Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can b...Show more |
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts()...Show more |
3Apache FedoraprojectNetapp3Clustered Data Ontap FedoraHttp ServerJun 17, 2026 Jun 9, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue af...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jun 9, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count f...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jun 9, 2022 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count f...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Jun 9, 2022 N/A· v4 6.4 MEDIUM· v3 6.9 MEDIUM· v2 x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests...Show more |
3Debian FedoraprojectFirejail Project3Debian Linux FedoraFirejailJun 17, 2026 Jun 9, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A Privilege Context Switching issue was discovered in join.c in Firejail 0.9.68. By crafting a bogus Firejail container that is accepted by the Firejail setuid-root program as a join target, a local attacker can enter an...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Jun 9, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Out-of-bounds Write in GitHub repository vim/vim prior to 8.2. |
4Fedoraproject LinuxNetapp+1 more8Enterprise Linux FedoraH300s Firmware+5 moreJun 17, 2026 Jun 9, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the sys...Show more |
3Debian FedoraprojectLinuxfoundation3Containerd Debian LinuxFedoraJun 17, 2026 Jun 9, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation o...Show more |
2Fedoraproject Go Restful Project2Fedora Go RestfulJun 17, 2026 Jun 8, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0. |
2Cookiecutter Project Fedoraproject2Cookiecutter FedoraJun 17, 2026 Jun 8, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout co...Show more |
3Fedoraproject KubernetesRedhat4Cri O Enterprise LinuxFedora+1 moreJun 17, 2026 Jun 7, 2022 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. Thi...Show more |
3Fedoraproject JmespathJmespath Project3Fedora JmespathJmespathJun 17, 2026 Jun 6, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable. |
4Debian FedoraprojectLinux+1 more8Debian Linux FedoraH300s Firmware+5 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-f...Show more |
3Bottlepy DebianFedoraproject3Bottle Debian LinuxFedoraJun 17, 2026 Jun 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Bottle before 0.12.20 mishandles errors during early request binding. |
2Fedoraproject Liblouis2Fedora LiblouisJun 17, 2026 Jun 2, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace. |
6Brocade DebianFedoraproject+3 more13Clustered Data Ontap CurlDebian Linux+10 moreJun 17, 2026 Jun 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number. |
2Fedoraproject Redhat4389 Directory Server Directory ServerEnterprise Linux+1 moreJun 17, 2026 Jun 2, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An access control bypass vulnerability found in 389-ds-base. That mishandling of the filter that would yield incorrect results, but as that has progressed, can be determined that it actually is an access control bypass....Show more |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jun 2, 2022 N/A· v4 6.8 MEDIUM· v3 6.9 MEDIUM· v2 With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference. |