CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject LinuxOracle5Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+2 moreJun 17, 2026 Mar 25, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is...Show more |
4Fedoraproject LinuxNetapp+1 more10Communications Cloud Native Core Binding Support Function FedoraH300e Firmware+7 moreJun 17, 2026 Mar 25, 2022 N/A· v4 8.0 HIGH· v3 7.4 HIGH· v2 An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potent...Show more |
3Fedoraproject NetappRedhat3Fedora LibvirtOntap Select Deploy Administration UtilityJun 17, 2026 Mar 25, 2022 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition. |
4Debian FedoraprojectOpenexr+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 25, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not...Show more |
3Debian FedoraprojectOpenexr3Debian Linux FedoraOpenexrJun 17, 2026 Mar 25, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application s...Show more |
2Fedoraproject Linuxfoundation2Fedora ImgcryptJun 17, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images. The imgcrypt...Show more |
2Fedoraproject Powerdns3Authoritative Server FedoraRecursorJun 17, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition c...Show more |
11Apple AzulDebian+8 more27Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+24 moreJul 14, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. |
4Debian FedoraprojectLinuxfoundation+1 more4Debian Linux FedoraMoby+1 moreJun 17, 2026 Mar 24, 2022 N/A· v4 5.9 MEDIUM· v3 4.6 MEDIUM· v2 Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-em...Show more |
2Fedoraproject Redhat3389 Directory Server Enterprise LinuxFedoraJun 17, 2026 Mar 23, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Mar 23, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem. |
5Canonical DebianFedoraproject+2 more6Debian Linux Enterprise LinuxEnterprise Linux Advanced Virtualization Eus+3 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 6.9 MEDIUM· v2 A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has b...Show more |
5Debian F5Fedoraproject+2 more5Debian Linux FedoraNginx+2 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker...Show more |
5Fedoraproject IscJuniper+2 more12Bind FedoraH300e Firmware+9 moreJun 17, 2026 Mar 23, 2022 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported...Show more |
4Fedoraproject IscNetapp+1 more11Bind FedoraH300e Firmware+8 moreJun 17, 2026 Mar 23, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an...Show more |
5Debian FedoraprojectLinux+2 more13Debian Linux Enterprise LinuxFedora+10 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause...Show more |
6Debian FedoraprojectLinux+3 more30Build Of Quarkus Codeready Linux BuilderCommunications Cloud Native Core Binding Support Function+27 moreJun 17, 2026 Mar 18, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege...Show more |
3Debian FedoraprojectOpenvpn3Debian Linux FedoraOpenvpnJun 17, 2026 Mar 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be grant...Show more |
3Fedoraproject GolangRedhat4Advanced Cluster Management For Kubernetes Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 18, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. |
3Debian FedoraprojectParamiko3Debian Linux FedoraParamikoJun 17, 2026 Mar 17, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure. |