Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGoogle4Debian Linux FedoraProtobuf Cpp+1 moreJun 17, 2026 Sep 22, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17....Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 22, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Use After Free in GitHub repository vim/vim prior to 9.0.0530. |
By sending specific queries to the resolver, an attacker can cause named to crash. |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
4Debian FedoraprojectIsc+1 more4Active Iq Unified Manager BindDebian Linux+1 moreJun 17, 2026 Sep 21, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for l...Show more |
3Debian FedoraprojectIsc3Bind Debian LinuxFedoraJun 17, 2026 Sep 21, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service. |
2Fedoraproject Grafana2Fedora GrafanaJun 17, 2026 Sep 20, 2022 N/A· v4 6.6 MEDIUM· v3 N/A· v2 Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over t...Show more |
3Apple DebianFedoraproject5Debian Linux FedoraIpados+2 moreJun 17, 2026 Sep 20, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A buffer overflow issue was addressed with improved memory handling. This issue is fixed in Safari 16, iOS 16, iOS 15.7 and iPadOS 15.7. Processing maliciously crafted web content may lead to arbitrary code execution. |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte ran...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass. A client can issue an HTTP Accept header field containing an optional "charset" parameter in order to receive the response in an encoded fo...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-...Show more |
3Debian FedoraprojectOwasp3Debian Linux FedoraOwasp Modsecurity Core Rule SetJun 17, 2026 Sep 20, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass by submitting a specially crafted HTTP Content-Type header field that indicates multiple character encoding schemes. A vulnerable back-en...Show more |
2Fedoraproject Imagemagick3Extra Packages For Enterprise Linux FedoraImagemagickJun 17, 2026 Sep 19, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 18, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Use After Free in GitHub repository vim/vim prior to 9.0.0490. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Sep 18, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 17, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483. |
2Adobe Fedoraproject2Fedora IndesignJun 17, 2026 Sep 16, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to...Show more |
2Fedoraproject Github2Cmark Gfm FedoraJun 17, 2026 Sep 15, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbound...Show more |
3Debian FedoraprojectLibexpat Project3Debian Linux FedoraLibexpatJun 17, 2026 Sep 14, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. |
2Fedoraproject Kdiskmark Project2Fedora KdiskmarkJun 17, 2026 Sep 14, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache. |