Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. |
3Apache DebianFedoraproject3Debian Linux FedoraTraffic ServerJun 17, 2026 Aug 10, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper Input Validation vulnerability in header parsing of Apache Traffic Server allows an attacker to request secure resources. This issue affects Apache Traffic Server 8.0.0 to 9.1.2. |
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc. |
3Fedoraproject LinuxNetapp7Fedora H300s FirmwareH410c Firmware+4 moreJun 17, 2026 Aug 5, 2022 N/A· v4 7.1 HIGH· v3 N/A· v2 A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attacker to crash the system and leads to a kernel information leak problem. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Aug 5, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the page's pfn. As vaddr and vm_pgoff are controllable by user-mode processes, this flaw allows unprivi...Show more |
6Apple DebianFedoraproject+3 more18Active Iq Unified Manager Debian LinuxFedora+15 moreJul 14, 2026 Aug 5, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applicati...Show more |
3Debian FedoraprojectPostgresql3Debian Linux FedoraPostgresql Jdbc DriverJun 17, 2026 Aug 3, 2022 N/A· v4 8.0 HIGH· v3 N/A· v2 PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method...Show more |
An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. H...Show more |
2Fedoraproject Rust Websocket Project2Fedora Rust WebsocketJun 17, 2026 Aug 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the i...Show more |
2Fedoraproject Nlnetlabs2Fedora UnboundJun 17, 2026 Aug 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain na...Show more |
2Fedoraproject Nlnetlabs2Fedora UnboundJun 17, 2026 Aug 1, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a r...Show more |
4Debian FedoraprojectGnu+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Aug 1, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function. |
4Debian FedoraprojectLibtiff+1 more5Active Iq Unified Manager Debian LinuxFedora+2 moreJun 17, 2026 Jul 29, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" u...Show more |
2Fedoraproject Squirrel Lang2Fedora SquirrelJun 17, 2026 Jul 28, 2022 N/A· v4 10.0 CRITICAL· v3 N/A· v2 sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possibl...Show more |
3Clusterlabs DebianFedoraproject3Booth Debian LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from...Show more |
2Fedoraproject Google3Chrome Extra Packages For Enterprise LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via di...Show more |
2Fedoraproject Google3Chrome Extra Packages For Enterprise LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
6Apple FedoraprojectGoogle+3 more12Chrome Extra Packages For Enterprise LinuxFedora+9 moreJun 17, 2026 Jul 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google3Chrome Extra Packages For Enterprise LinuxFedoraJun 17, 2026 Jul 28, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction. |