CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject ImagemagickRedhat4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 May 30, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding. |
3Fedoraproject ImagemagickRedhat4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 May 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. |
4Debian FedoraprojectImagemagick+1 more5Debian Linux Enterprise LinuxExtra Packages For Enterprise Linux+2 moreJun 17, 2026 May 30, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546). |
4Apple FedoraprojectHaxx+1 more9Clustered Data Ontap CurlFedora+6 moreJun 17, 2026 May 26, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFI...Show more |
5Apple DebianFedoraproject+2 more10Clustered Data Ontap CurlDebian Linux+7 moreJun 17, 2026 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use...Show more |
2Fedoraproject Python2Fedora RequestsJun 17, 2026 May 26, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to re...Show more |
3Fedoraproject LibsshRedhat3Enterprise Linux FedoraLibsshJun 17, 2026 May 26, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is ins...Show more |
2Fedoraproject Usebottles2Bottles FedoraJun 17, 2026 May 26, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file. |
3Avahi FedoraprojectRedhat3Avahi Enterprise LinuxFedoraJun 17, 2026 May 26, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash. |
4Debian FedoraprojectLibssh+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 26, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service. |
3C Ares Project DebianFedoraproject3C Ares Debian LinuxFedoraJun 17, 2026 May 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target reso...Show more |
2C Ares Project Fedoraproject2C Ares FedoraJun 17, 2026 May 25, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by sr...Show more |
3C Ares Project DebianFedoraproject3C Ares Debian LinuxFedoraJun 17, 2026 May 25, 2023 N/A· v4 6.4 MEDIUM· v3 N/A· v2 c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function...Show more |
2C Ares Project Fedoraproject2C Ares FedoraJun 17, 2026 May 25, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using...Show more |
3Debian FedoraprojectSysstat Project3Debian Linux FedoraSysstatJun 17, 2026 May 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377. |
3Fedoraproject LibtiffRedhat3Enterprise Linux FedoraLibtiffJun 17, 2026 May 17, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL p...Show more |
3Debian FedoraprojectLinuxfoundation3Cups Filters Debian LinuxFedoraJun 17, 2026 May 17, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible netw...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 May 16, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 May 16, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Guest View in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium se...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 May 16, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Type confusion in V8 in Google Chrome prior to 113.0.5672.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |