← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Htmldoc Project
2Fedora
Htmldoc
Jun 17, 2026
Apr 4, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.
4Debian
FedoraprojectLinux+1 more
4Debian Linux
FedoraHci Baseboard Management Controller+1 more
Jun 17, 2026
Apr 3, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
4Debian
FedoraprojectLinux+1 more
11Debian Linux
FedoraH300e Firmware+8 more
Jun 17, 2026
Apr 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
4Debian
FedoraprojectLinux+1 more
11Debian Linux
FedoraH300e Firmware+8 more
Jun 17, 2026
Apr 3, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
2Fedoraproject
Linux
2Fedora
Linux Kernel
Jun 17, 2026
Apr 1, 2022
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local u...Show more
An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.Show less
3Debian
FedoraprojectPuma
3Debian Linux
FedoraPuma
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Pum...Show more
Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may disagree on where a request starts and ends. This would allow requests to be smuggled via the front-end proxy to Puma. The vulnerability has been fixed in 5.6.4 and 4.3.12. Users are advised to upgrade as soon as possible. Workaround: when deploying a proxy in front of Puma, turning on any and all functionality to make sure that the request matches the RFC7230 standard.Show less
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
4Debian
FedoraprojectOracle+1 more
4Communications Cloud Native Core Network Exposure Function
Debian LinuxFedora+1 more
Jun 17, 2026
Mar 30, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
3Debian
FedoraprojectMediawiki
3Debian Linux
FedoraMediawiki
Jun 17, 2026
Mar 30, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Specia...Show more
An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Special:RevisionDelete.Show less
3Debian
FedoraprojectUclouvain
3Debian Linux
FedoraOpenjpeg
Jun 17, 2026
Mar 29, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory,...Show more
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.Show less
5Canonical
FedoraprojectLinux+2 more
12Enterprise Linux
FedoraH300e Firmware+9 more
Jun 17, 2026
Mar 29, 2022
8.6 HIGH· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47f...Show more
A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5Show less
2Fedoraproject
Libarchive
2Fedora
Libarchive
Jun 17, 2026
Mar 28, 2022
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
2Fedoraproject
Python
2Fedora
Pillow
Jun 17, 2026
Mar 28, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
2Fedoraproject
Gnu
2Fedora
Gcc
Jun 17, 2026
Mar 26, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
Mar 26, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
Mar 26, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
Mar 26, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
Mar 26, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
3Fedoraproject
NetatalkWesterndigital
13Fedora
My Cloud Dl2100 FirmwareMy Cloud Dl4100 Firmware+10 more
Jun 17, 2026
Mar 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
2Fedoraproject
Kiwix
2Fedora
Libkiwix
Jun 17, 2026
Mar 25, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.