Where
AND
AND
-Infinity
0
Severity
7.5
Infoleak
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

ABRT might allow attackers to obtain sensitive information from crash reports.

First published (updated )
Severity
8.1
Malicious File Upload
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Last updated 25 August 2025

1 / 4
Source: Ubuntu
First published (updated )
Severity
7.8
Use After Free
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability

1 / 3
Source: CISA
First published (updated )
Severity
8.1
Malicious File Upload, Input Validation
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

A vulnerability was discovered in Tomcat where if a servlet context was configured with readonly=false and HTTP PUT requests were allowed, an attacker could upload a JSP file to that context and achieve code execution.

1 / 4
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic

1 / 5
Source: Microsoft
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Last updated 11 July 2025

1 / 4
Source: Ubuntu
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A missing bounds check was found in the way OpenSSL handled TLS heartbeat extension packets. This flaw could be used to reveal up to 64k of memory from a connected client or server.

Only 1.0.1 releases of OpenSSL are affected including 1.0.1f (and 1.0.2 betas)

The following upstream commit introduced TLS/DTLS heatbeat support and also this issue:

http://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff;h=4817504

1 / 3
Source: Red Hat
First published (updated )
Severity
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

Withdrawn Advisory This advisory has been withdrawn because the vulnerability only affects the Qpid Proton C library and not org.apache.qpid:proton-j. This link has been maintained to preserve external references.

Original Description

While investigating bug PROTON-2014, we discovered that under some circumstances Apache Qpid Proton versions 0.9 to 0.27.0 (C library and its language bindings) can connect to a peer anonymously using TLS even when configured to verify the peer certificate while used with OpenSSL versions before 1.1.0. This means that an undetected man in the middle attack could be constructed if an attacker can arrange to intercept TLS traffic.

1 / 3
Source: GitHub
First published (updated )
Severity
8.3
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

It was discovered that the JNDI comment of OpenJDK did not properly enforce the restriction controlled by the com.sun.jndi.ldap.object.trustURLCodebase system property. In certain cases, a Java LDAP client could unexpectedly load and execute code form an LDAP server.

1 / 3
Source: Red Hat
First published (updated )
Severity
7.8
Use After Free, Double Free
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

It was found that the raw midi kernel driver does not protect against concurrent access which leads to a double realloc (double free) in sndrawmidiinputparams() and sndrawmidioutputstatus() which are part of sndrawmidiioctl() handler in rawmidi.c file. A malicious local attacker could possibly use this for privilege escalation.

1 / 3
Source: Launchpad
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Google Chromium V8 Engine contains a type confusion vulnerability allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

1 / 3
Source: CISA
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An inappropriate implementation flaw was found in the JavaScript component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1029576

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An insufficient data validation flaw was found in the streams component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1031895

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An use after free flaw was found in the audio component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1042254

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An inappropriate implementation flaw was found in the Blink component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1024256

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An insufficient policy enforcement flaw was found in the downloads component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1029375

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An uninitialized use flaw was found in the PDFium component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1032090

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An use after free flaw was found in the speech component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1043603

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop18.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An insufficient policy enforcement flaw was found in the storage component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1035399

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An out of bounds memory access flaw was found in the streams component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1045874

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A type confusion flaw was found in the V8 component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1051017

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop18.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An use after free flaw was found in the WebAudio component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1048473

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop18.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

A type confusion flaw was found in the JavaScript component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1031909

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
Integer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An integer overflow flaw was found in the JavaScript component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1034394

External References:

https://chromereleases.googleblog.com/2020/02/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
Use After Free
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

An use after free flaw was found in the audio component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=1029462

External References:

https://chromereleases.googleblog.com/2020/01/stable-channel-update-for-desktop.html

1 / 2
Source: Red Hat
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

1 / 2
Source: MITRE
First published (updated )
Severity
8.1
AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

A flaw was found in the Serialization component of OpenJDK handled serialization filter. A process-wide filter could have been modified by setting jdk.serialFilter system property at runtime, possibly leading to a bypass of the intended filter during deserialization.

1 / 5
Source: Red Hat
First published (updated )
Severity
7.5
SQL Injection, Null Pointer Dereference
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Last updated 25 August 2025

1 / 4
Source: Ubuntu
First published (updated )
Severity
7.5
Null Pointer Dereference, SQL Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

flattenSubquery in select.c in SQLite 3.30.1 mishandles certain uses of SELECT DISTINCT involving a LEFT JOIN in which the right-hand side is a view. This can cause a NULL pointer dereference (or incorrect results).

1 / 4
Source: Launchpad
First published (updated )
Severity
7.5
SQL Injection, Malicious File Upload
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Last updated 25 August 2025

1 / 4
Source: Ubuntu
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203