Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Freetype2Fedora FreetypeJun 17, 2026 Apr 22, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face. |
3Apple FedoraprojectVim3Fedora MacosVimJun 17, 2026 Apr 21, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774. |
3Debian FedoraprojectGnome3Debian Linux EpiphanyFedoraJun 17, 2026 Apr 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for...Show more |
2Fedoraproject Golang3Extra Packages For Enterprise Linux FedoraGoJun 17, 2026 Apr 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input. |
3Fedoraproject GolangNetapp3Fedora GoKubernetes Monitoring OperatorJun 17, 2026 Apr 20, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data. |
3Debian FedoraprojectGit4Debian Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Apr 19, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The package git before 1.11.0 are vulnerable to Command Injection via git argument injection. When calling the fetch(remote = 'origin', opts = {}) function, the remote parameter is passed to the git fetch subcommand in a...Show more |
2Fedoraproject Hashicorp2Consul FedoraJun 17, 2026 Apr 19, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 HashiCorp Consul and Consul Enterprise up to 1.9.16, 1.10.9, and 1.11.4 may allow server side request forgery when the Consul client agent follows redirects returned by HTTP health check endpoints. Fixed in 1.9.17, 1.10....Show more |
4Fedoraproject KubernetesMobyproject+1 more4Cri O FedoraMoby+1 moreJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable L...Show more |
2Fedoraproject Opensc Project2Fedora OpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library. |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library. |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library. |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid. |
3Fedoraproject Opensc ProjectRedhat3Enterprise Linux FedoraOpenscJun 17, 2026 Apr 18, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo. |
3Apple FedoraprojectVim3Fedora MacosVimJun 17, 2026 Apr 18, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution |
2Fedoraproject Plantuml2Fedora PlantumlJun 17, 2026 Apr 15, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets t...Show more |
2Fedoraproject Stb Project2Fedora StbJun 17, 2026 Apr 15, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac. |
3Debian FedoraprojectNothings3Debian Linux FedoraStb Image.hJun 17, 2026 Apr 15, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode. |
3Debian FedoraprojectNothings3Debian Linux FedoraStb Image.hJun 17, 2026 Apr 15, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors. |
3Debian FedoraprojectMutt3Debian Linux FedoraMuttJun 17, 2026 Apr 14, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line |
3E2fsprogs Project FedoraprojectRedhat3E2fsprogs Enterprise LinuxFedoraJun 17, 2026 Apr 14, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem. |