← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used f...Show more
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.Show less
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare...Show more
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.Show less
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be u...Show more
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.Show less
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.3 MEDIUM· v3
3.3 LOW· v2
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
3Fedoraproject
NetappNpmjs
3Fedora
Next Generation Application Programming InterfaceNpm
Jun 17, 2026
Nov 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and m...Show more
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.Show less
2Fedoraproject
Xiph
2Fedora
Speex
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.
2Fedoraproject
Lua
2Fedora
Lua
Jun 17, 2026
Nov 9, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file.
3Fedoraproject
GolangOracle
3Fedora
GoTimesten In Memory Database
Jun 17, 2026
Nov 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.
3Debian
FedoraprojectGolang
3Debian Linux
FedoraGo
Jun 17, 2026
Nov 8, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
2Barrier Project
Fedoraproject
2Barrier
Fedora
Jun 17, 2026
Nov 8, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses...Show more
An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses in the provided protocol to cause denial-of-service or stage further attacks that could lead to information leaks or integrity corruption.Show less
3Debian
FedoraprojectOwasp
3Debian Linux
FedoraOwasp Modsecurity Core Rule Set
Jun 17, 2026
Nov 5, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.