CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectNetapp+1 more5Debian Linux FedoraHci Management Node+2 moreJun 17, 2026 Jul 20, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an o...Show more |
6Debian FedoraprojectLinux+3 more7Communications Session Border Controller Debian LinuxFedora+4 moreJun 17, 2026 Jul 20, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged use...Show more |
3Debian FedoraprojectLibsndfile Project3Debian Linux FedoraLibsndfileJun 17, 2026 Jul 20, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file. |
2Fedoraproject Unicorn Engine2Fedora Unicorn EngineJun 17, 2026 Jul 20, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb). |
4Apple FedoraprojectLibarchive+1 more7Fedora IpadosIphone Os+4 moreJun 17, 2026 Jul 20, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block). |
2Fedoraproject Libass Project2Fedora LibassJun 17, 2026 Jul 20, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction. |
3Debian FedoraprojectGnu3Aspell Debian LinuxFedoraJun 17, 2026 Jul 20, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list). |
2Fedoraproject Linuxfoundation2Containerd FedoraJun 17, 2026 Jul 19, 2021 N/A· v4 6.3 MEDIUM· v3 6.8 MEDIUM· v2 containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing...Show more |
2Fail2ban Fedoraproject2Fail2ban FedoraJun 17, 2026 Jul 16, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code exec...Show more |
4Fedoraproject GolangNetapp+1 more6Cloud Insights Telegraf FedoraGo+3 moreJun 17, 2026 Jul 15, 2021 N/A· v4 6.5 MEDIUM· v3 2.6 LOW· v2 The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to c...Show more |
5Debian FedoraprojectVarnish Cache+2 more5Debian Linux FedoraVarnish Cache+2 moreJun 17, 2026 Jul 14, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x...Show more |
3Arm DebianFedoraproject3Debian Linux FedoraMbed TlsJun 17, 2026 Jul 14, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-ch...Show more |
3Debian FedoraprojectPython3Debian Linux FedoraPillowJun 17, 2026 Jul 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enume...Show more |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumer...Show more |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 8.8 HIGH· v3 7.5 HIGH· v2 Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e....Show more |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a sha...Show more |
2Fedoraproject Fossil Scm2Fedora FossilJun 17, 2026 Jul 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied f...Show more |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Jul 12, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`)...Show more |