Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2020-15166

In ZeroMQ before version 4.3.3, there is a denial-of-service vulnerability. Users with TCP transport public endpoints, even with CURVE/ZAP enabled, a…

Fix: 4.3.3+
Fix from $1,950 2020-09-11
Fedora HIGH 7.0
CVE-2020-14342

It was found that cifs-utils' mount.cifs was invoking a shell when requesting the Samba password, which could be used to inject arbitrary commands. A…

Fix: after 6.10
Fix from $1,950 2020-09-09
Fedora HIGH 7.5
CVE-2020-24659

An issue was discovered in GnuTLS before 3.6.15. A server can trigger a NULL pointer dereference in a TLS 1.3 client if a no_renegotiation alert is s…

Fix: 3.6.15+
Fix from $1,950 2020-09-04
Fedora MEDIUM 5.5
CVE-2020-16150

A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to reco…

Fix: 2.7.17 / 2.16.8+
Fix from $1,600 2020-09-02
Fedora HIGH 8.8
CVE-2020-24972

The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are…

Fix: 20.07.80+
Fix from $1,950 2020-08-29
Fedora MEDIUM 5.9
CVE-2020-24661

GNOME Geary before 3.36.3 mishandles pinned TLS certificate verification for IMAP and SMTP services using invalid TLS certificates (e.g., self-signed…

Fix: 3.36.3+
Fix from $1,600 2020-08-26
Fedora HIGH 8.8
CVE-2020-24614

Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must ha…

Fix: 2.10.2 / 2.11.2+
Fix from $1,950 2020-08-25
Fedora MEDIUM 6.0
CVE-2020-14367

A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd star…

Fix: 3.5.1+
Fix from $1,600 2020-08-24
Fedora HIGH 7.5
CVE-2020-8623EPSS 6%

In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attac…

Fix: 2.2.2-5027+
Fix from $1,950 2020-08-21
Fedora MEDIUM 6.5
CVE-2020-8622EPSS 6%

In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacke…

Fix: 2.2.2-5028+
Fix from $1,600 2020-08-21
Fedora HIGH 7.5
CVE-2020-1597EPSS 7%

A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability…

Fix: after 16.6
Fix from $1,950 2020-08-17
Fedora MEDIUM 5.5
CVE-2020-1472 KEVEPSS 100%

An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, u…

Patch available
Fix from $1,600 2020-08-17
Fedora MEDIUM 5.3
CVE-2020-24370

ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).

Patch available
Fix from $1,600 2020-08-17
Fedora HIGH 7.8
CVE-2020-24342

Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.

Patch available
Fix from $1,950 2020-08-13
Fedora HIGH 7.8
CVE-2020-24330

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop t…

Fix: after 0.3.14
Fix from $1,950 2020-08-13
Fedora HIGH 7.8
CVE-2020-24331

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access …

Fix: after 0.3.14
Fix from $1,950 2020-08-13
Fedora MEDIUM 5.5
CVE-2020-24332

An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone…

Fix: after 0.3.14
Fix from $1,600 2020-08-13
Fedora MEDIUM 6.1
CVE-2020-16145

Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been f…

Fix: 1.3.15 / 1.4.8+
Fix from $1,600 2020-08-12
Fedora HIGH 7.5
CVE-2020-17487

radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This…

No fix yet
Fix from $1,950 2020-08-11
Fedora HIGH 7.8
CVE-2020-6070

An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can c…

No fix yet
Fix from $1,950 2020-08-10
Fedora HIGH 7.1
CVE-2020-15113

In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatic…

Fix: 3.3.23 / 3.4.10+
Fix from $1,950 2020-08-05
Fedora MEDIUM 6.5
CVE-2020-15112

In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.…

Fix: 3.3.23 / 3.4.10+
Fix from $1,600 2020-08-05
Fedora MEDIUM 6.5
CVE-2020-15106

In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a…

Fix: 3.3.23 / 3.4.10+
Fix from $1,600 2020-08-05
Fedora CRITICAL 9.8
CVE-2020-17353

scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and emb…

Fix: after 2.21.4
Fix from $2,300 2020-08-05
Fedora MEDIUM 6.7
CVE-2020-14344

An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. A…

Fix: 1.6.10+
Fix from $1,600 2020-08-05
Fedora MEDIUM 5.5
CVE-2020-16269

radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_na…

Patch available
Fix from $1,600 2020-08-03
Fedora HIGH 7.5
CVE-2020-16094

In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into s…

Fix: after 3.17.6
Fix from $1,950 2020-07-28
Fedora CRITICAL 9.8
CVE-2020-12460

OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte…

Fix: after 1.3.2
Fix from $2,300 2020-07-27
Fedora HIGH 7.4
CVE-2020-15953

LibEtPan through 1.9.4, as used in MailCore 2 through 0.6.3 and other products, has a STARTTLS buffering issue that affects IMAP, SMTP, and POP3. Whe…

Fix: after 1.9.4
Fix from $1,950 2020-07-27
Fedora CRITICAL 9.8
CVE-2020-15917

common/session.c in Claws Mail before 3.17.6 has a protocol violation because suffix data after STARTTLS is mishandled.

Fix: 3.17.6+
Fix from $2,300 2020-07-23