← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectLibslirp Project
3Debian Linux
FedoraLibslirp
Jun 17, 2026
Nov 26, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
3Debian
FedoraprojectSpice Space
3Debian Linux
FedoraSpice Vdagent
Jun 17, 2026
Nov 26, 2020
N/A· v4
6.3 MEDIUM· v3
5.4 MEDIUM· v2
A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly r...Show more
A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from the host. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.Show less
3Debian
FedoraprojectSpice Space
3Debian Linux
FedoraSpice Vdagent
Jun 17, 2026
Nov 26, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local gu...Show more
A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user could use this flaw to prevent legitimate agents from connecting to the spice-vdagentd daemon, resulting in a denial of service. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and prior.Show less
3Debian
FedoraprojectSpice Space
3Debian Linux
FedoraSpice Vdagent
Jun 17, 2026
Nov 26, 2020
N/A· v4
6.4 MEDIUM· v3
3.3 LOW· v2
A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from othe...Show more
A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.Show less
3Debian
FedoraprojectX11vnc Project
3Debian Linux
FedoraX11vnc
Jun 17, 2026
Nov 25, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.
3Debian
FedoraprojectSpice Space
3Debian Linux
FedoraSpice Vdagent
Jun 17, 2026
Nov 25, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/...Show more
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM system. The highest threat from this vulnerability is to system availability. This flaw affects spice-vdagent versions 0.20 and previous versions.Show less
4Debian
FedoraprojectMusl Libc+1 more
4Debian Linux
FedoraGraalvm+1 more
Jun 17, 2026
Nov 24, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).
2Fedoraproject
Matrix
2Fedora
Synapse
Jun 17, 2026
Nov 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federa...Show more
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event is accepted into the room's state, the impact is long-lasting and is not fixed by an upgrade to a newer version, requiring the event to be manually redacted instead. Since events are replicated to servers of other room members, the impact is not constrained to the server of the event sender.Show less
2Fedoraproject
Redhat
4Ceph
Ceph StorageFedora+1 more
Jun 17, 2026
Nov 23, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows a...Show more
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph service via a packet sniffer and perform actions allowed by the Ceph service. This issue is a reintroduction of CVE-2018-1128, affecting the msgr2 protocol. The msgr 2 protocol is used for all communication except older clients that do not support the msgr2 protocol. The msgr1 protocol is not affected. The highest threat from this vulnerability is to confidentiality, integrity, and system availability.Show less
2Fedoraproject
Xpdfreader
2Fedora
Xpdf
Jun 17, 2026
Nov 21, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested...Show more
In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested Type 3 characters wasn't correctly handling the case where a Type 3 char referred to another char in the same Type 3 font.Show less
3Debian
FedoraprojectPdfresurrect Project
3Debian Linux
FedoraPdfresurrect
Jun 17, 2026
Nov 20, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
3Debian
FedoraprojectLibvips
3Debian Linux
FedoraLibvips
Jun 17, 2026
Nov 20, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
2Drupal
Fedoraproject
2Drupal
Fedora
Jun 17, 2026
Nov 20, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting co...Show more
Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8.8.11, and 7 versions prior to 7.74.Show less
3Fedoraproject
IbmOracle
6Aix
Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+3 more
Jun 17, 2026
Nov 20, 2020
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
2Fedoraproject
Rclone
2Fedora
Rclone
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords...Show more
An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on the time the second rclone was started. This limits the entropy of the passwords enormously. These passwords are often used in the crypt backend for encryption of data. It would be possible to make a dictionary of all possible passwords with about 38 million entries per password length. This would make decryption of secret material possible with a plausible amount of effort. NOTE: all passwords generated by affected versions should be changed.Show less
4Debian
DrupalFedoraproject+1 more
4Archive Tar
Debian LinuxDrupal+1 more
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as file:// to overwrite files) can still succeed.
4Debian
DrupalFedoraproject+1 more
4Archive Tar
Debian LinuxDrupal+1 more
Jun 17, 2026
Nov 19, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Archive_Tar through 1.4.10 allows an unserialization attack because phar: is blocked but PHAR: is not blocked.
3Debian
FedoraprojectLinux
3Debian Linux
FedoraLinux Kernel
Jun 17, 2026
Nov 19, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d4122754442...Show more
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.Show less
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Nov 19, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in mood...Show more
The participants table download in Moodle always included user emails, but should have only done so when users' emails are not hidden. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5 and 3.7 to 3.7.8. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, and 3.10.Show less
2Fedoraproject
Moodle
2Fedora
Moodle
Jun 17, 2026
Nov 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.