Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Htmldoc Project2Fedora HtmldocJun 17, 2026 Apr 4, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow. |
4Debian FedoraprojectLinux+1 more4Debian Linux FedoraHci Baseboard Management Controller+1 moreJun 17, 2026 Apr 3, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free. |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Apr 3, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free. |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Apr 3, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Apr 1, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local u...Show more |
3Debian FedoraprojectPuma3Debian Linux FedoraPumaJun 17, 2026 Mar 30, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Pum...Show more |
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647. |
4Debian FedoraprojectOracle+1 more4Communications Cloud Native Core Network Exposure Function Debian LinuxFedora+1 moreJun 17, 2026 Mar 30, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. |
3Debian FedoraprojectMediawiki3Debian Linux FedoraMediawikiJun 17, 2026 Mar 30, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An XSS issue was discovered in MediaWiki before 1.35.6, 1.36.x before 1.36.4, and 1.37.x before 1.37.2. The widthheight, widthheightpage, and nbytes properties of messages are not escaped when used in galleries or Specia...Show more |
3Debian FedoraprojectUclouvain3Debian Linux FedoraOpenjpegJun 17, 2026 Mar 29, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory,...Show more |
5Canonical FedoraprojectLinux+2 more12Enterprise Linux FedoraH300e Firmware+9 moreJun 17, 2026 Mar 29, 2022 8.6 HIGH· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47f...Show more |
2Fedoraproject Libarchive2Fedora LibarchiveJun 17, 2026 Mar 28, 2022 N/A· v4 6.5 MEDIUM· v3 5.8 MEDIUM· v2 Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init. |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Mar 28, 2022 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled. |
2Fedoraproject Gnu2Fedora GccJun 17, 2026 Mar 26, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 26, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 26, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 26, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c. |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 26, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c. |
3Fedoraproject NetatalkWesterndigital13Fedora My Cloud Dl2100 FirmwareMy Cloud Dl4100 Firmware+10 moreJun 17, 2026 Mar 25, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code. |
2Fedoraproject Kiwix2Fedora LibkiwixJun 17, 2026 Mar 25, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0. |