Vulnerabilities > Debian

DATE CVE VULNERABILITY TITLE RISK
2020-06-29 CVE-2020-15393 Memory Leak vulnerability in multiple products
In the Linux kernel 4.4 through 5.7.6, usbtest_disconnect in drivers/usb/misc/usbtest.c has a memory leak, aka CID-28ebeb8db770.
local
low complexity
linux debian opensuse canonical CWE-401
2.1
2020-06-29 CVE-2020-15389 Use After Free vulnerability in multiple products
jp2/opj_decompress.c in OpenJPEG through 2.3.1 has a use-after-free that can be triggered if there is a mix of valid and invalid files in a directory operated on by the decompressor.
network
high complexity
uclouvain debian oracle CWE-416
6.5
2020-06-29 CVE-2020-4067 Improper Initialization vulnerability in multiple products
In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly.
7.5
2020-06-26 CVE-2020-11996 A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds.
network
low complexity
apache canonical oracle opensuse debian netapp
7.5
2020-06-26 CVE-2020-15306 Out-of-bounds Write vulnerability in multiple products
An issue was discovered in OpenEXR before v2.5.2.
5.5
2020-06-26 CVE-2020-15305 Use After Free vulnerability in multiple products
An issue was discovered in OpenEXR before 2.5.2.
5.5
2020-06-25 CVE-2020-10177 Out-of-bounds Read vulnerability in multiple products
Pillow before 7.1.0 has multiple out-of-bounds reads in libImaging/FliDecode.c.
5.5
2020-06-24 CVE-2020-15005 In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them.
network
high complexity
mediawiki fedoraproject debian
3.1
2020-06-24 CVE-2020-9494 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Apache Traffic Server 6.0.0 to 6.2.3, 7.0.0 to 7.1.10, and 8.0.0 to 8.0.7 is vulnerable to certain types of HTTP/2 HEADERS frames that can cause the server to allocate a large amount of memory and spin the thread.
network
low complexity
apache debian CWE-119
5.0
2020-06-24 CVE-2020-12865 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow in SANE Backends before 1.0.30 may allow a malicious device connected to the same local network as the victim to execute arbitrary code, aka GHSL-2020-084.
8.0