CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Qpdf Project2Fedora QpdfJun 17, 2026 Feb 29, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h. |
An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function. |
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_r...Show more |
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectYardoc3Debian Linux FedoraYardJun 17, 2026 Feb 28, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScri...Show more |
libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp. |
2Fedoraproject Reproducible Builds2Diffoscope FedoraJun 17, 2026 Feb 27, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embed...Show more |
3Debian FedoraprojectFontforge3Debian Linux FedoraFontforgeJun 17, 2026 Feb 26, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files. |
3Debian FedoraprojectFontforge3Debian Linux FedoraFontforgeJun 17, 2026 Feb 26, 2024 N/A· v4 4.2 MEDIUM· v3 N/A· v2 Splinefont in FontForge through 20230101 allows command injection via crafted filenames. |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerabi...Show more |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the htt...Show more |
LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed in 0.5.46. |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft traffic to cause Suricata to use far more CP...Show more |
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes....Show more |
2Fedoraproject Nlnetlabs2Fedora RoutinatorJun 17, 2026 Feb 26, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening. |
2Apostrophecms Fedoraproject2Fedora Sanitize HtmlJun 17, 2026 Feb 24, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dep...Show more |
2Fedoraproject Linuxfoundation2Fedora OnnxJun 17, 2026 Feb 23, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy. |
2Fedoraproject Linuxfoundation2Fedora OnnxJun 17, 2026 Feb 23, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is outside the model current directory or us...Show more |
c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version...Show more |