CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Apr 11, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents...Show more |
2Fedoraproject Lua2Fedora LuaJun 17, 2026 Apr 8, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code. |
4Fedoraproject LinuxNetapp+1 more15Active Iq Unified Manager Enterprise LinuxFedora+12 moreJun 17, 2026 Apr 8, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. |
2Async Project Fedoraproject2Async FedoraJun 17, 2026 Apr 6, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution. |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system m...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 7.0 HIGH· v3 6.2 MEDIUM· v2 race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xe...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Apr 5, 2022 N/A· v4 5.6 MEDIUM· v3 4.0 MEDIUM· v2 Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirt...Show more |
3Buildah Project FedoraprojectRedhat3Buildah Enterprise LinuxFedoraJun 17, 2026 Apr 4, 2022 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in buildah where containers were incorrectly started with non-empty default permissions. A bug was found in Moby (Docker Engine) where containers were incorrectly started with non-empty inheritable Linux...Show more |
3Crun Project FedoraprojectRedhat4Crun Enterprise LinuxFedora+1 moreJun 17, 2026 Apr 4, 2022 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritabl...Show more |
3Fedoraproject Podman ProjectRedhat14Developer Tools Enterprise LinuxEnterprise Linux Eus+11 moreJun 17, 2026 Apr 4, 2022 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheri...Show more |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraTwisted+1 moreJun 17, 2026 Apr 4, 2022 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to version 22.4.0rc1, the Twisted Web HTTP 1.1 server, located in the `twisted.web.http` module, parsed several HTTP request co...Show more |
5Debian FedoraprojectMomentjs+2 more5Active Iq Debian LinuxFedora+2 moreJun 17, 2026 Apr 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if...Show more |
2Fedoraproject Htmldoc Project2Fedora HtmldocJun 17, 2026 Apr 4, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow. |
4Debian FedoraprojectLinux+1 more4Debian Linux FedoraHci Baseboard Management Controller+1 moreJun 17, 2026 Apr 3, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free. |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Apr 3, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free. |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Apr 3, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Apr 1, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local u...Show more |