Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in...Show more |
In certain Moodle products after creating a course, it is possible to add in a arbitrary "Topic" a resource, in this case a "Database" with the type "Text" where its values "Field name" and "Field description" are vulner...Show more |
2Fedoraproject Microsoft5.net .net CoreFedora+2 moreJun 17, 2026 Sep 13, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 .NET Core and Visual Studio Denial of Service Vulnerability |
2Fedoraproject Wireshark2Fedora WiresharkJun 17, 2026 Sep 13, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file |
2Fedoraproject Libconfuse Project2Fedora LibconfuseJun 17, 2026 Sep 9, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read. |
2Fedoraproject Oauthlib Project2Fedora OauthlibJun 17, 2026 Sep 9, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 OAuthLib is an implementation of the OAuth request-signing logic for Python 3.6+. In OAuthLib versions 3.1.1 until 3.2.1, an attacker providing malicious redirect uri can cause denial of service. An attacker can also lev...Show more |
2Fedoraproject Mobyproject2Fedora MobyJun 17, 2026 Sep 9, 2022 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a cont...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Sep 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_IOCTL_RESET and the NVME_IOCTL_SUBSYS_RESET through the device file of the driver, resulting in a PCI...Show more |
3Fedoraproject PythonRedhat5Enterprise Linux FedoraPython+2 moreJun 17, 2026 Sep 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (fl...Show more |
2Fedoraproject Pdfkit Project2Fedora PdfkitJun 17, 2026 Sep 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The package pdfkit from 0.0.0 are vulnerable to Command Injection where the URL is not properly sanitized. |
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error. |
2Dokuwiki Fedoraproject2Dokuwiki FedoraJun 17, 2026 Sep 5, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a. |
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_string in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly h...Show more |
An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or po...Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Sep 3, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Use After Free in GitHub repository vim/vim prior to 9.0.0360. |
2Fedoraproject Libdwarf Project2Fedora LibdwarfJun 17, 2026 Sep 2, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c. |
Samba does not validate the Validated-DNS-Host-Name right for the dNSHostName attribute which could permit unprivileged users to write it. |
2Fedoraproject Redhat3Ansible Automation Platform FedoraOpenshift Container PlatformJun 17, 2026 Sep 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allo...Show more |
In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values. |
Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol. |