Search

Found 5,160 results in 570ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-26137 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:1761: python27:2.7 security and bug fix update (Moderate)
CVE-2019-20916 medium 5.5 FIX sles rockydebian debian 5y ago The pip package before 19.2 for Python allows Directory Traversal when a URL is given in an install command, because a Content-Disposition header can have ../ in a filename, as demonstrated by overwr…
CVE-2021-28677 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-25288 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-28678 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-28675 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-25287 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2021-28676 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:4149: python-pillow security update (Moderate)
CVE-2017-18640 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2020:4807: prometheus-jmx-exporter security update (Moderate)
CVE-2020-13956 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2022:1861: maven:3.5 security update (Moderate)
CVE-2021-33503 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:4162: python38:3.8 and python38-devel:3.8 security update (Moderate)
CVE-2021-31204 medium 5.5 FIX arch arch rhel 5y ago privilege escalation in dotnet-sdk, dotnet-runtime
CVE-2020-14040 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2020:4694: container-tools:rhel8 security, bug fix, and enhancement update (Moderate)
CVE-2020-5238 medium 5.5 FIX debian debian rhel 5y ago RHSA-2021:1972: pandoc security update (Moderate)
CVE-2020-13632 medium 5.5 FIX rocky slesdebian debian 5y ago RHSA-2021:1968: mingw packages security and bug fix update (Moderate)
CVE-2020-13631 medium 5.5 FIX rocky slesdebian debian 5y ago RHSA-2021:1968: mingw packages security and bug fix update (Moderate)
CVE-2020-13630 medium 5.5 FIX rocky slesdebian debian 5y ago RHSA-2021:1968: mingw packages security and bug fix update (Moderate)
CVE-2020-13434 medium 5.5 FIX rocky slesdebian debian 5y ago RHSA-2021:1968: mingw packages security and bug fix update (Moderate)
CVE-2019-16168 medium 6.5 6.5 FIX rocky slesdebian debian sqlitenetapptenable 5y ago RHSA-2021:1968: mingw packages security and bug fix update (Moderate)
CVE-2019-20398 medium 5.5 FIX rockydebian debianalmalinux almalinux 5y ago RHEA-2021:1906: libyang bug fix and enhancement update (Moderate)
CVE-2019-20397 medium 5.5 FIX rockydebian debianalmalinux almalinux 5y ago RHEA-2021:1906: libyang bug fix and enhancement update (Moderate)
CVE-2019-20396 medium 5.5 FIX rockydebian debianalmalinux almalinux 5y ago RHEA-2021:1906: libyang bug fix and enhancement update (Moderate)
CVE-2019-20395 medium 5.5 FIX rockydebian debianalmalinux almalinux 5y ago RHEA-2021:1906: libyang bug fix and enhancement update (Moderate)
CVE-2019-20394 medium 5.5 FIX rockydebian debianalmalinux almalinux 5y ago RHEA-2021:1906: libyang bug fix and enhancement update (Moderate)
CVE-2019-20393 medium 5.5 FIX rockydebian debianalmalinux almalinux 5y ago RHEA-2021:1906: libyang bug fix and enhancement update (Moderate)
CVE-2019-20392 medium 5.5 FIX rockydebian debianalmalinux almalinux 5y ago RHEA-2021:1906: libyang bug fix and enhancement update (Moderate)
CVE-2019-20391 medium 5.5 FIX rockydebian debianalmalinux almalinux 5y ago RHEA-2021:1906: libyang bug fix and enhancement update (Moderate)
CVE-2020-25275 medium 5.5 FIX arch arch slesdebian debian 5y ago Dovecot before 2.3.13 has Improper Input Validation in lda, lmtp, and imap, leading to an application crash via a crafted email message with certain choices for ten thousand MIME parts.
CVE-2020-24386 medium 5.5 FIX arch arch slesdebian debian 5y ago An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email m…
CVE-2020-27778 medium 5.5 FIX sles rockydebian debian 5y ago A flaw was found in Poppler in the way certain PDF files were converted into HTML. A remote attacker could exploit this flaw by providing a malicious PDF file that, when processed by the 'pdftohtml' …
CVE-2021-3177 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:1879: python38:3.8 security update (Moderate)
CVE-2020-26116 medium 5.5 FIX sles rockydebian debian 5y ago http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by ins…
CVE-2020-17538 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16310 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16309 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16308 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16307 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16306 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16305 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2023:7053: ghostscript security and bug fix update (Moderate)
CVE-2020-16304 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16303 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16302 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16301 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16300 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16299 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16298 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16297 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16296 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16295 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16294 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16293 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16292 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16291 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16290 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16289 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16288 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-16287 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-14373 medium 5.5 FIX slesdebian debian rocky 5y ago RHSA-2021:1852: ghostscript security, bug fix, and enhancement update (Moderate)
CVE-2020-4033 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:1849: freerdp security, bug fix, and enhancement update (Moderate)
CVE-2020-4030 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:1849: freerdp security, bug fix, and enhancement update (Moderate)
CVE-2020-15103 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:1849: freerdp security, bug fix, and enhancement update (Moderate)
CVE-2020-11099 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:1849: freerdp security, bug fix, and enhancement update (Moderate)
CVE-2020-11098 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:1849: freerdp security, bug fix, and enhancement update (Moderate)
CVE-2020-11097 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:1849: freerdp security, bug fix, and enhancement update (Moderate)
CVE-2020-11096 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:1849: freerdp security, bug fix, and enhancement update (Moderate)
CVE-2020-11095 medium 5.5 FIX arch arch slesdebian debian 5y ago RHSA-2021:1849: freerdp security, bug fix, and enhancement update (Moderate)
CVE-2020-25713 medium 5.5 FIX arch arch sles rocky 5y ago A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.
CVE-2017-18926 medium 5.5 FIX arch arch sles rocky 5y ago raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overfl…
CVE-2020-25708 medium 5.5 FIX rockydebian debian rhel 5y ago A divide by zero issue was found to occur in libvncserver-0.9.12. A malicious client could use this flaw to send a specially crafted message that, when processed by the VNC server, would lead to a fl…
CVE-2020-14405 medium 5.5 FIX sles rockydebian debian 5y ago An issue was discovered in LibVNCServer before 0.9.13. libvncclient/rfbproto.c does not limit TextChat size.
CVE-2020-14397 medium 5.5 FIX sles rockydebian debian 5y ago An issue was discovered in LibVNCServer before 0.9.13. libvncserver/rfbregion.c has a NULL pointer dereference.
CVE-2019-20839 medium 5.5 FIX sles rockydebian debian 5y ago libvncclient/sockets.c in LibVNCServer before 0.9.13 has a buffer overflow via a long socket filename.
CVE-2018-21247 medium 5.5 FIX sles rockydebian debian 5y ago An issue was discovered in LibVNCServer before 0.9.13. There is an information leak (of uninitialized memory contents) in the libvncclient/rfbproto.c ConnectToRFBRepeater function.
CVE-2020-11993 medium 5.5 FIX debian debian sles rocky 5y ago Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing con…
CVE-2020-11984 medium 5.5 FIX debian debian sles rocky 5y ago Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
CVE-2018-17199 medium 5.5 FIX debian debianarch arch sles 5y ago In Apache HTTP Server 2.4 release 2.4.37 and prior, mod_session checks the session expiry time before decoding the session. This causes session expiry time to be ignored for mod_session_cookie sessio…
CVE-2020-25712 medium 5.5 FIX arch arch sles rocky 5y ago A flaw was found in xorg-x11-server before 1.20.10. A heap-buffer overflow in XkbSetDeviceInfo may lead to a privilege escalation vulnerability. The highest threat from this vulnerability is to data …
CVE-2020-14363 medium 5.5 FIX sles rockydebian debian 5y ago RHSA-2021:1804: userspace graphics, xorg-x11, and mesa security, bug fix, and enhancement update (Moderate)
CVE-2020-14362 medium 5.5 FIX sles rockydebian debian 5y ago A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vul…
CVE-2020-14361 medium 5.5 FIX sles rockydebian debian 5y ago A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Integer underflow leading to heap-buffer overflow may lead to a privilege escalation vulnerability. The highest threat from this vul…
CVE-2020-14360 medium 5.5 FIX arch arch sles rocky 5y ago A flaw was found in the X.Org Server before version 1.20.10. An out-of-bounds access in the XkbSetMap function may lead to a privilege escalation vulnerability. The highest threat from this vulnerabi…
CVE-2020-14347 medium 5.5 FIX arch arch sles rocky 5y ago A flaw was found in the way xserver memory was not properly initialized. This could leak parts of server memory to the X client. In cases where Xorg server runs with elevated privileges, this could r…
CVE-2020-14346 medium 5.5 FIX sles rockydebian debian 5y ago A flaw was found in xorg-x11-server before 1.20.9. An integer underflow in the X input extension protocol decoding in the X server may lead to arbitrary access of memory contents. The highest threat …
CVE-2020-14345 medium 5.5 FIX sles rockydebian debian 5y ago A flaw was found in X.Org Server before xorg-x11-server 1.20.9. An Out-Of-Bounds access in XkbSetNames function may lead to a privilege escalation vulnerability. The highest threat from this vulnerab…
CVE-2020-14344 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:1804: userspace graphics, xorg-x11, and mesa security, bug fix, and enhancement update (Moderate)
CVE-2020-25653 medium 5.5 FIX arch arch sles rocky 5y ago A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice…
CVE-2020-25652 medium 5.5 FIX arch arch sles rocky 5y ago A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any …
CVE-2020-25651 medium 5.5 FIX arch arch sles rocky 5y ago A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active fil…
CVE-2020-25650 medium 5.5 FIX arch arch sles rocky 5y ago A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path …
CVE-2020-12695 medium 5.5 FIX arch archdebian debian rocky 5y ago RHSA-2021:1789: gssdp and gupnp security update (Moderate)
CVE-2020-29443 medium 5.5 FIX sles rockydebian debian 5y ago ide_atapi_cmd_reply_end in hw/ide/atapi.c in QEMU 5.1.0 allows out-of-bounds read access because a buffer index is not validated.
CVE-2020-29130 medium 5.5 FIX arch arch sles rocky 5y ago slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
CVE-2020-29129 medium 5.5 FIX arch arch sles rocky 5y ago ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
CVE-2020-28916 medium 5.5 FIX sles rockydebian debian 5y ago hw/net/e1000e_core.c in QEMU 5.0.0 has an infinite loop via an RX descriptor with a NULL buffer address.
CVE-2020-27821 medium 5.5 FIX sles rockydebian debian 5y ago A flaw was found in the memory management API of QEMU during the initialization of a memory region cache. This issue could lead to an out-of-bounds write access to the MSI-X table while performing MM…
CVE-2020-25723 medium 5.5 FIX sles rockydebian debian 5y ago A reachable assertion issue was found in the USB EHCI emulation code of QEMU. It could occur while processing USB requests due to missing handling of DMA memory map failure. A malicious privileged us…
CVE-2020-25707 medium 5.5 sles rocky rhel 5y ago RHSA-2021:1762: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
CVE-2020-25637 medium 5.5 FIX arch arch sles rocky 5y ago RHSA-2021:1762: virt:rhel and virt-devel:rhel security, bug fix, and enhancement update (Moderate)
CVE-2020-16092 medium 5.5 FIX sles rockydebian debian 5y ago In QEMU through 5.0.0, an assertion failure can occur in the network packet processing. This issue affects the e1000e and vmxnet3 network devices. A malicious guest user/process could use this flaw t…
CVE-2020-11947 medium 5.5 FIX sles rockydebian debian 5y ago iscsi_aio_ioctl_cb in block/iscsi.c in QEMU 4.1.0 has a heap-based buffer over-read that may disclose unrelated information from process memory to an attacker.