Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apache AzulDebian+3 more167 Mode Transition Tool Active Iq Unified ManagerCloud Insights Acquisition Unit+13 moreJun 17, 2026 Jul 19, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 The Apache Xalan Java XSLT library is vulnerable to an integer truncation issue when processing malicious XSLT stylesheets. This can be used to corrupt Java class files generated by the internal XSLTC compiler and execut...Show more |
2Autotrace Project Fedoraproject2Autotrace FedoraJun 17, 2026 Jul 14, 2022 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660. |
4Amd DebianFedoraproject+1 more126A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+123 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. |
6Debian FedoraprojectLlhttp+3 more6Debian Linux FedoraLlhttp+3 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS). |
6Debian FedoraprojectLlhttp+3 more6Debian Linux FedoraLlhttp+3 moreJun 17, 2026 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS). |
4Debian FedoraprojectNodejs+1 more4Debian Linux FedoraNode.js+1 moreJun 17, 2026 Jul 14, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP addr...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Jul 12, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Git is a distributed revision control system. Git prior to versions 2.37.1, 2.36.2, 2.35.4, 2.34.4, 2.33.4, 2.32.3, 2.31.4, and 2.30.5, is vulnerable to privilege escalation in all platforms. An unsuspecting user could s...Show more |
5Debian FedoraprojectIntel+2 more129Core I3 6100 Firmware Core I3 6100e FirmwareCore I3 6100h Firmware+126 moreJun 17, 2026 Jul 12, 2022 N/A· v4 6.5 MEDIUM· v3 1.9 LOW· v2 Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack r...Show more |
4Amd DebianFedoraproject+1 more126A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+123 moreJun 17, 2026 Jul 12, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions. |
Use After Free in GitHub repository vim/vim prior to 9.0.0046. |
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045. |
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044. |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 When curl < 7.84.0 does FTP transfers secured by krb5, it handles message verification failures wrongly. This flaw makes it possible for a Man-In-The-Middle attack to go unnoticed and even allows it to inject data to the...Show more |
6Apple DebianFedoraproject+3 more14Bootstrap Os Clustered Data OntapCurl+11 moreJun 17, 2026 Jul 7, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 When curl < 7.84.0 saves cookies, alt-svc and hsts data to local files, it makes the operation atomic by finalizing the operation with a rename from a temporary name to the final target file name.In that rename operation...Show more |
6Debian FedoraprojectHaxx+3 more19Bootstrap Os Clustered Data OntapCurl+16 moreJun 17, 2026 Jul 7, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompress...Show more |
7Apple DebianFedoraproject+4 more19Clustered Data Ontap CurlDebian Linux+16 moreJun 17, 2026 Jul 7, 2022 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this,...Show more |
3Debian FedoraprojectMomentjs3Debian Linux FedoraMomentJun 17, 2026 Jul 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing i...Show more |
4Fedoraproject GnuNetapp+1 more14Codeready Linux Builder Developer ToolsEnterprise Linux+11 moreJun 17, 2026 Jul 6, 2022 N/A· v4 4.5 MEDIUM· v3 4.4 MEDIUM· v2 A crafted 16-bit grayscale PNG image may lead to a out-of-bounds write in the heap area. An attacker may take advantage of that to cause heap data corruption or eventually arbitrary code execution and circumvent secure b...Show more |
2Fedoraproject Ultrajson Project2Fedora UltrajsonJun 17, 2026 Jul 5, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. In versions prior to 5.4.0 an error occurring while reallocating a buffer for string decoding can cause the buffer to get free...Show more |
2Fedoraproject Ultrajson Project2Fedora UltrajsonJun 17, 2026 Jul 5, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters n...Show more |