CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Tpm2 Software Stack Project2Fedora Tpm2 Software StackJun 17, 2026 Feb 26, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3. |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreJun 17, 2026 Feb 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 .NET Core Remote Code Execution Vulnerability |
2Fedoraproject Keylime2Fedora KeylimeJun 17, 2026 Feb 25, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations. |
3Debian FedoraprojectQemu3Debian Linux FedoraQemuJun 17, 2026 Feb 25, 2021 N/A· v4 3.2 LOW· v3 2.1 LOW· v2 An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest...Show more |
2Apache Fedoraproject2Fedora Xmlgraphics CommonsJun 17, 2026 Feb 24, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnera...Show more |
4Apache DebianFedoraproject+1 more22Agile Engineering Data Management Banking ApisBanking Digital Experience+19 moreJun 17, 2026 Feb 24, 2021 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the...Show more |
2Fedoraproject Openscad2Fedora OpenscadJun 17, 2026 Feb 24, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2. A specially crafted STL file can lead to code execution. An attacker can provide a mali...Show more |
3Debian FedoraprojectGnu3Debian Linux FedoraGlibcJun 17, 2026 Feb 24, 2021 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service o...Show more |
3Debian FedoraprojectLibcaca Project3Debian Linux FedoraLibcacaJun 17, 2026 Feb 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context. |
3Artifex DebianFedoraproject3Debian Linux FedoraMupdfJun 17, 2026 Feb 23, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in mupdf 1.18.0. Double free of object during linearization may lead to memory corruption and other potential consequences. |
3Debian FedoraprojectMatroska3Debian Linux FedoraLibebmlJun 17, 2026 Feb 23, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml. |
2Fedoraproject Jasper Project2Fedora JasperJun 17, 2026 Feb 23, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service. |
3Debian FedoraprojectMbsync Project4Debian Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 23, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in mbsync before v1.3.5 and v1.4.1. Validations of the mailbox names returned by IMAP LIST/LSUB do not occur allowing a malicious or compromised server to use specially crafted mailbox names containing '...Show more |
2Fedoraproject Jasper Project2Fedora JasperJun 17, 2026 Feb 23, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash. |
3Fedoraproject PostgresqlRedhat4Enterprise Linux FedoraPostgresql+1 moreJun 17, 2026 Feb 23, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerabili...Show more |
3Fedoraproject GoogleMicrosoft4Chrome EdgeEdge Chromium+1 moreJun 17, 2026 Feb 22, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 22, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 22, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 22, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 22, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. |