Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Redhat2Enterprise Linux SssdJun 30, 2026 Jun 30, 2026 N/A· v4 6.4 MEDIUM· v3 N/A· v2 A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this fla...Show more |
3Abrt Project FedoraprojectRedhat3Abrt Enterprise LinuxFedoraJun 29, 2026 Jun 13, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to...Show more |
3Abrt Project FedoraprojectRedhat3Abrt Enterprise LinuxFedoraJul 15, 2026 Jun 13, 2026 N/A· v4 7.8 HIGH· v3 N/A· v2 A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replace...Show more |
2Fedoraproject Freedesktop2Fedora LibinputJun 17, 2026 Apr 1, 2026 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is call...Show more |
2Fedoraproject Freedesktop2Fedora LibinputJul 15, 2026 Apr 1, 2026 N/A· v4 8.8 HIGH· v3 N/A· v2 A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run una...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Nov 14, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could all...Show more |
3Fedoraproject Podman ProjectRedhat4Enterprise Linux FedoraOpenshift Container Platform+1 moreJun 17, 2026 Aug 2, 2024 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resourc...Show more |
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two. |
Incorrect CSRF token checks resulted in multiple CSRF risks. |
Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt. |
Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access. |
Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) |
Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) |
Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) |
Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) |
Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: Medium) |