CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Busybox Fedoraproject2Busybox FedoraJun 17, 2026 Nov 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function |
2Busybox Fedoraproject2Busybox FedoraJun 17, 2026 Nov 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function |
2Busybox Fedoraproject2Busybox FedoraJun 17, 2026 Nov 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function |
2Busybox Fedoraproject2Busybox FedoraJun 17, 2026 Nov 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function |
2Busybox Fedoraproject2Busybox FedoraJun 17, 2026 Nov 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function |
2Busybox Fedoraproject2Busybox FedoraJun 17, 2026 Nov 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function |
2Busybox Fedoraproject2Busybox FedoraJun 17, 2026 Nov 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function |
2Busybox Fedoraproject2Busybox FedoraJun 17, 2026 Nov 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used f...Show more |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare...Show more |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be u...Show more |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 5.3 MEDIUM· v3 3.3 LOW· v2 An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that |
3Busybox FedoraprojectNetapp12Busybox Cloud BackupFedora+9 moreJun 17, 2026 Nov 15, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given |
3Fedoraproject NetappNpmjs3Fedora Next Generation Application Programming InterfaceNpmJun 17, 2026 Nov 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and m...Show more |
2Fedoraproject Xiph2Fedora SpeexJun 17, 2026 Nov 10, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. |
Stack overflow in lua_resume of ldo.c in Lua Interpreter 5.1.0~5.4.4 allows attackers to perform a Denial of Service via a crafted script file. |
3Fedoraproject GolangOracle3Fedora GoTimesten In Memory DatabaseJun 17, 2026 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field. |
3Debian FedoraprojectGolang3Debian Linux FedoraGoJun 17, 2026 Nov 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation. |
2Barrier Project Fedoraproject2Barrier FedoraJun 17, 2026 Nov 8, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Nov 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname. |