← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectNetapp+1 more
5Debian Linux
FedoraHci Management Node+2 more
Jun 17, 2026
Jul 20, 2021
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an o...Show more
basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.Show less
6Debian
FedoraprojectLinux+3 more
7Communications Session Border Controller
Debian LinuxFedora+4 more
Jun 17, 2026
Jul 20, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged use...Show more
fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05.Show less
3Debian
FedoraprojectLibsndfile Project
3Debian Linux
FedoraLibsndfile
Jun 17, 2026
Jul 20, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A heap buffer overflow vulnerability in msadpcm_decode_block of libsndfile 1.0.30 allows attackers to execute arbitrary code via a crafted WAV file.
2Fedoraproject
Unicorn Engine
2Fedora
Unicorn Engine
Jun 17, 2026
Jul 20, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb).
4Apple
FedoraprojectLibarchive+1 more
7Fedora
IpadosIphone Os+4 more
Jun 17, 2026
Jul 20, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
libarchive 3.4.1 through 3.5.1 has a use-after-free in copy_string (called from do_uncompress_block and process_block).
2Fedoraproject
Libass Project
2Fedora
Libass
Jun 17, 2026
Jul 20, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
3Debian
FedoraprojectGnu
3Aspell
Debian LinuxFedora
Jun 17, 2026
Jul 20, 2021
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
2Fedoraproject
Linuxfoundation
2Containerd
Fedora
Jun 17, 2026
Jul 19, 2021
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing...Show more
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to others, or set extended bits like setuid, setgid, and sticky. This bug does not directly allow files to be read, modified, or executed without an additional cooperating process. This bug has been fixed in containerd 1.5.4 and 1.4.8. As a workaround, ensure that users only pull images from trusted sources. Linux security modules (LSMs) like SELinux and AppArmor can limit the files potentially affected by this bug through policies and profiles that prevent containerd from interacting with specific files.Show less
2Fail2ban
Fedoraproject
2Fail2ban
Fedora
Jun 17, 2026
Jul 16, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code exec...Show more
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action mail-whois. Command `mail` from mailutils package used in mail actions like `mail-whois` can execute command if unescaped sequences (`\n~`) are available in "foreign" input (for instance in whois output). To exploit the vulnerability, an attacker would need to insert malicious characters into the response sent by the whois server, either via a MITM attack or by taking over a whois server. The issue is patched in versions 0.10.7 and 0.11.3. As a workaround, one may avoid the usage of action `mail-whois` or patch the vulnerability manually.Show less
4Fedoraproject
GolangNetapp+1 more
6Cloud Insights Telegraf
FedoraGo+3 more
Jun 17, 2026
Jul 15, 2021
N/A· v4
6.5 MEDIUM· v3
2.6 LOW· v2
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to c...Show more
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.Show less
5Debian
FedoraprojectVarnish Cache+2 more
5Debian Linux
FedoraVarnish Cache+2 more
Jun 17, 2026
Jul 14, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x...Show more
Varnish Cache, with HTTP/2 enabled, allows request smuggling and VCL authorization bypass via a large Content-Length header for a POST request. This affects Varnish Enterprise 6.0.x before 6.0.8r3, and Varnish Cache 5.x and 6.x before 6.5.2, 6.6.x before 6.6.1, and 6.0 LTS before 6.0.8.Show less
3Arm
DebianFedoraproject
3Debian Linux
FedoraMbed Tls
Jun 17, 2026
Jul 14, 2021
N/A· v4
4.9 MEDIUM· v3
4.0 MEDIUM· v2
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-ch...Show more
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.Show less
3Debian
FedoraprojectPython
3Debian Linux
FedoraPillow
Jun 17, 2026
Jul 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enume...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share tokens or credentials. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.Show less
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumer...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.Show less
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
8.8 HIGH· v3
7.5 HIGH· v2
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e....Show more
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the user to not have any filesystem access. Due to a lacking permission check, the tokens were able to change their own permissions in versions prior to 19.0.13, 20.0.11, and 21.0.3. Thus fileystem limited tokens were able to grant themselves access to the filesystem. The issue is patched in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds aside from upgrading.Show less
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a sha...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13, 20.0.11, and 21.0.3.Show less
2Fedoraproject
Fossil Scm
2Fedora
Fossil
Jun 17, 2026
Jul 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied f...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized into a `DownloadResponse`, this could be used to trick users into downloading malicious files with a benign file extension. This would show in UI behaviours where Nextcloud applications would display a benign file extension (e.g. JPEG), but the file will actually be downloaded with an executable file extension. The vulnerability is patched in versions 19.0.13, 20.0.11, and 21.0.3. Administrators of Nextcloud instances do not have a workaround available, but developers of Nextcloud apps may manually escape the file name before passing it into `DownloadResponse`.Show less
2Fedoraproject
Nextcloud
2Fedora
Nextcloud Server
Jun 17, 2026
Jul 12, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`)...Show more
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`) using the `@BruteForceProtection` annotation. Risk depends on the installed applications on the Nextcloud Server, but could range from bypassing authentication ratelimits or spamming other Nextcloud users. The vulnerability is patched in versions 19.0.13, 20.0.11, and 21.0.3. No workarounds aside from upgrading are known to exist.Show less