Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2020-24387

An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned sessi…

Fix: after 2.0.2
Fix from $1,950 2020-10-19
Fedora HIGH 7.5
CVE-2020-24388

An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field o…

Fix: after 2.0.2
Fix from $1,950 2020-10-19
Fedora HIGH 7.5
CVE-2020-24265

An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep…

Patch available
Fix from $1,950 2020-10-19
Fedora HIGH 7.5
CVE-2020-24266

An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cau…

Patch available
Fix from $1,950 2020-10-19
Fedora CRITICAL 9.8
CVE-2020-26935EPSS 67%

An issue was discovered in SearchController in phpMyAdmin before 4.9.6 and 5.x before 5.0.3. A SQL injection vulnerability was discovered in how phpM…

Fix: 4.9.6 / 5.0.3+
Fix from $2,300 2020-10-10
Fedora MEDIUM 6.1
CVE-2020-26934

phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.

Fix: 4.9.6 / 5.0.3+
Fix from $1,600 2020-10-10
Fedora HIGH 7.8
CVE-2020-26880

Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration…

Fix: after 6.2.56
Fix from $1,950 2020-10-07
Fedora MEDIUM 5.5
CVE-2020-26572

The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.

Fix: after 0.20.0
Fix from $1,600 2020-10-06
Fedora MEDIUM 5.5
CVE-2020-26570

The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.

Fix: after 0.20.0
Fix from $1,600 2020-10-06
Fedora CRITICAL 9.8
CVE-2020-26154

url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a…

Fix: after 0.4.15
Fix from $2,300 2020-09-30
Fedora MEDIUM 6.5
CVE-2020-15216

In goxmldsig (XML Digital Signatures implemented in pure Go) before version 1.1.0, with a carefully crafted XML file, an attacker can completely bypa…

Fix: 1.1.0+
Fix from $1,600 2020-09-29
Fedora HIGH 7.5
CVE-2020-26121

An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protect…

Fix: 1.34.4+
Fix from $1,950 2020-09-27
Fedora MEDIUM 6.1
CVE-2020-26120

XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from …

Fix: 1.34.4+
Fix from $1,600 2020-09-27
Fedora HIGH 7.5
CVE-2020-25827

An issue was discovered in the OATHAuth extension in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. For Wikis using OATHAuth on a …

Fix: 1.31.10 / 1.34.4+
Fix from $1,950 2020-09-27
Fedora HIGH 7.5
CVE-2020-25869

An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use…

Fix: 1.31.10 / 1.34.4+
Fix from $1,950 2020-09-27
Fedora MEDIUM 6.1
CVE-2020-25812

An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key …

Fix: 1.34.4+
Fix from $1,600 2020-09-27
Fedora MEDIUM 6.1
CVE-2020-25814

In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript…

Fix: 1.31.10 / 1.34.4+
Fix from $1,600 2020-09-27
Fedora MEDIUM 6.1
CVE-2020-25815

An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build opti…

Fix: 1.34.4+
Fix from $1,600 2020-09-27
Fedora MEDIUM 6.1
CVE-2020-25828

An issue was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. The non-jqueryMsg version of mw.message().parse() doesn'…

Fix: 1.34.4+
Fix from $1,600 2020-09-27
Fedora MEDIUM 5.3
CVE-2020-25813

In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.

Fix: 1.31.10 / 1.34.4+
Fix from $1,600 2020-09-27
Fedora HIGH 7.8
CVE-2020-25603

An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control s…

Fix: after 4.14.0
Fix from $1,950 2020-09-23
Fedora HIGH 7.0
CVE-2020-25599

An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or…

Fix: after 4.14.0
Fix from $1,950 2020-09-23
Fedora MEDIUM 6.5
CVE-2020-25597

An issue was discovered in Xen through 4.14.x. There is mishandling of the constraint that once-valid event channels may not turn invalid. Logic in t…

Fix: after 4.14.0
Fix from $1,600 2020-09-23
Fedora MEDIUM 6.0
CVE-2020-25602

An issue was discovered in Xen through 4.14.x. An x86 PV guest can trigger a host OS crash when handling guest access to MSR_MISC_ENABLE. When a gues…

Fix: after 4.14.0
Fix from $1,600 2020-09-23
Fedora MEDIUM 5.5
CVE-2020-25596

An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves va…

Fix: after 4.14.0
Fix from $1,600 2020-09-23
Fedora MEDIUM 5.5
CVE-2020-25598

An issue was discovered in Xen 4.14.x. There is a missing unlock in the XENMEM_acquire_resource error path. The RCU (Read, Copy, Update) mechanism is…

Fix: after 4.14.0
Fix from $1,600 2020-09-23
Fedora MEDIUM 5.5
CVE-2020-25600

An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel …

Fix: after 4.14.0
Fix from $1,600 2020-09-23
Fedora HIGH 7.8
CVE-2020-25595

An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been ide…

Fix: after 4.14.0
Fix from $1,950 2020-09-23
Fedora HIGH 7.8
CVE-2020-14363

An integer overflow vulnerability leading to a double-free was found in libX11. This flaw allows a local privileged attacker to cause an application …

Fix: 1.6.12+
Fix from $1,950 2020-09-11
Fedora HIGH 7.5
CVE-2020-1045EPSS 6%

<p>A security feature bypass vulnerability exists in the way Microsoft ASP.NET Core parses encoded cookie names.</p> <p>The ASP.NET Core cookie parse…

Fix: 3.1.8+
Fix from $1,950 2020-09-11