← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Debian
FedoraprojectOpensuse+3 more
9Date
Debian LinuxEnterprise Linux+6 more
Jun 17, 2026
Jan 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
4Debian
FedoraprojectOracle+1 more
4Debian Linux
FedoraGdal+1 more
Jun 17, 2026
Jan 1, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
3Debian
FedoraprojectOpenexr
3Debian Linux
FedoraOpenexr
Jun 17, 2026
Jan 1, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2...Show more
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.Show less
2Fedoraproject
Harfbuzz Project
2Fedora
Harfbuzz
Jun 17, 2026
Jan 1, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).
3Debian
FedoraprojectQt
3Debian Linux
FedoraQtsvg
Jun 17, 2026
Jan 1, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).
3Debian
FedoraprojectUltrajson Project
3Debian Linux
FedoraUltrajson
Jun 17, 2026
Jan 1, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
4Apple
DebianFedoraproject+1 more
5Debian Linux
FedoraMac Os X+2 more
Jun 17, 2026
Dec 31, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
vim is vulnerable to Out-of-bounds Read
4Apple
DebianFedoraproject+1 more
5Debian Linux
FedoraMac Os X+2 more
Jun 17, 2026
Dec 31, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
vim is vulnerable to Use After Free
2Fedoraproject
Wireshark
2Fedora
Wireshark
Jun 17, 2026
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
2Fedoraproject
Wireshark
2Fedora
Wireshark
Jun 17, 2026
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
4Debian
FedoraprojectOracle+1 more
5Debian Linux
FedoraHttp Server+2 more
Jun 17, 2026
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
4Debian
FedoraprojectOracle+1 more
5Debian Linux
FedoraHttp Server+2 more
Jun 17, 2026
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
3Fedoraproject
OracleWireshark
4Fedora
Http ServerWireshark+1 more
Jun 17, 2026
Dec 30, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
3Fedoraproject
OracleWireshark
4Fedora
Http ServerWireshark+1 more
Jun 17, 2026
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
4Debian
FedoraprojectOracle+1 more
5Debian Linux
FedoraHttp Server+2 more
Jun 17, 2026
Dec 30, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
3Apple
FedoraprojectVim
4Fedora
Mac Os XMacos+1 more
Jun 17, 2026
Dec 29, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
vim is vulnerable to Use After Free
2Celeryproject
Fedoraproject
3Celery
Extra Packages For Enterprise LinuxFedora
Jun 17, 2026
Dec 29, 2021
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attack...Show more
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulnerability and potentially gain further access to the system.Show less
5Apache
CiscoDebian+2 more
22Cloudcenter
Communications Brm Elastic Charging EngineCommunications Diameter Signaling Router+19 more
Jun 17, 2026
Dec 28, 2021
N/A· v4
6.6 MEDIUM· v3
8.5 HIGH· v2
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data so...Show more
Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data source URI when an attacker has control of the target LDAP server. This issue is fixed by limiting JNDI data source names to the java protocol in Log4j2 versions 2.17.1, 2.12.4, and 2.3.2.Show less
3Apple
FedoraprojectVim
4Fedora
Mac Os XMacos+1 more
Jun 17, 2026
Dec 27, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
vim is vulnerable to Use After Free
7Apple
DebianFedoraproject+4 more
8Debian Linux
Enterprise LinuxFactory+5 more
Jun 17, 2026
Dec 25, 2021
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
vim is vulnerable to Out-of-bounds Read