CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Sep 27, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Users were able to forge read receipts for any event (if they knew the room ID and event ID). Note that the users were not...Show more |
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. When users update their passwords, the new credentials may be briefly held in the server database. While this doesn't grant...Show more |
3Apple DebianFedoraproject8Debian Linux FedoraIpados+5 moreJun 17, 2026 Sep 27, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The issue was addressed with improved checks. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution. |
2Apple Fedoraproject7Fedora IpadosIphone Os+4 moreJun 17, 2026 Sep 27, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The issue was addressed with improved memory handling. This issue is fixed in tvOS 17, Safari 17, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. Processing web content may lead to arbitrary code execution. |
3Fedoraproject KubernetesRedhat7Cri O Extra Packages For Enterprise LinuxFedora+4 moreJun 17, 2026 Sep 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in cri-o. This issue allows the addition of arbitrary lines into /etc/passwd by use of a specially crafted environment variable. |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGawkJun 17, 2026 Sep 25, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information. |
2Aes Gcm Project Fedoraproject2Aes Gcm FedoraJun 17, 2026 Sep 22, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plainte...Show more |
2Fedoraproject Pgadmin2Fedora Pgadmin 4Jun 17, 2026 Sep 22, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in pgAdmin. This issue occurs when the pgAdmin server HTTP API validates the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. Versions of pgAdmin prior to 7.6 failed t...Show more |
2Fedoraproject Gnome2Fedora Gnome ShellJun 17, 2026 Sep 22, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of...Show more |
3Debian FedoraprojectOpenprinting4Cups Debian LinuxFedora+1 moreJun 17, 2026 Sep 21, 2023 N/A· v4 7.0 HIGH· v3 N/A· v2 Due to failure in validating the length provided by an attacker-crafted PPD PostScript document, CUPS and libppd are susceptible to a heap-based buffer overflow and possibly code execution. This issue has been fixed in C...Show more |
6Apple DebianFedoraproject+3 more14Active Iq Unified Manager Cloud Insights Acquisition UnitCloud Insights Storage Workload Security Agent+11 moreJun 17, 2026 Sep 21, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploit...Show more |
2Fedoraproject Snapview2Fedora TungsteniteJun 17, 2026 Sep 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how...Show more |
4Debian FedoraprojectIsc+1 more8Bind Debian LinuxFedora+5 moreJun 17, 2026 Sep 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS...Show more |
3Debian FedoraprojectIsc3Bind Debian LinuxFedoraJun 17, 2026 Sep 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environmen...Show more |
3Fedoraproject GnuRedhat22Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+19 moreJul 14, 2026 Sep 18, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module imp...Show more |
4Fedoraproject GnuNetapp+1 more27Codeready Linux Builder Eus Codeready Linux Builder Eus For Power Little EndianCodeready Linux Builder Eus For Power Little Endian Eus+24 moreJun 17, 2026 Sep 18, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can...Show more |
2Artifex Fedoraproject2Fedora GhostscriptJun 17, 2026 Sep 18, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER h...Show more |
3Fedoraproject HaxxMicrosoft10Curl FedoraWindows 10 1809+7 moreJun 17, 2026 Sep 15, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Sep 13, 2023 N/A· v4 5.6 MEDIUM· v3 N/A· v2 A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEX...Show more |
3Fedoraproject QemuRedhat3Enterprise Linux FedoraQemuJun 17, 2026 Sep 13, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A flaw was found in the QEMU built-in VNC server while processing ClientCutText messages. A wrong exit condition may lead to an infinite loop when inflating an attacker controlled zlib buffer in the `inflate_buffer` func...Show more |