← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Debian
FedoraprojectNetapp+2 more
11Active Iq Unified Manager
Clustered Data Ontap Antivirus ConnectorDebian Linux+8 more
Jun 17, 2026
Jul 5, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in...Show more
AES OCB mode for 32-bit x86 platforms using the AES-NI assembly optimised implementation will not encrypt the entirety of the data under some circumstances. This could reveal sixteen bytes of data that was preexisting in the memory that wasn't written. In the special case of "in place" encryption, sixteen bytes of the plaintext would be revealed. Since OpenSSL does not support OCB based cipher suites for TLS and DTLS, they are both unaffected. Fixed in OpenSSL 3.0.5 (Affected 3.0.0-3.0.4). Fixed in OpenSSL 1.1.1q (Affected 1.1.1-1.1.1p).Show less
2Fedoraproject
Lxml
2Fedora
Lxml
Jun 17, 2026
Jul 5, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected....Show more
NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused by the iterwalk function (also used by the canonicalize function). Such code shouldn't be in wide-spread use, given that parsing + iterwalk would usually be replaced with the more efficient iterparse function. However, an XML converter that serialises to C14N would also be vulnerable, for example, and there are legitimate use cases for this code sequence. If untrusted input is received (also remotely) and processed via iterwalk function, a crash can be triggered.Show less
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jul 3, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Use After Free in GitHub repository vim/vim prior to 9.0.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jul 3, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jul 2, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Jun 17, 2026
Jul 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a u...Show more
An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a username contains HTML entities, it won't be escaped.Show less
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
Jun 17, 2026
Jul 2, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when i...Show more
An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to "Welcome" followed by the username, the username is not escaped: SpecialCreateAccount::successfulAction() calls ::showSuccessPage() with a message as second parameter, and OutputPage::setPageTitle() uses text().Show less
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jul 2, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
3Debian
FedoraprojectVim
3Debian Linux
FedoraVim
Jun 17, 2026
Jul 2, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jul 2, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
4Debian
FedoraprojectGnupg+1 more
5Active Iq Unified Manager
Debian LinuxFedora+2 more
Jun 17, 2026
Jul 1, 2022
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into th...Show more
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.Show less
2Fedoraproject
Jpegoptim Project
2Fedora
Jpegoptim
Jun 17, 2026
Jul 1, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c.
3Debian
FedoraprojectMariadb
3Debian Linux
FedoraMariadb
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.
2Fedoraproject
Mariadb
2Fedora
Mariadb
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.
3Debian
FedoraprojectMariadb
3Debian Linux
FedoraMariadb
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
2Fedoraproject
Mariadb
2Fedora
Mariadb
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
2Fedoraproject
Mariadb
2Fedora
Mariadb
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.
2Fedoraproject
Lua
2Fedora
Lua
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jun 30, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.