← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Apr 13, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
4Debian
FedoraprojectGoogle+1 more
5Backports
ChromeDebian Linux+2 more
Jun 17, 2026
Apr 13, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient policy enforcement in full screen in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted HTML page.
4Debian
FedoraprojectGoogle+1 more
5Backports Sle
ChromeDebian Linux+2 more
Jun 17, 2026
Apr 13, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
4Debian
FedoraprojectGoogle+1 more
5Backports Sle
ChromeDebian Linux+2 more
Jun 17, 2026
Apr 13, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
3Fedoraproject
LinuxfoundationRedhat
5Ceph
Ceph StorageFedora+2 more
Jun 17, 2026
Apr 13, 2020
N/A· v4
6.8 MEDIUM· v3
5.8 MEDIUM· v2
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attack...Show more
A vulnerability was found in Red Hat Ceph Storage 4 and Red Hat Openshift Container Storage 4.2 where, A nonce reuse vulnerability was discovered in the secure mode of the messenger v2 protocol, which can allow an attacker to forge auth tags and potentially manipulate the data by leveraging the reuse of a nonce in a session. Messages encrypted using a reused nonce value are susceptible to serious confidentiality and integrity attacks.Show less
5Debian
FedoraprojectNetapp+2 more
13Communications Brm Elastic Charging Engine
Communications Cloud Native Core Service Communication ProxyCommunications Design Studio+10 more
Jun 17, 2026
Apr 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server...Show more
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.Show less
2Convert\
Fedoraproject
2\
Fedora
Nov 21, 2024
Apr 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
perl-Convert-ASN1 (aka the Convert::ASN1 module for Perl) through 0.27 allows remote attackers to cause an infinite loop via unexpected input.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraGnutls+2 more
Jun 17, 2026
Apr 3, 2020
N/A· v4
7.4 HIGH· v3
5.8 MEDIUM· v2
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a rand...Show more
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.Show less
4Canonical
FedoraprojectLinux+1 more
278300 Firmware
8700 FirmwareA220 Firmware+24 more
Jun 17, 2026
Apr 2, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerabi...Show more
In the Linux kernel 5.5.0 and newer, the bpf verifier (kernel/bpf/verifier.c) did not properly restrict the register bounds for 32-bit operations, leading to out-of-bounds reads and writes in kernel memory. The vulnerability also affects the Linux 5.4 stable series, starting with v5.4.7, as the introducing commit was backported to that branch. This vulnerability was fixed in 5.6.1, 5.5.14, and 5.4.29. (issue is aka ZDI-CAN-10780)Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraHaproxy+3 more
Jun 17, 2026
Apr 2, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly ca...Show more
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.Show less
8Apache
BroadcomCanonical+5 more
14Brocade Fabric Operating System
Communications Element ManagerCommunications Session Report Manager+11 more
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request U...Show more
In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.Show less
3Debian
FedoraprojectGnu
3Debian Linux
FedoraGlibc
Jun 17, 2026
Apr 1, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for t...Show more
An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulnerability could lead to undefined behavior such as writing to out-of-bounds memory and potentially remote code execution. Furthermore, this memcpy() implementation allows for program execution to continue in scenarios where a segmentation fault or crash should have occurred. The dangers occur in that subsequent execution and iterations of this code will be executed with this corrupted data.Show less
6Apache
CanonicalDebian+3 more
11Communications Element Manager
Communications Session Report ManagerCommunications Session Route Manager+8 more
Jun 17, 2026
Apr 1, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
In Apache HTTP Server 2.4.0 to 2.4.41, mod_proxy_ftp may use uninitialized memory when proxying to a malicious FTP server.
3Fedoraproject
OpensuseRedhat
8Ansible Engine
Ansible TowerBackports Sle+5 more
Jun 17, 2026
Mar 31, 2020
N/A· v4
5.6 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on...Show more
A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of confidentiality of the system among other issues.Show less
2Fedoraproject
Kubernetes
2Fedora
Kubernetes
Jun 17, 2026
Mar 27, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
2Fedoraproject
Kubernetes
2Fedora
Kubernetes
Jun 17, 2026
Mar 27, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typica...Show more
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.Show less
2Fedoraproject
Mozilla
2Bleach
Fedora
Jun 17, 2026
Mar 24, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
2Fedoraproject
Mozilla
2Bleach
Fedora
Jun 17, 2026
Mar 24, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
3Arm
DebianFedoraproject
4Debian Linux
FedoraMbed Crypto+1 more
Jun 17, 2026
Mar 24, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.
4Fedoraproject
OpensuseOracle+1 more
4Communications Cloud Native Core Network Function Cloud Native Environment
FedoraLeap+1 more
Jun 17, 2026
Mar 24, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoade...Show more
A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoader loader. Applications that use the library to process untrusted input may be vulnerable to this flaw. An attacker could use this flaw to execute arbitrary code on the system by abusing the python/object/new constructor.Show less