CVEs from 2020

4,160 normalized CVEs published or assigned in this year.

Total
4,160
critical
critical 193
high
high 470
medium
medium 675
low
low 56
% Critical
4.6%
% with KEV
3.5%
% with exploit
3.6%

Top products

  • banking_digital_experience 30
  • retail_xstore_point_of_service 28
  • primavera_unifier 27
  • retail_service_backbone 15
  • financial_services_institutional_performance_analytics 10
  • communications_network_charging_and_control 10
  • communications_contacts_server 9
  • agile_plm 8
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2020-12460 medium 5.5 OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a spe… archdebian
CVE-2020-26416 medium 5.5 information disclosure in gitlab arch
CVE-2020-22037 medium 5.5 A Denial of Service vulnerability exists in FFmpeg 4.2 due to a memory leak in avcodec_alloc_context3 at options.c. archsusedebian
CVE-2020-22019 medium 5.5 Buffer Overflow vulnerability in FFmpeg 4.2 at convolution_y_10bit in libavfilter/vf_vmafmotion.c, which could let a remote malicious user cause a Denial of Service. archsusedebian
CVE-2020-28928 medium 5.5 In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow). archdebian
CVE-2020-25722 medium 5.5 Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise. archsusedebian
CVE-2020-27748 medium 5.5 A flaw was found in the xdg-email component of xdg-utils-1.1.0-rc1 and newer. When handling mailto: URIs, xdg-email allows attachments to be discreetly added via the URI when being passed to Thunderb… archsusedebian
CVE-2020-36222 medium 5.5 A flaw was discovered in OpenLDAP before 2.4.57 leading to an assertion failure in slapd in the saslAuthzTo validation, resulting in denial of service. archsusedebian
CVE-2020-0499 medium 5.5 In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional exe… archsusedebian
CVE-2020-35965 medium 5.5 decode_frame in libavcodec/exr.c in FFmpeg 4.3.1 has an out-of-bounds write because of errors in calculations of when to perform memset zero operations. archsusedebian
CVE-2020-35512 medium 5.5 A use-after-free flaw was found in D-Bus Development branch <= 1.13.16, dbus-1.12.x stable branch <= 1.12.18, and dbus-1.10.x and older branches <= 1.10.30 when a system has multiple usernames sharin… archdebiansuse
CVE-2020-23922 medium 5.5 An issue was discovered in giflib through 5.1.4. DumpScreen2RGB in gif2rgb.c has a heap-based buffer over-read. archsusedebian
CVE-2020-22015 medium 5.5 Buffer Overflow vulnerability in FFmpeg 4.2 in mov_write_video_tag due to the out of bounds in libavformat/movenc.c, which could let a remote malicious user obtain sensitive information, cause a Deni… archsusedebian
CVE-2020-35498 medium 5.5 A vulnerability was found in openvswitch. A limitation in the implementation of userspace packet parsing can allow a malicious user to send a specially crafted packet causing the resulting megaflow i… archsusedebian
CVE-2020-11810 medium 5.5 An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arri… archsusedebian
CVE-2020-18972 medium 5.5 Exposure of Sensitive Information to an Unauthorized Actor in PoDoFo v0.9.6 allows attackers to obtain sensitive information via 'IsNextToken' in the component 'src/base/PdfToenizer.cpp'. archdebian
CVE-2020-15078 medium 5.5 OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentia… archsusedebian
CVE-2020-6851 medium 5.5 OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation. archsusedebian
CVE-2020-22033 medium 5.5 A heap-based Buffer Overflow Vulnerability exists FFmpeg 4.2 at libavfilter/vf_vmafmotion.c in convolution_y_8bit, which could let a remote malicious user cause a Denial of Service. archsusedebian
CVE-2020-28634 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-35474 medium 5.5 In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that t… archdebian
CVE-2020-26977 medium 5.5 By attempting to connect a website using an unresponsive port, an attacker could have controlled the content of a tab while the URL bar displayed the original domain. *Note: This issue only affects F… archdebian
CVE-2020-12272 medium 5.5 OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsin… archdebian
CVE-2020-16154 medium 5.5 The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass. archdebian
CVE-2020-27637 medium 5.5 The R programming language’s default package manager CRAN is affected by a path traversal vulnerability that can lead to server compromise. This vulnerability affects packages installed via the R CMD… archdebian
CVE-2020-35478 medium 5.5 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. MediaWiki:blanknamespace potentially can be output as raw HTML with SCRIPT tags via LogFormatter::makePageLink(). This affects MediaWiki … archdebian
CVE-2020-26975 medium 5.5 When a malicious application installed on the user's device broadcast an Intent to Firefox for Android, arbitrary headers could have been specified, leading to attacks such as abusing ambient authori… archdebian
CVE-2020-35479 medium 5.5 MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is alway… archdebian
CVE-2020-35480 medium 5.5 An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the vi… archdebian
CVE-2020-36225 medium 5.5 A flaw was discovered in OpenLDAP before 2.4.57 leading to a double free and slapd crash in the saslAuthzTo processing, resulting in denial of service. archsusedebian
CVE-2020-28633 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-35499 medium 5.5 A NULL pointer dereference flaw in Linux kernel versions prior to 5.11 may be seen if sco_sock_getsockopt function in net/bluetooth/sco.c do not have a sanity check for a socket connection, when usin… archsusedebian
CVE-2020-28600 medium 5.5 An out-of-bounds write vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can … archdebian
CVE-2020-28196 medium 5.5 MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite l… susedebianrockylinux
CVE-2020-35518 medium 5.5 information disclosure in 389-ds-base debianarchsuse
CVE-2020-13848 medium 5.5 Portable UPnP SDK (aka libupnp) 1.12.1 and earlier allows remote attackers to cause a denial of service (crash) via a crafted SSDP message due to a NULL pointer dereference in the functions FindServi… archdebian
CVE-2020-28635 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-15011 medium 5.5 Moderate: mailman:2.1 security update suserockylinux
CVE-2020-28621 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… debianarch
CVE-2020-28622 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-28623 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-28627 medium 5.5 Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confu… archdebian
CVE-2020-23930 medium 5.5 An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldump_send_header located in write_nhml.c. It allows an attacker to cause Denial of Service. archdebian
CVE-2020-28636 medium 5.5 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->… archdebian
CVE-2020-11653 medium 5.5 An issue was discovered in Varnish Cache before 6.0.6 LTS, 6.1.x and 6.2.x before 6.2.3, and 6.3.x before 6.3.2. It occurs when communication with a TLS termination proxy uses PROXY version 2. There … rockylinuxdebian
CVE-2020-37174 medium 5.5 5.5 15d ago WOOF Products Filter for WooCommerce 1.2.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by entering XSS payloads in design …
CVE-2020-37169 medium 5.5 5.5 15d ago WordPress Plugin ultimate-member 2.1.3 contains a local file inclusion vulnerability that allows authenticated attackers to include arbitrary files by manipulating the pack parameter in class-admin-u…
CVE-2020-36855 medium 5.5 5.5 7mo ago A security vulnerability has been detected in DCMTK up to 3.6.5. The affected element is the function parseQuota of the component dcmqrscp. The manipulation of the argument StorageQuota leads to stac… debian
CVE-2020-16156 medium 5.5 1y ago Moderate: perl-CPAN security update archrockylinuxsusedebian
CVE-2020-13790 medium 5.5 1y ago Moderate: libjpeg-turbo security update rockylinuxsusedebian
CVE-2020-27792 medium 5.5 1y ago Moderate: ghostscript security update rockylinuxsusedebian
CVE-2020-10135 medium 5.5 2y ago RHSA-2024:9315: kernel security update (Moderate) redhatsuse
CVE-2020-27827 medium 5.5 2y ago Moderate: lldpd security update redhatarchsuserockylinux+1
CVE-2020-36777 medium 5.5 2y ago In the Linux kernel, the following vulnerability has been resolved: media: dvbdev: Fix memory leak in dvb_media_device_free() dvb_media_device_free() is leaking memory. Free `dvbdev->adapter->conn`… rockylinuxsusedebian
CVE-2020-18651 medium 5.5 2y ago Moderate: exempi security update rockylinuxsusedebian
CVE-2020-25656 medium 5.5 2y ago A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access … rockylinuxsusedebian
CVE-2020-15778 medium 5.5 2y ago Moderate: openssh security update rockylinuxsusedebian
CVE-2020-36024 medium 5.5 2y ago Moderate: poppler security update susedebian
CVE-2020-18652 medium 5.5 2y ago Moderate: exempi security update rockylinuxsusedebian
CVE-2020-18770 medium 5.5 2y ago Moderate: zziplib security update redhatrockylinuxsusedebian
CVE-2020-14370 medium 5.5 2y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update archsuserockylinuxdebian+1
CVE-2020-28991 medium 5.5 2y ago Improper Access Control in Gitea archgolang
CVE-2020-28241 medium 5.5 2y ago Moderate: libmaxminddb security update rockylinuxdebian
CVE-2020-35177 medium 5.5 2y ago Enumeration of users in HashiCorp Vault in github.com/hashicorp/vault archgolang
CVE-2020-28053 medium 5.5 2y ago Privilege Escalation in HashiCorp Consul in github.com/hashicorp/consul archdebiangolang
CVE-2020-25201 medium 5.5 2y ago Denial of service in HashiCorp Consul in github.com/hashicorp/consul archdebiangolang
CVE-2020-22217 medium 5.5 3y ago Moderate: c-ares security update debiansuserockylinux
CVE-2020-12762 medium 5.5 3y ago Moderate: libfastjson security update redhatarchsuserockylinux+1
CVE-2020-24736 medium 5.5 3y ago Moderate: sqlite security update rockylinuxdebian
CVE-2020-36518 medium 5.5 3y ago Deeply nested json in jackson-databind redhatsusedebianjava
CVE-2020-17049 medium 5.5 3y ago Moderate: krb5 security, bug fix, and enhancement update redhatsuserockylinux
CVE-2020-28851 medium 5.5 4y ago Moderate: podman security and bug fix update redhatsuserockylinuxdebian
CVE-2020-28852 medium 5.5 4y ago Moderate: podman security and bug fix update redhatsuserockylinuxdebian
CVE-2020-36516 medium 5.5 4y ago An issue was discovered in the Linux kernel through 5.16.11. The mixed IPID assignment method with the hash-based IPID assignment policy allows an off-path attacker to inject data into a victim's TCP… redhatsuserockylinuxdebian
CVE-2020-36558 medium 5.5 4y ago A race condition in the Linux kernel before 5.5.7 involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault. suserockylinuxdebian
CVE-2020-0256 medium 5.5 4y ago Moderate: gdisk security update rockylinuxdebian
CVE-2020-10735 medium 5.5 4y ago Moderate: python3.9 security update rockylinuxredhatsusedebian
CVE-2020-35525 medium 5.5 4y ago Moderate: sqlite security update suserockylinuxdebian
CVE-2020-35527 medium 5.5 4y ago Moderate: sqlite security update suserockylinuxdebian
CVE-2020-28469 medium 5.5 4y ago Moderate: nodejs and nodejs-nodemon security and bug fix update redhatrockylinuxdebiannpm
CVE-2020-7788 medium 5.5 4y ago Moderate: nodejs:10 security update redhatrockylinuxdebiannpm
CVE-2020-35509 medium 5.5 4y ago Keycloak vulnerable to Improper Certificate Validation archjava
CVE-2020-29652 medium 5.5 4y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update debianrockylinuxgolang
CVE-2020-1695 medium 5.5 4y ago Improper Input Validation in RESTEasy rockylinuxdebianjava
CVE-2020-25864 medium 5.5 4y ago HashiCorp Consul Cross-site Scripting vulnerability in github.com/hashicorp/consul archdebiangolang
CVE-2020-10770 medium 5.5 4y ago Keycloak vulnerable to Server-Side Request Forgery archjava
CVE-2020-24303 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update suserockylinuxgolang
CVE-2020-11110 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update susegolang
CVE-2020-10749 medium 5.5 4y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update susedebianrockylinuxgolang
CVE-2020-13430 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update susegolang
CVE-2020-12458 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update susegolang
CVE-2020-12459 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update golang
CVE-2020-12245 medium 5.5 4y ago Moderate: grafana security, bug fix, and enhancement update susegolang
CVE-2020-1726 medium 5.5 4y ago Moderate: container-tools:rhel8 security, bug fix, and enhancement update debianrockylinuxgolang
CVE-2020-35492 medium 5.5 4y ago Moderate: cairo and pixman security and bug fix update debianarchsuserockylinux
CVE-2020-35452 medium 5.5 4y ago Moderate: httpd:2.4 security and bug fix update debianarchsuserockylinux
CVE-2020-19131 medium 5.5 4y ago Moderate: libtiff security update suserockylinuxdebian
CVE-2020-18898 medium 5.5 4y ago Moderate: compat-exiv2-026 security update archsusedebianrockylinux
CVE-2020-27826 medium 5.5 4y ago Authentication Bypass in keycloak archjava
CVE-2020-29509 medium 5.5 4y ago The encoding/xml package in Go (all versions) does not correctly preserve the semantics of attribute namespace prefixes during tokenization round-trips, which allows an attacker to craft inputs that … archsusedebiangolang