CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectLinux+1 more14Active Iq Unified Manager Cloud BackupDebian Linux+11 moreJun 17, 2026 May 25, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A memory leak vulnerability was found in Linux kernel in llcp_sock_connect |
5Bluetooth DebianFedoraproject+2 more19Ac 1550 Firmware Ac 3165 FirmwareAc 3168 Firmware+16 moreJun 17, 2026 May 24, 2021 N/A· v4 4.2 MEDIUM· v3 4.3 MEDIUM· v2 Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure)...Show more |
3Bluetooth FedoraprojectIntel17Ac 3165 Firmware Ac 3168 FirmwareAc 7265 Firmware+14 moreJun 17, 2026 May 24, 2021 N/A· v4 5.4 MEDIUM· v3 4.8 MEDIUM· v2 Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B through 5.2 may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the P...Show more |
6Debian Eterm ProjectFedoraproject+3 more6Debian Linux EtermFedora+3 moreJun 17, 2026 May 20, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline. |
2Fedoraproject Slapi Nis Project2Fedora Slapi NisJun 17, 2026 May 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest thre...Show more |
6Debian FedoraprojectNetapp+3 more10Cloud Backup Communications Cloud Native Core Binding Support FunctionDebian Linux+7 moreJun 17, 2026 May 20, 2021 N/A· v4 5.7 MEDIUM· v3 2.7 LOW· v2 There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive inform...Show more |
3Fedoraproject OpenidcOracle3Essbase FedoraMod Auth OpenidcJun 17, 2026 May 20, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors. |
6Debian FedoraprojectNetapp+3 more28Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+25 moreJun 17, 2026 May 19, 2021 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 There is a flaw in the xml entity encoding functionality of libxml2 in versions before 2.9.11. An attacker who is able to supply a crafted file to be processed by an application linked with the affected functionality of...Show more |
3Fedoraproject RedhatRpm3Enterprise Linux FedoraLibdnfJun 17, 2026 May 19, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then tric...Show more |
3Fedoraproject RedhatRpm3Enterprise Linux FedoraRpmJun 17, 2026 May 19, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the RPM package in the read functionality. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package or compromise an RPM repository, to cause RPM database corru...Show more |
Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee. |
2Fedoraproject Redhat3Ceph Ceph StorageFedoraJun 17, 2026 May 18, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A flaw was found in the Red Hat Ceph Storage RGW in versions before 14.2.21. When processing a GET Request for a swift URL that ends with two slashes it can cause the rgw to crash, resulting in a denial of service. The g...Show more |
6Debian FedoraprojectNetapp+3 more18Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+15 moreJun 17, 2026 May 18, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this fl...Show more |
2Exiv2 Fedoraproject2Exiv2 FedoraJun 17, 2026 May 17, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier....Show more |
3Debian FedoraprojectRedhat4Ceph Ceph StorageDebian Linux+1 moreJun 17, 2026 May 17, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in t...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 May 14, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value. |
2Fedoraproject Virustotal2Fedora YaraJun 17, 2026 May 14, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or information disclosure via a malicious Mach-O...Show more |
A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect. |
6Debian FedoraprojectNetapp+3 more19Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+16 moreJun 17, 2026 May 14, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and...Show more |
3Fedoraproject ImagemagickRedhat3Enterprise Linux Desktop FedoraImagemagickJun 17, 2026 May 14, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c. |