CVEs (1,858)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Debian FedoraprojectOpensuse+3 more9Date Debian LinuxEnterprise Linux+6 moreJun 17, 2026 Jan 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. |
7Apple DebianFedoraproject+4 more8Debian Linux Enterprise LinuxFactory+5 moreJun 17, 2026 Dec 25, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 vim is vulnerable to Out-of-bounds Read |
2Fedoraproject Redhat4Enterprise Linux Enterprise Linux WorkstationFedora+1 moreJun 17, 2026 Dec 23, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack...Show more |
2Fedoraproject Redhat8Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+5 moreJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially c...Show more |
3Fedoraproject Podman ProjectRedhat3Enterprise Linux FedoraPodmanJun 17, 2026 Dec 23, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on p...Show more |
4Fedoraproject GeglGimp+1 more4Enterprise Linux FedoraGegl+1 moreJun 17, 2026 Dec 23, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick conv...Show more |
5Debian FedoraprojectLinux+2 more12Debian Linux Enterprise LinuxFedora+9 moreJun 17, 2026 Dec 22, 2021 N/A· v4 7.0 HIGH· v3 4.4 MEDIUM· v2 A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object. |
5Debian FedoraprojectGnu+2 more5Binutils Debian LinuxEnterprise Linux+2 moreJun 17, 2026 Dec 15, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds wr...Show more |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
5Fedoraproject JulialangLapack Project+2 more8Ceph Storage Enterprise LinuxFedora+5 moreJun 17, 2026 Dec 8, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these function...Show more |
3Fedoraproject RedhatUdisks Project3Enterprise Linux FedoraUdisksJun 17, 2026 Nov 29, 2021 N/A· v4 4.2 MEDIUM· v3 6.3 MEDIUM· v2 A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability. |
6C Ares Project FedoraprojectNodejs+3 more17C Ares Enterprise LinuxEnterprise Linux Computer Node+14 moreJun 17, 2026 Nov 23, 2021 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The h...Show more |
4Debian FedoraprojectPgbouncer+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Nov 22, 2021 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 When PgBouncer is configured to use "cert" authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of TLS certificate verification and encrypt...Show more |
4Debian LinuxOracle+1 more6Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+3 moreJun 17, 2026 Nov 4, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.14.15. There is an array-index-out-of-bounds flaw in the detach_capi_ctr function in drivers/isdn/capi/kcapi.c. |
3Fedoraproject Libtpms ProjectRedhat3Enterprise Linux FedoraLibtpmsJun 17, 2026 Oct 19, 2021 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in the libtpms code that may cause access beyond the boundary of internal buffers. The vulnerability is triggered by specially-crafted TPM2 command packets that then trigger the issue when the state of t...Show more |
6Debian FedoraprojectNetapp+3 more8Communications Operations Monitor Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Oct 4, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. Thi...Show more |
3Debian LinuxRedhat3Debian Linux Enterprise LinuxLinux KernelJun 17, 2026 Sep 29, 2021 N/A· v4 8.8 HIGH· v3 6.1 MEDIUM· v2 A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more |
11Apache BroadcomDebian+8 more39Brocade Fabric Operating System Firmware Cloud BackupClustered Data Ontap+36 moreJun 17, 2026 Sep 16, 2021 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Sep 7, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Sep 7, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vul...Show more |