CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject RedhatSound Exchange Project4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Jul 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service. |
3Fedoraproject RedhatSound Exchange Project4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Jul 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service. |
3Fedoraproject LibreofficeRedhat3Enterprise Linux FedoraLibreofficeJun 17, 2026 Jul 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determi...Show more |
4Fedoraproject Youtube Dlc ProjectYt Dl+1 more4Fedora Youtube DlYoutube Dlc+1 moreJun 17, 2026 Jul 6, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different host, or leak them whe...Show more |
4Debian FedoraprojectLinux+1 more8Debian Linux FedoraH300s+5 moreJun 17, 2026 Jul 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Jul 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Jul 3, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name la...Show more |
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to deli...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Jun 30, 2023 N/A· v4 5.7 MEDIUM· v3 N/A· v2 A hash collision flaw was found in the IPv6 connection lookup table in the Linux kernel’s IPv6 functionality when a user makes a new kind of SYN flood attack. A user located in the local network or with a high bandwidth...Show more |
2Fedoraproject Plantuml2Fedora PlantumlJun 17, 2026 Jun 27, 2023 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9. |
2Fedoraproject Plantuml2Fedora PlantumlJun 17, 2026 Jun 27, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Improper Access Control in GitHub repository plantuml/plantuml prior to 1.2023.9. |
3Artifex DebianFedoraproject3Debian Linux FedoraGhostscriptJun 17, 2026 Jun 25, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix). |
5Debian FedoraprojectLinux+2 more9Debian Linux Enterprise LinuxFedora+6 moreJun 17, 2026 Jun 23, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been fre...Show more |
4Apple DebianFedoraproject+1 more4Cups Debian LinuxFedora+1 moreJun 17, 2026 Jun 22, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging serv...Show more |
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 If the `recursive-clients` quota is reached on a BIND 9 resolver configured with both `stale-answer-enable yes;` and `stale-answer-client-timeout 0;`, a sequence of serve-stale-related lookups could cause `named` to loop...Show more |
4Debian FedoraprojectIsc+1 more9Active Iq Unified Manager BindDebian Linux+6 moreJun 17, 2026 Jun 21, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Every `named` instance configured to run as a recursive resolver maintains a cache database holding the responses to the queries it has recently sent to authoritative servers. The size limit for that cache database can b...Show more |
2Fedoraproject Imagemagick3Extra Packages For Enterprise Linux FedoraImagemagickJun 17, 2026 Jun 16, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resultin...Show more |
2Fedoraproject Imagemagick3Extra Packages For Enterprise Linux FedoraImagemagickJun 17, 2026 Jun 16, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free...Show more |
2Fedoraproject Imagemagick3Extra Packages For Enterprise Linux FedoraImagemagickJun 17, 2026 Jun 16, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read...Show more |
2Fedoraproject Kubernetes2Fedora KubernetesJun 17, 2026 Jun 16, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In t...Show more |