CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 8, 2022 N/Aยท v4 7.1 HIGHยท v3 5.8 MEDIUMยท v2 Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2. |
3Fedoraproject GrafanaNetapp3E Series Performance Analyzer FedoraGrafanaJun 17, 2026 Feb 8, 2022 N/Aยท v4 5.4 MEDIUMยท v3 2.1 LOWยท v2 Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a...Show more |
2Fedoraproject Neutrinolabs2Fedora XrdpJun 17, 2026 Feb 7, 2022 N/Aยท v4 7.8 HIGHยท v3 7.2 HIGHยท v2 xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a...Show more |
3Debian FedoraprojectTwisted3Debian Linux FedoraTwistedJun 17, 2026 Feb 7, 2022 N/Aยท v4 7.5 HIGHยท v3 5.0 MEDIUMยท v2 twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.Redir...Show more |
2Fedoraproject Ruby Lang2Cgi FedoraJun 17, 2026 Feb 6, 2022 N/Aยท v4 9.8 CRITICALยท v3 7.5 HIGHยท v2 CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This...Show more |
3Debian FedoraprojectKicad3Debian Linux FedoraKicad EdaJun 17, 2026 Feb 4, 2022 N/Aยท v4 7.8 HIGHยท v3 6.8 MEDIUMยท v2 A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file c...Show more |
3Debian FedoraprojectKicad3Debian Linux FedoraKicad EdaJun 17, 2026 Feb 4, 2022 N/Aยท v4 7.8 HIGHยท v3 6.8 MEDIUMยท v2 A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file c...Show more |
3Debian FedoraprojectSymfony3Debian Linux FedoraTwigJun 17, 2026 Feb 4, 2022 N/Aยท v4 9.8 CRITICALยท v3 7.5 HIGHยท v2 Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions th...Show more |
3Debian FedoraprojectGerbv Project3Debian Linux FedoraGerbvJun 17, 2026 Feb 4, 2022 N/Aยท v4 6.3 MEDIUMยท v3 4.3 MEDIUMยท v2 An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit th...Show more |
3Debian FedoraprojectGerbv Project3Debian Linux FedoraGerbvJun 17, 2026 Feb 4, 2022 N/Aยท v4 8.6 HIGHยท v3 6.8 MEDIUMยท v2 A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execut...Show more |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Feb 3, 2022 N/Aยท v4 7.5 HIGHยท v3 5.0 MEDIUMยท v2 An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files. |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Feb 3, 2022 N/Aยท v4 6.1 MEDIUMยท v3 4.3 MEDIUMยท v2 The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Feb 2, 2022 N/Aยท v4 7.8 HIGHยท v3 6.8 MEDIUMยท v2 Use After Free in GitHub repository vim/vim prior to 8.2. |
4Debian FedoraprojectPostgresql+1 more4Debian Linux FedoraPostgresql Jdbc Driver+1 moreJun 17, 2026 Feb 2, 2022 N/Aยท v4 9.8 CRITICALยท v3 7.5 HIGHยท v2 pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker con...Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Feb 1, 2022 N/Aยท v4 7.8 HIGHยท v3 6.8 MEDIUMยท v2 Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. |
5Debian FedoraprojectJenkins+2 more11Commerce Guided Search Communications Brm Elastic Charging EngineCommunications Cloud Native Core Automated Test Suite+8 moreJun 17, 2026 Feb 1, 2022 N/Aยท v4 7.5 HIGHยท v3 5.0 MEDIUMยท v2 XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel exe...Show more |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 1, 2022 N/Aยท v4 5.5 MEDIUMยท v3 4.3 MEDIUMยท v2 NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0. |
3Debian FedoraprojectMariadb3Debian Linux FedoraMariadbJun 17, 2026 Feb 1, 2022 N/Aยท v4 7.5 HIGHยท v3 5.0 MEDIUMยท v2 MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used. |
2Fedoraproject Mariadb2Fedora MariadbJun 17, 2026 Feb 1, 2022 N/Aยท v4 5.5 MEDIUMยท v3 2.1 LOWยท v2 MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures. |
2Fedoraproject Mariadb2Fedora MariadbJun 17, 2026 Feb 1, 2022 N/Aยท v4 5.5 MEDIUMยท v3 2.1 LOWยท v2 MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash. |