← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Mar 15, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Mar 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Text-based feedback answers required additional sanitizing to prevent stored XSS and blind SSRF risks in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Mar 15, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
3Fedoraproject
OraclePython
3Fedora
Peoplesoft Enterprise PeopletoolsUrllib3
Jun 17, 2026
Mar 15, 2021
N/A· v4
6.5 MEDIUM· v3
6.4 MEDIUM· v2
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_confi...Show more
The urllib3 library 1.26.x before 1.26.4 for Python omits SSL certificate validation in some cases involving HTTPS to HTTPS proxies. The initial connection to the HTTPS proxy (if an SSLContext isn't given via proxy_config) doesn't verify the hostname of the certificate. This means certificates for different servers that still validate properly with the default urllib3 SSLContext will be silently accepted.Show less
3Dogtagpki
FedoraprojectRedhat
4Certificate System
DogtagpkiEnterprise Linux+1 more
Jun 17, 2026
Mar 15, 2021
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat...Show more
A flaw was found in pki-core. An attacker who has successfully compromised a key could use this flaw to renew the corresponding certificate over and over again, as long as it is not explicitly revoked. The highest threat from this vulnerability is to data confidentiality and integrity.Show less
3Fedoraproject
LinuxNetapp
4Cloud Backup
FedoraLinux Kernel+1 more
Jun 17, 2026
Mar 15, 2021
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related i...Show more
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.Show less
3Fedoraproject
GnuRedhat
3Enterprise Linux
FedoraGnutls
Jun 17, 2026
Mar 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
4Fedoraproject
GnuNetapp+1 more
5Active Iq Unified Manager
E Series Performance AnalyzerEnterprise Linux+2 more
Jun 17, 2026
Mar 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
2Elementary
Fedoraproject
2Fedora
Switchboard Bluetooth Plug
Jun 17, 2026
Mar 12, 2021
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service...Show more
Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted, allowing physically proximate attackers to pair with a device running an affected version of switchboard-plug-bluetooth without the active consent of the user. By default, elementary OS doesn't expose any services via Bluetooth that allow information to be extracted by paired Bluetooth devices. However, if such services (i.e. contact list sharing software) have been installed, it's possible that attackers have been able to extract data from such services without authorization. If no such services have been installed, attackers are only able to pair with a device running an affected version without authorization and then play audio out of the device or possibly present a HID device (keyboard, mouse, etc...) to control the device. As such, users should check the list of trusted/paired devices and remove any that are not 100% confirmed to be genuine. This is fixed in version 2.3.5. To reduce the likelihood of this vulnerability on an unpatched version, only open the Bluetooth plug for short intervals when absolutely necessary and preferably not in crowded public areas. To mitigate the risk entirely with unpatched versions, do not open the Bluetooth plug within switchboard at all, and use a different method for pairing devices if necessary (e.g. `bluetoothctl` CLI).Show less
3Debian
FedoraprojectLeptonica
3Debian Linux
FedoraLeptonica
Jun 17, 2026
Mar 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixFewColorsOctcubeQuantMixed in colorquant1.c.
2Fedoraproject
Leptonica
2Fedora
Leptonica
Jun 17, 2026
Mar 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
3Debian
FedoraprojectLeptonica
3Debian Linux
FedoraLeptonica
Jun 17, 2026
Mar 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
3Debian
FedoraprojectLeptonica
3Debian Linux
FedoraLeptonica
Jun 17, 2026
Mar 12, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Leptonica before 1.80.0 allows a heap-based buffer over-read in findNextBorderPixel in ccbord.c.
4Broadcom
DebianFedoraproject+1 more
4Brocade Fabric Operating System Firmware
Debian LinuxFedora+1 more
Jun 17, 2026
Mar 11, 2021
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlin...Show more
An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink to a file that already exists, then the contents of that file correctly remain unchanged.)Show less
3Debian
FedoraprojectLeptonica
3Debian Linux
FedoraLeptonica
Jun 17, 2026
Mar 11, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
3Debian
FedoraprojectFlatpak
3Debian Linux
FedoraFlatpak
Jun 17, 2026
Mar 11, 2021
N/A· v4
8.2 HIGH· v3
5.8 MEDIUM· v2
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which ca...Show more
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to gain access to files that would not ordinarily be allowed by the app's permissions. By putting the special tokens `@@` and/or `@@u` in the Exec field of a Flatpak app's .desktop file, a malicious app publisher can trick flatpak into behaving as though the user had chosen to open a target file with their Flatpak app, which automatically makes that file available to the Flatpak app. This is fixed in version 1.10.2. A minimal solution is the first commit "`Disallow @@ and @@U usage in desktop files`". The follow-up commits "`dir: Reserve the whole @@ prefix`" and "`dir: Refuse to export .desktop files with suspicious uses of @@ tokens`" are recommended, but not strictly required. As a workaround, avoid installing Flatpak apps from untrusted sources, or check the contents of the exported `.desktop` files in `exports/share/applications/*.desktop` (typically `~/.local/share/flatpak/exports/share/applications/*.desktop` and `/var/lib/flatpak/exports/share/applications/*.desktop`) to make sure that literal filenames do not follow `@@` or `@@u`.Show less
2Fedoraproject
Golang
2Fedora
Go
Jun 17, 2026
Mar 11, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.
2Fedoraproject
Linuxfoundation
2Containerd
Fedora
Jun 17, 2026
Mar 10, 2021
N/A· v4
6.3 MEDIUM· v3
4.3 MEDIUM· v2
In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that use...Show more
In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that uses the containerd CRI service) that share the same image may receive incorrect environment variables, including values that are defined for other containers. If the affected containers have different security contexts, this may allow sensitive information to be unintentionally shared. If you are not using containerd's CRI implementation (through one of the mechanisms described above), you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image which have different environment variables, you are not vulnerable to this issue. If you are not launching multiple containers or Kubernetes pods from the same image in rapid succession, you have reduced likelihood of being vulnerable to this issue This vulnerability has been fixed in containerd 1.3.10 and containerd 1.4.4. Users should update to these versions.Show less
33mf
DebianFedoraproject
3Debian Linux
FedoraLib3mf
Jun 17, 2026
Mar 10, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious...Show more
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
2Fedoraproject
Libjpeg Turbo
2Fedora
Libjpeg Turbo
Jun 17, 2026
Mar 10, 2021
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.