CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FedoraprojectLinux+3 more17Cloud Backup Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+14 moreJun 17, 2026 Jul 9, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An out-of-bounds memory write flaw was found in the Linux kernel's joystick devices subsystem in versions before 5.9-rc1, in the way the user calls ioctl JSIOCSBTNMAP. This flaw allows a local user to crash the system or...Show more |
3Fedoraproject Linuxptp ProjectRedhat3Enterprise Linux FedoraLinuxptpJun 17, 2026 Jul 9, 2021 N/A· v4 7.1 HIGH· v3 5.5 MEDIUM· v2 A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an...Show more |
4Debian FedoraprojectLinuxptp Project+1 more7Debian Linux Enterprise LinuxEnterprise Linux Aus+4 moreJun 17, 2026 Jul 9, 2021 N/A· v4 8.8 HIGH· v3 8.0 HIGH· v2 A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code e...Show more |
3Debian FedoraprojectWebkitgtk3Debian Linux FedoraWebkitgtkJun 17, 2026 Jul 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A use-after-free vulnerability exists in the way Webkit’s GraphicsContext handles certain events in WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. A...Show more |
3Debian FedoraprojectWebkitgtk3Debian Linux FedoraWebkitgtkJun 17, 2026 Jul 7, 2021 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory c...Show more |
2Addressable Project Fedoraproject2Addressable FedoraJun 17, 2026 Jul 6, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jul 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jul 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jul 2, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Jul 2, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages th...Show more |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 Jul 2, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Django 3.1.x before 3.1.13 and 3.2.x before 3.2.5 allows QuerySet.order_by SQL injection if order_by is untrusted input from a client of a web application. |
2Fedoraproject Selinux Project2Fedora SelinuxJun 17, 2026 Jul 1, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack of checks for invalid statements in an o...Show more |
4Debian FedoraprojectNetapp+1 more8Active Iq Unified Manager Bootstrap OsDebian Linux+5 moreJun 17, 2026 Jul 1, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The CIL compiler in SELinux 3.2 has a use-after-free in cil_reset_classpermission (called from cil_reset_classperms_set and cil_reset_classperms_list). |
2Fedoraproject Selinux Project2Fedora SelinuxJun 17, 2026 Jul 1, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map). |
2Fedoraproject Selinux Project2Fedora SelinuxJun 17, 2026 Jul 1, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper). |
3Debian Djvulibre ProjectFedoraproject3Debian Linux DjvulibreFedoraJun 17, 2026 Jun 30, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to...Show more |
3Fedoraproject OraclePython5Enterprise Manager Ops Center FedoraInstantis Enterprisetrack+2 moreJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of...Show more |
3Debian DovecotFedoraproject3Debian Linux DovecotFedoraJun 17, 2026 Jun 28, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address. |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Jun 28, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension. |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Jun 28, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during...Show more |