CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Pgadmin2Fedora Pgadmin 4Jun 17, 2026 Jan 17, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially c...Show more |
3Debian FedoraprojectRuby Git Project3Debian Linux FedoraRuby GitJun 17, 2026 Jan 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability...Show more |
3Debian FedoraprojectTorproject3Debian Linux FedoraTorJun 17, 2026 Jan 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002. |
A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. |
A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file. |
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the...Show more |
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Jan 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are create...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Jan 11, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties. |
2Fedoraproject Microsoft3.net FedoraPowershellJun 17, 2026 Jan 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 .NET Denial of Service Vulnerability |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Jan 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Jan 10, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Jan 10, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are sl...Show more |
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. |
JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 do...Show more |
4Fedoraproject HaxxNetapp+1 more7Active Iq Unified Manager CurlFedora+4 moreJun 17, 2026 Dec 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even...Show more |
2Fedoraproject Openatom2Fedora OpeneulerJun 17, 2026 Dec 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released me...Show more |
3Debian FedoraprojectFfmpeg3Debian Linux FedoraFfmpegJun 17, 2026 Dec 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability. |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 17, 2026 Dec 15, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL...Show more |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 17, 2026 Dec 15, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) c...Show more |