← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Microsoft
4Asp.net Core
FedoraVisual Studio 2017+1 more
Jun 17, 2026
Aug 17, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web applicatio...Show more
A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web application. The vulnerability can be exploited remotely, without authentication. A remote unauthenticated attacker could exploit this vulnerability by issuing specially crafted requests to the ASP.NET Core application. The update addresses the vulnerability by correcting how the ASP.NET Core web application handles web requests.Show less
8Canonical
DebianFedoraproject+5 more
15Debian Linux
Directory ServerFedora+12 more
Jun 17, 2026
Aug 17, 2020
N/A· v4
10.0 CRITICAL· v3
9.3 HIGH· v2
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successful...Show more
An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially crafted application on a device on the network. To exploit the vulnerability, an unauthenticated attacker would be required to use MS-NRPC to connect to a domain controller to obtain domain administrator access. Microsoft is addressing the vulnerability in a phased two-part rollout. These updates address the vulnerability by modifying how Netlogon handles the usage of Netlogon secure channels. For guidelines on how to manage the changes required for this vulnerability and more information on the phased rollout, see How to manage the changes in Netlogon secure channel connections associated with CVE-2020-1472 (updated September 28, 2020). When the second phase of Windows updates become available in Q1 2021, customers will be notified via a revision to this security vulnerability. If you wish to be notified when these updates are released, we recommend that you register for the security notifications mailer to be alerted of content changes to this advisory. See Microsoft Technical Security Notifications.Show less
3Debian
FedoraprojectLua
3Debian Linux
FedoraLua
Jun 17, 2026
Aug 17, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
2Fedoraproject
Lua
2Fedora
Lua
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
2Fedoraproject
Trustedcomputinggroup
2Fedora
Trousers
Jun 17, 2026
Aug 13, 2020
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt exis...Show more
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.Show less
2Fedoraproject
Trousers Project
2Fedora
Trousers
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to...Show more
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to this daemon).Show less
2Fedoraproject
Trousers Project
2Fedora
Trousers
Jun 17, 2026
Aug 13, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed.
4Fedoraproject
OpensuseOracle+1 more
4Fedora
LeapWireshark+1 more
Jun 17, 2026
Aug 13, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
3Debian
FedoraprojectQt
3Debian Linux
FedoraQt
Jun 17, 2026
Aug 12, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read.
4Canonical
DebianDovecot+1 more
4Debian Linux
DovecotFedora+1 more
Jun 17, 2026
Aug 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
4Canonical
DebianDovecot+1 more
4Debian Linux
DovecotFedora+1 more
Jun 17, 2026
Aug 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read.
4Canonical
DebianDovecot+1 more
4Debian Linux
DovecotFedora+1 more
Jun 17, 2026
Aug 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts.
2Fedoraproject
Roundcube
2Fedora
Webmail
Jun 17, 2026
Aug 12, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Aug 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECUR...Show more
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.Show less
4Debian
FedoraprojectFirejail Project+1 more
4Debian Linux
FedoraFirejail+1 more
Jun 17, 2026
Aug 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
4Debian
FedoraprojectFirejail Project+1 more
4Debian Linux
FedoraFirejail+1 more
Jun 17, 2026
Aug 11, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
2F2fs Tools Project
Fedoraproject
2F2fs Tools
Fedora
Jun 17, 2026
Aug 10, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code...Show more
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
7Apache
CanonicalDebian+4 more
25Communications Element Manager
Communications Session Report ManagerCommunications Session Route Manager+22 more
Jun 17, 2026
Aug 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.Show less
7Apache
CanonicalDebian+4 more
13Clustered Data Ontap
Communications Element ManagerCommunications Session Report Manager+10 more
Jun 17, 2026
Aug 7, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory...Show more
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.Show less
7Apache
CanonicalDebian+4 more
13Clustered Data Ontap
Communications Element ManagerCommunications Session Report Manager+10 more
Jun 17, 2026
Aug 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE