CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Fedoraproject GnuNetapp+1 more8Enterprise Linux Enterprise Linux Server AusEnterprise Linux Server Eus+5 moreJun 17, 2026 Mar 3, 2021 N/A· v4 8.2 HIGH· v3 7.2 HIGH· v2 A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-fr...Show more |
4Fedoraproject GnuNetapp+1 more9Cloud Backup Enterprise LinuxEnterprise Linux Server Aus+6 moreJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 6.2 MEDIUM· v2 A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System...Show more |
2Fedoraproject Markdown2 Project2Fedora Markdown2Jun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICO container, and thus an attempted memory allocation...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for an ICNS container, and thus an attempted memory allocation...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pillow before 8.1.2 allows attackers to cause a denial of service (memory consumption) because the reported size of a contained image is not properly checked for a BLP container, and thus an attempted memory allocation c...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt before 3002.5. The salt-api's ssh client is vulnerable to a shell injection by including ProxyCommand in an argument, or via ssh_options provided in an API request. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quote...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.1 CRITICAL· v3 7.5 HIGH· v2 In SaltStack Salt before 3002.5, eauth tokens can be used once after expiration. (They might be used to run command against the salt master or minions.) |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 4.4 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An issue was discovered in through SaltStack Salt before 3002.5. The salt.wheel.pillar_roots.write method is vulnerable to directory traversal. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in through SaltStack Salt before 3002.5. salt-api does not honor eauth credentials for the wheel_async client. Thus, an attacker can remotely run any wheel modules on the master. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 In SaltStack Salt before 3002.5, when authenticating to services using certain modules, the SSL certificate is not always validated. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In SaltStack Salt before 3002.5, authentication to VMware vcenter, vsphere, and esxi servers (in the vmware.py files) does not always validate the SSL/TLS certificate. |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a...Show more |
3Debian FedoraprojectW1.fi3Debian Linux FedoraWpa SupplicantJun 17, 2026 Feb 26, 2021 N/A· v4 7.5 HIGH· v3 5.4 MEDIUM· v2 A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of a...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Feb 26, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, a malicious homeserver cou...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Feb 26, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided...Show more |
3Aiohttp DebianFedoraproject3Aiohttp Debian LinuxFedoraJun 17, 2026 Feb 26, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. In aiohttp before version 3.7.4 there is an open redirect vulnerability. A maliciously crafted link to an aiohttp-based web-server could red...Show more |