← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Apple
FedoraprojectHaxx+1 more
14Active Iq Unified Manager
Bootstrap OsBrocade Fabric Operating System+11 more
Jun 17, 2026
Mar 27, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl i...Show more
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all the previously allocated headers and instead leaks the memory. Further, this error condition fails silently and is therefore not easily detected by an application.Show less
4Apple
FedoraprojectHaxx+1 more
10Bootstrap Os
CurlFedora+7 more
Jun 17, 2026
Mar 27, 2024
N/A· v4
3.5 LOW· v3
N/A· v2
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below comman...Show more
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.se The flaw is only present if the set of selected protocols disables the entire set of available protocols, in itself a command with no practical use and therefore unlikely to be encountered in real situations. The curl security team has thus assessed this to be low severity bug.Show less
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 26, 2024
N/A· v4
7.7 HIGH· v3
N/A· v2
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 26, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 26, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 26, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
2Fedoraproject
Wireshark
2Fedora
Wireshark
Jun 17, 2026
Mar 26, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file
2Apache
Fedoraproject
2Commons Configuration
Fedora
Jun 17, 2026
Mar 21, 2024
N/A· v4
5.4 MEDIUM· v3
N/A· v2
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.
3Apache
FedoraprojectNetapp
4Commons Configuration
FedoraOntap Tools+1 more
Jun 17, 2026
Mar 21, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1. Users are recommended to upgrade to version 2.10.1, which fixes the issue.
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 20, 2024
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
2Fedoraproject
Google
2Chrome
Fedora
Jun 17, 2026
Mar 20, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Object lifecycle issue in V8 in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
2Fedoraproject
Latchset
2Fedora
Jose
Jun 17, 2026
Mar 20, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
2Fedoraproject
Xen
2Fedora
Xen
Jun 17, 2026
Mar 20, 2024
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a hardware feature designed to protect against Return Oriented Programming...Show more
Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a hardware feature designed to protect against Return Oriented Programming attacks. When enabled, traditional stacks holding both data and return addresses are accompanied by so called "shadow stacks", holding little more than return addresses. Shadow stacks aren't writable by normal instructions, and upon function returns their contents are used to check for possible manipulation of a return address coming from the traditional stack. In particular certain memory accesses need intercepting by Xen. In various cases the necessary emulation involves kind of replaying of the instruction. Such replaying typically involves filling and then invoking of a stub. Such a replayed instruction may raise an exceptions, which is expected and dealt with accordingly. Unfortunately the interaction of both of the above wasn't right: Recovery involves removal of a call frame from the (traditional) stack. The counterpart of this operation for the shadow stack was missing.Show less
2Fedoraproject
Xen
2Fedora
Xen
Jun 17, 2026
Mar 20, 2024
N/A· v4
4.1 MEDIUM· v3
N/A· v2
Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate as intended when support for HVM guests is compiled out of Xen.
2Fedoraproject
Xen
2Fedora
Xen
Jun 17, 2026
Mar 20, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of functions that are otherwise unpopulated. This allows a device to extend th...Show more
PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of functions that are otherwise unpopulated. This allows a device to extend the number of outstanding requests. Such phantom functions need an IOMMU context setup, but failure to setup the context is not fatal when the device is assigned. Not failing device assignment when such failure happens can lead to the primary device being assigned to a guest, while some of the phantom functions are assigned to a different domain. Show less