CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGit4Debian Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Apr 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a...Show more |
2Fedoraproject Hashicorp2Consul FedoraJun 17, 2026 Apr 19, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10....Show more |
4Fedoraproject KubernetesMobyproject+1 more4Cri O FedoraMoby+1 moreJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable L...Show more |
2Fedoraproject Opensc Project2Fedora OpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library. |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library. |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library. |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid. |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo. |
3Apple FedoraprojectVim3Fedora MacosVimJun 17, 2026 Apr 18, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution |
2Fedoraproject Plantuml2Fedora PlantumlJun 17, 2026 Apr 15, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets t...Show more |
2Fedoraproject Stb Project2Fedora StbJun 17, 2026 Apr 15, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac. |
3Debian FedoraprojectNothings3Debian Linux FedoraStb Image.hJun 17, 2026 Apr 15, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode. |
3Debian FedoraprojectNothings3Debian Linux FedoraStb Image.hJun 17, 2026 Apr 15, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors. |
3Debian FedoraprojectMutt3Debian Linux FedoraMuttJun 17, 2026 Apr 14, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line |
3E2fsprogs Project FedoraprojectRedhat3E2fsprogs Enterprise LinuxFedoraJun 17, 2026 Apr 14, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem. |
3Fedoraproject GetcomposerTenable3Composer FedoraTenable.scJun 17, 2026 Apr 13, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$iden...Show more |
3Fedoraproject NetappPython5Active Iq Unified Manager FedoraOntap Select Deploy Administration Utility+2 moreNov 3, 2025 Apr 13, 2022 N/A· v4 7.6 HIGH· v3 8.0 HIGH· v2 In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call m...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Apr 12, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Git for Windows is a fork of Git containing Windows-specific patches. This vulnerability affects users working on multi-user machines, where untrusted parties have write access to the same hard disk. Those untrusted part...Show more |
4Apache AppleDebian+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Apr 12, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn se...Show more |
4Apache AppleDebian+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Apr 12, 2022 N/A· v4 4.3 MEDIUM· v3 3.5 LOW· v2 Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied...Show more |