← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Fedoraproject
Http Proxy Agent ProjectRedhat
4Enterprise Linux
FedoraHttp Proxy Agent+1 more
Jun 17, 2026
Mar 19, 2021
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service throu...Show more
A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.Show less
3Apache
FedoraprojectOracle
19Banking Corporate Lending Process Management
Banking Credit Facilities Process ManagementBanking Supply Chain Finance+16 more
Jun 17, 2026
Mar 19, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
3Apache
FedoraprojectOracle
15Banking Trade Finance Process Management
Banking Treasury ManagementBanking Virtual Account Management+12 more
Jun 17, 2026
Mar 19, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
3Debian
FedoraprojectKramdown Project
3Debian Linux
FedoraKramdown
Jun 17, 2026
Mar 19, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
3Busybox
DebianFedoraproject
3Busybox
Debian LinuxFedora
Jun 17, 2026
Mar 19, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.
2Fedoraproject
Torproject
2Fedora
Tor
Jun 17, 2026
Mar 19, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
2Fedoraproject
Torproject
2Fedora
Tor
Jun 17, 2026
Mar 19, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
4Debian
FedoraprojectNetapp+1 more
4Cloud Manager
Debian LinuxFedora+1 more
Jun 17, 2026
Mar 19, 2021
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security...Show more
An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.Show less
4Debian
FedoraprojectQemu+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jun 17, 2026
Mar 18, 2021
N/A· v4
6.0 MEDIUM· v3
2.1 LOW· v2
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A...Show more
A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A guest user/process may use this flaw to consume CPU cycles or crash the QEMU process on the host resulting in DoS scenario.Show less
2Fedoraproject
Mediaarea
2Fedora
Mediainfo
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.
5Fedoraproject
Lldpd ProjectOpenvswitch+2 more
17Enterprise Linux
FedoraLldpd+14 more
Jun 17, 2026
Mar 18, 2021
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest...Show more
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.Show less
4Debian
FedoraprojectLinux+1 more
12Cloud Backup
Debian LinuxFedora+9 more
Jun 17, 2026
Mar 17, 2021
N/A· v4
8.8 HIGH· v3
8.3 HIGH· v2
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not...Show more
rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have situations in which a drivers/staging issue is relevant to their own customer base.Show less
3Debian
FedoraprojectPygments
3Debian Linux
FedoraPygments
Jun 17, 2026
Mar 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to...Show more
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a denial of service.Show less
2Fedoraproject
Gnome
2Fedora
Gnome Autoar
Jun 17, 2026
Mar 17, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink i...Show more
autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink in certain complex situations. NOTE: this issue exists because of an incomplete fix for CVE-2020-36241.Show less
2Fedoraproject
Varnish Cache
3Fedora
Varnish ModulesVarnish Modules Klarlack
Jun 17, 2026
Mar 16, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however,...Show more
Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure or NULL pointer dereference can be triggered in Varnish Cache through the varnish-modules header.append() and header.copy() functions. For some Varnish Configuration Language (VCL) files, this gives remote clients an opportunity to cause a Varnish Cache restart. A restart reduces overall availability and performance due to an increased number of cache misses, and may cause higher load on backend servers.Show less
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Jun 17, 2026
Mar 16, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Jun 17, 2026
Mar 16, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
3Debian
FedoraprojectGoogle
3Chrome
Debian LinuxFedora
Jun 17, 2026
Mar 16, 2021
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Mar 15, 2021
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The web service responsible for fetching other users' enrolled courses did not validate that the requesting user had permission to view that information in each course in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Mar 15, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.