution…

Patch available
Fix from $2,300 2020-11-10
Fedora CRITICAL 9.8
CVE-2020-26892

The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.

Fix: 2.1.9+
Fix from $2,300 2020-11-06
Fedora HIGH 7.5
CVE-2020-26521

The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).

Fix: 2.1.9+
Fix from $1,950 2020-11-06
Fedora HIGH 7.5
CVE-2020-28196

MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb…

Fix: 1.17.2 / 1.18.3+
Fix from $1,950 2020-11-06
Fedora MEDIUM 6.5
CVE-2020-28242

An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified As…

Fix: 13.37.1 / 16.14.1+
Fix from $1,600 2020-11-06
Fedora MEDIUM 5.5
CVE-2020-14323

A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could …

Fix: 4.11.15 / 4.12.9+
Fix from $1,600 2020-10-29
Fedora MEDIUM 5.3
CVE-2020-27674

An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because…

Fix: after 4.14.0
Fix from $1,600 2020-10-22
Fedora HIGH 7.8
CVE-2020-27670

An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a denial of service (data corruption), cause a data leak, or possi…

Fix: after 4.14.0
Fix from $1,950 2020-10-22
Fedora HIGH 7.0
CVE-2020-27672

An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly …

Fix: after 4.14.0
Fix from $1,950 2020-10-22