← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Mariadb
2Fedora
Mariadb
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
2Fedoraproject
Mariadb
2Fedora
Mariadb
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
7.5 HIGH· v2
MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.
2Fedoraproject
Lua
2Fedora
Lua
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue in the component luaG_runerror of Lua v5.4.4 and below leads to a heap-buffer overflow when a recursive error occurs.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jul 1, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jun 30, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
4Debian
FedoraprojectLibtiff+1 more
4Active Iq Unified Manager
Debian LinuxFedora+1 more
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
4Debian
FedoraprojectLibtiff+1 more
4Active Iq Unified Manager
Debian LinuxFedora+1 more
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
4Debian
FedoraprojectLibtiff+1 more
4Active Iq Unified Manager
Debian LinuxFedora+1 more
Jun 17, 2026
Jun 30, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jun 28, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
2Fedoraproject
Matrix
2Fedora
Synapse
Jun 17, 2026
Jun 28, 2022
N/A· v4
6.5 MEDIUM· v3
3.5 LOW· v2
Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded...Show more
Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion. This is sometimes recoverable and leads to an error for the request causing the problem, but in other cases the Synapse process may crash altogether. It is possible to exploit this maliciously, either by malicious users on the homeserver, or by remote users sending URLs that a local user's client may automatically request a URL preview for. Remote users are not able to exploit this directly, because the URL preview endpoint is authenticated. Deployments with `url_preview_enabled: false` set in configuration are not affected. Deployments with `url_preview_enabled: true` set in configuration **are** affected. Deployments with no configuration value set for `url_preview_enabled` are not affected, because the default is `false`. Administrators of homeservers with URL previews enabled are advised to upgrade to v1.61.1 or higher. Users unable to upgrade should set `url_preview_enabled` to false.Show less
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jun 27, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jun 27, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jun 27, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jun 26, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
3Debian
FedoraprojectRubyonrails
3Debian Linux
FedoraRails Html Sanitizers
Jun 17, 2026
Jun 24, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
# Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Ver...Show more
# Possible XSS Vulnerability in Rails::Html::SanitizerThere is a possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer.This vulnerability has been assigned the CVE identifier CVE-2022-32209.Versions Affected: ALLNot affected: NONEFixed Versions: v1.4.3## ImpactA possible XSS vulnerability with certain configurations of Rails::Html::Sanitizer may allow an attacker to inject content if the application developer has overridden the sanitizer's allowed tags to allow both `select` and `style` elements.Code is only impacted if allowed tags are being overridden. This may be done via application configuration:```ruby# In config/application.rbconfig.action_view.sanitized_allowed_tags = ["select", "style"]```see https://guides.rubyonrails.org/configuring.html#configuring-action-viewOr it may be done with a `:tags` option to the Action View helper `sanitize`:```<%= sanitize @comment.body, tags: ["select", "style"] %>```see https://api.rubyonrails.org/classes/ActionView/Helpers/SanitizeHelper.html#method-i-sanitizeOr it may be done with Rails::Html::SafeListSanitizer directly:```ruby# class-level optionRails::Html::SafeListSanitizer.allowed_tags = ["select", "style"]```or```ruby# instance-level optionRails::Html::SafeListSanitizer.new.sanitize(@article.body, tags: ["select", "style"])```All users overriding the allowed tags by any of the above mechanisms to include both "select" and "style" should either upgrade or use one of the workarounds immediately.## ReleasesThe FIXED releases are available at the normal locations.## WorkaroundsRemove either `select` or `style` from the overridden allowed tags.## CreditsThis vulnerability was responsibly reported by [windshock](https://hackerone.com/windshock?type=user).Show less
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Jun 23, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
2Fedoraproject
Protobuf C Project
2Fedora
Protobuf C
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspe...Show more
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.Show less
2Fedoraproject
Harfbuzz Project
2Fedora
Harfbuzz
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An integer overflow in the component hb-ot-shape-fallback.cc of Harfbuzz v4.3.0 allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
3Fedoraproject
GolangNetapp
3Beegfs Csi Driver
FedoraGo
Jun 17, 2026
Jun 23, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.