โ† Back

Fedora

fedora

Vendor: Fedoraproject โ€ข 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Feb 8, 2022
N/Aยท v4
7.1 HIGHยท v3
5.8 MEDIUMยท v2
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
3Fedoraproject
GrafanaNetapp
3E Series Performance Analyzer
FedoraGrafana
Jun 17, 2026
Feb 8, 2022
N/Aยท v4
5.4 MEDIUMยท v3
2.1 LOWยท v2
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a...Show more
Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either compromise an existing datasource for a specific Grafana instance or either set up its own public service and instruct anyone to set it up in their Grafana instance. To be impacted, all of the following must be applicable. For the data source proxy: A Grafana HTTP-based datasource configured with Server as Access Mode and a URL set, the attacker has to be in control of the HTTP server serving the URL of above datasource, and a specially crafted link pointing at the attacker controlled data source must be clicked on by an authenticated user. For the plugin proxy: A Grafana HTTP-based app plugin configured and enabled with a URL set, the attacker has to be in control of the HTTP server serving the URL of above app, and a specially crafted link pointing at the attacker controlled plugin must be clocked on by an authenticated user. For the backend plugin resource: An attacker must be able to navigate an authenticated user to a compromised plugin through a crafted link. Users are advised to update to a patched version. There are no known workarounds for this vulnerability.Show less
2Fedoraproject
Neutrinolabs
2Fedora
Xrdp
Jun 17, 2026
Feb 7, 2022
N/Aยท v4
7.8 HIGHยท v3
7.2 HIGHยท v2
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a...Show more
xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability has been patched in version 0.9.18.1 and above. Users are advised to upgrade. There are no known workarounds.Show less
3Debian
FedoraprojectTwisted
3Debian Linux
FedoraTwisted
Jun 17, 2026
Feb 7, 2022
N/Aยท v4
7.5 HIGHยท v3
5.0 MEDIUMยท v2
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.Redir...Show more
twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.RedirectAgent` and `twisted.web. BrowserLikeRedirectAgent` functions. Users are advised to upgrade. There are no known workarounds.Show less
2Fedoraproject
Ruby Lang
2Cgi
Fedora
Jun 17, 2026
Feb 6, 2022
N/Aยท v4
9.8 CRITICALยท v3
7.5 HIGHยท v2
CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This...Show more
CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This also affects the CGI gem before 0.3.1 for Ruby.Show less
3Debian
FedoraprojectKicad
3Debian Linux
FedoraKicad Eda
Jun 17, 2026
Feb 4, 2022
N/Aยท v4
7.8 HIGHยท v3
6.8 MEDIUMยท v2
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file c...Show more
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
3Debian
FedoraprojectKicad
3Debian Linux
FedoraKicad Eda
Jun 17, 2026
Feb 4, 2022
N/Aยท v4
7.8 HIGHยท v3
6.8 MEDIUMยท v2
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file c...Show more
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
3Debian
FedoraprojectSymfony
3Debian Linux
FedoraTwig
Jun 17, 2026
Feb 4, 2022
N/Aยท v4
9.8 CRITICALยท v3
7.5 HIGHยท v2
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions th...Show more
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to code injection of arbitrary PHP code. Patched versions now disallow calling non Closure in the `sort` filter as is the case for some other filters. Users are advised to upgrade.Show less
3Debian
FedoraprojectGerbv Project
3Debian Linux
FedoraGerbv
Jun 17, 2026
Feb 4, 2022
N/Aยท v4
6.3 MEDIUMยท v3
4.3 MEDIUMยท v2
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit th...Show more
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.Show less
3Debian
FedoraprojectGerbv Project
3Debian Linux
FedoraGerbv
Jun 17, 2026
Feb 4, 2022
N/Aยท v4
8.6 HIGHยท v3
6.8 MEDIUMยท v2
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execut...Show more
A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
3Debian
DjangoprojectFedoraproject
3Debian Linux
DjangoFedora
Jun 17, 2026
Feb 3, 2022
N/Aยท v4
7.5 HIGHยท v3
5.0 MEDIUMยท v2
An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files.
3Debian
DjangoprojectFedoraproject
3Debian Linux
DjangoFedora
Jun 17, 2026
Feb 3, 2022
N/Aยท v4
6.1 MEDIUMยท v3
4.3 MEDIUMยท v2
The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS.
3Debian
FedoraprojectVim
3Debian Linux
FedoraVim
Jun 17, 2026
Feb 2, 2022
N/Aยท v4
7.8 HIGHยท v3
6.8 MEDIUMยท v2
Use After Free in GitHub repository vim/vim prior to 8.2.
4Debian
FedoraprojectPostgresql+1 more
4Debian Linux
FedoraPostgresql Jdbc Driver+1 more
Jun 17, 2026
Feb 2, 2022
N/Aยท v4
9.8 CRITICALยท v3
7.5 HIGHยท v2
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker con...Show more
pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker control the jdbc url or properties. pgjdbc instantiates plugin instances based on class names provided via `authenticationPluginClassName`, `sslhostnameverifier`, `socketFactory`, `sslfactory`, `sslpasswordcallback` connection properties. However, the driver did not verify if the class implements the expected interface before instantiating the class. This can lead to code execution loaded via arbitrary classes. Users using plugins are advised to upgrade. There are no known workarounds for this issue.Show less
3Debian
FedoraprojectVim
3Debian Linux
FedoraVim
Jun 17, 2026
Feb 1, 2022
N/Aยท v4
7.8 HIGHยท v3
6.8 MEDIUMยท v2
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
5Debian
FedoraprojectJenkins+2 more
11Commerce Guided Search
Communications Brm Elastic Charging EngineCommunications Cloud Native Core Automated Test Suite+8 more
Jun 17, 2026
Feb 1, 2022
N/Aยท v4
7.5 HIGHยท v3
5.0 MEDIUMยท v2
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel exe...Show more
XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors and accumulates the time it takes to add elements to collections and throws an exception if a set threshold is exceeded. Users are advised to upgrade as soon as possible. Users unable to upgrade may set the NO_REFERENCE mode to prevent recursion. See GHSA-rmr5-cpv2-vgjf for further details on a workaround if an upgrade is not possible.Show less
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Feb 1, 2022
N/Aยท v4
5.5 MEDIUMยท v3
4.3 MEDIUMยท v2
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
3Debian
FedoraprojectMariadb
3Debian Linux
FedoraMariadb
Jun 17, 2026
Feb 1, 2022
N/Aยท v4
7.5 HIGHยท v3
5.0 MEDIUMยท v2
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
2Fedoraproject
Mariadb
2Fedora
Mariadb
Jun 17, 2026
Feb 1, 2022
N/Aยท v4
5.5 MEDIUMยท v3
2.1 LOWยท v2
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
2Fedoraproject
Mariadb
2Fedora
Mariadb
Jun 17, 2026
Feb 1, 2022
N/Aยท v4
5.5 MEDIUMยท v3
2.1 LOWยท v2
MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.