CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 22, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 22, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 22, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Feb 22, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. |
2Fedoraproject Reportlab2Fedora ReportlabJun 17, 2026 Feb 18, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Kar...Show more |
5Debian FedoraprojectIsc+2 more7500f Firmware A250 FirmwareBind+4 moreJun 17, 2026 Feb 17, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server...Show more |
3Fedoraproject OracleWireshark3Fedora WiresharkZfs Storage ApplianceJun 17, 2026 Feb 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Crash in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file |
3Fedoraproject OracleWireshark3Fedora WiresharkZfs Storage ApplianceJun 17, 2026 Feb 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Feb 17, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't sta...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Feb 17, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as the ones during scrub...Show more |
4Debian FedoraprojectLinux+1 more8Cloud Backup Debian LinuxFedora+5 moreJun 17, 2026 Feb 17, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failu...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Feb 17, 2021 N/A· v4 5.5 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Feb 17, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encounter...Show more |
5Broadcom DebianFedoraproject+2 more7Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+4 moreJun 17, 2026 Feb 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could poten...Show more |
5Broadcom DebianFedoraproject+2 more7Active Iq Unified Manager Brocade Fabric Operating System FirmwareCloud Backup+4 moreJun 17, 2026 Feb 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in GNOME GLib before 2.66.7 and 2.67.x before 2.67.4. If g_byte_array_new_take() was called with a buffer of 4GB or more on a 64-bit platform, the length would be truncated modulo 2**32, causing u...Show more |
6Debian DjangoprojectFedoraproject+3 more12Cloud Backup Communications Offline Mediation ControllerCommunications Pricing Design Center+9 moreJun 17, 2026 Feb 15, 2021 N/A· v4 5.9 MEDIUM· v3 4.0 MEDIUM· v2 The package python/cpython from 0 and before 3.6.13, from 3.7.0 and before 3.7.10, from 3.8.0 and before 3.8.8, from 3.9.0 and before 3.9.2 are vulnerable to Web Cache Poisoning via urllib.parse.parse_qsl and urllib.pars...Show more |
2Autotrace Project Fedoraproject2Autotrace FedoraJun 17, 2026 Feb 11, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after the use-after-free in CVE-2017-9182. |
2Autotrace Project Fedoraproject2Autotrace FedoraJun 17, 2026 Feb 11, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image. |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Feb 11, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 The Host Authorization middleware in Action Pack before 6.1.2.1, 6.0.3.5 suffers from an open redirect vulnerability. Specially crafted `Host` headers in combination with certain "allowed host" formats can cause the Host...Show more |
2Fedoraproject Rubyonrails2Fedora RailsJun 17, 2026 Feb 11, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` ty...Show more |