CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Go Proxyproto Project2Fedora Go ProxyprotoJun 17, 2026 Mar 8, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Reader wrapping a net.Conn. It will read f...Show more |
2Fedoraproject Newlib Project2Fedora NewlibJun 17, 2026 Mar 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading t...Show more |
4Fedoraproject NetappOpenbsd+1 more9Cloud Backup Communications Offline Mediation ControllerFedora+6 moreJun 17, 2026 Mar 5, 2021 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-...Show more |
3Fedoraproject RedhatYtnef Project3Enterprise Linux FedoraYtnefJun 17, 2026 Mar 4, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file. |
3Fedoraproject RedhatYtnef Project3Enterprise Linux FedoraYtnefJun 17, 2026 Mar 4, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file. |
3Fedoraproject LinuxRedhat5Enterprise Linux FedoraLinux Kernel+2 moreJun 17, 2026 Mar 4, 2021 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local use...Show more |
3Cgal DebianFedoraproject3Computational Geometry Algorithms Library Debian LinuxFedoraJun 17, 2026 Mar 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->incident_sface. An at...Show more |
3Cgal DebianFedoraproject3Computational Geometry Algorithms Library Debian LinuxFedoraJun 17, 2026 Mar 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin() An attacker ca...Show more |
3Cgal DebianFedoraproject3Computational Geometry Algorithms Library Debian LinuxFedoraJun 17, 2026 Mar 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attac...Show more |
5Fedoraproject NetappNodejs+2 more13Active Iq Unified Manager E Series Performance AnalyzerFedora+10 moreJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is r...Show more |
5Fedoraproject NetappNodejs+2 more9E Series Performance Analyzer FedoraGraalvm+6 moreJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If...Show more |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Mar 3, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Mar 3, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Mar 3, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured. |
2Fedoraproject Slic3r2Fedora Libslic3rJun 17, 2026 Mar 3, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosur...Show more |
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreJun 17, 2026 Mar 3, 2021 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it...Show more |
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreJun 17, 2026 Mar 3, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of option...Show more |
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent Secure...Show more |
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreJun 17, 2026 Mar 3, 2021 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 A flaw was found in grub2 in versions prior to 2.06. Variable names present are expanded in the supplied command line into their corresponding variable contents, using a 1kB stack buffer for temporary storage, without su...Show more |
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreJun 17, 2026 Mar 3, 2021 N/A· v4 7.6 HIGH· v3 7.2 HIGH· v2 A flaw was found in grub2 in versions prior to 2.06. During USB device initialization, descriptors are read with very little bounds checking and assumes the USB device is providing sane values. If properly exploited, an...Show more |