CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Fedoraproject Filezilla ProjectPutty+3 more6Fedora Filezilla ClientPutty+3 moreJun 17, 2026 Apr 15, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scen...Show more |
2Fedoraproject Pydantic2Fedora PydanticJun 17, 2026 Apr 15, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string. |
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component. |
4Dnspython EventletFedoraproject+1 more4Bootstrap Os DnspythonEventlet+1 moreJun 17, 2026 Apr 11, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" a...Show more |
Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Apr 10, 2024 N/A· v4 9.6 CRITICAL· v3 N/A· v2 Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromiu...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Apr 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected. Users can set a new setting (proxy.config...Show more |
2Fedoraproject Ofono Project2Fedora OfonoJun 17, 2026 Apr 10, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the attack scenario is accessible from a co...Show more |
2Fedoraproject Rust Lang2Fedora RustJun 17, 2026 Apr 9, 2024 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Rust is a programming language. The Rust Security Response WG was notified that the Rust standard library prior to version 1.77.2 did not properly escape arguments when invoking batch files (with the `bat` and `cmd` exte...Show more |
3Fedoraproject LibarchiveMicrosoft5Fedora LibarchiveWindows 11 22h2+2 moreJun 17, 2026 Apr 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Libarchive Remote Code Execution Vulnerability |
3Apache FedoraprojectNetapp3Fedora Http ServerOntapJun 17, 2026 Apr 4, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 HTTP/2 incoming headers exceeding the limit are temporarily buffered in nghttp2 in order to generate an informative HTTP 413 response. If a client does not stop sending headers, this leads to memory exhaustion. |
6Apache AppleBroadcom+3 more7Debian Linux Fabric Operating SystemFedora+4 moreJun 17, 2026 Apr 4, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 HTTP Response splitting in multiple modules in Apache HTTP Server allows an attacker that can inject malicious response headers into backend applications to cause an HTTP desynchronization attack. Users are recommended...Show more |
6Apache AppleBroadcom+3 more7Debian Linux Fabric Operating SystemFedora+4 moreJun 17, 2026 Apr 4, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58. |
Undici is an HTTP/1.1 client, written from scratch for Node.js. Undici cleared Authorization and Proxy-Authorization headers for `fetch()`, but did not clear them for `undici.request()`. This vulnerability was patched in...Show more |
2Fedoraproject Pgadmin2Fedora Pgadmin 4Jun 17, 2026 Apr 4, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a sever...Show more |
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulne...Show more |
3Debian FedoraprojectNghttp23Debian Linux FedoraNghttp2Jun 17, 2026 Apr 4, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. The nghttp2 library prior to version 1.61.0 keeps reading the unbounded number of HTTP/2 CONTINUATION frames even after a stream is reset to...Show more |
2Fedoraproject Upx2Fedora UpxJun 17, 2026 Apr 2, 2024 N/A· v4 9.8 CRITICAL· v3 5.2 MEDIUM· v2 A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclos...Show more |
3Arm FedoraprojectTrustedfirmware4Fedora Mbed CryptoMbed Tls+1 moreJun 17, 2026 Mar 29, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory. |