Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject LinuxNetapp13Fedora H300e FirmwareH300s Firmware+10 moreJun 17, 2026 Mar 25, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged a...Show more |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Mar 25, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default. |
3Fedoraproject LinuxNetapp10Fedora H300e FirmwareH300s Firmware+7 moreJun 17, 2026 Mar 25, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to cras...Show more |
5Fedoraproject LinuxNetapp+2 more30Codeready Linux Builder Codeready Linux Builder EusCodeready Linux Builder Eus For Power Little Endian+27 moreJun 17, 2026 Mar 25, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw a...Show more |
4Fedoraproject LinuxNetapp+1 more383scale Api Management Codeready Linux BuilderCodeready Linux Builder Eus+35 moreJun 17, 2026 Mar 25, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their pr...Show more |
3Fedoraproject LinuxOracle5Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+2 moreJun 17, 2026 Mar 25, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is...Show more |
4Fedoraproject LinuxNetapp+1 more10Communications Cloud Native Core Binding Support Function FedoraH300e Firmware+7 moreJun 17, 2026 Mar 25, 2022 N/A· v4 8.0 HIGH· v3 7.4 HIGH· v2 An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potent...Show more |
3Fedoraproject NetappRedhat3Fedora LibvirtOntap Select Deploy Administration UtilityJun 17, 2026 Mar 25, 2022 N/A· v4 6.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition. |
4Debian FedoraprojectOpenexr+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 25, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not...Show more |
3Debian FedoraprojectOpenexr3Debian Linux FedoraOpenexrJun 17, 2026 Mar 25, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application s...Show more |
2Fedoraproject Linuxfoundation2Fedora ImgcryptJun 17, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The imgcrypt library provides API exensions for containerd to support encrypted container images and implements the ctd-decoder command line tool for use by containerd to decrypt encrypted container images. The imgcrypt...Show more |
2Fedoraproject Powerdns3Authoritative Server FedoraRecursorJun 17, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition c...Show more |
11Apple AzulDebian+8 more27Active Iq Unified Manager Debian LinuxE Series Santricity Os Controller+24 moreJul 14, 2026 Mar 25, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. |
4Debian FedoraprojectLinuxfoundation+1 more4Debian Linux FedoraMoby+1 moreJun 17, 2026 Mar 24, 2022 N/A· v4 5.9 MEDIUM· v3 4.6 MEDIUM· v2 Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-em...Show more |
2Fedoraproject Redhat3389 Directory Server Enterprise LinuxFedoraJun 17, 2026 Mar 23, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication. |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Mar 23, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem. |
5Canonical DebianFedoraproject+2 more6Debian Linux Enterprise LinuxEnterprise Linux Advanced Virtualization Eus+3 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 6.9 MEDIUM· v2 A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has b...Show more |
5Debian F5Fedoraproject+2 more5Debian Linux FedoraNginx+2 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ALPACA is an application layer protocol content confusion attack, exploiting TLS servers implementing different protocols but using compatible certificates, such as multi-domain or wildcard certificates. A MiTM attacker...Show more |
5Fedoraproject IscJuniper+2 more12Bind FedoraH300e Firmware+9 moreJun 17, 2026 Mar 23, 2022 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported...Show more |
4Fedoraproject IscNetapp+1 more11Bind FedoraH300e Firmware+8 moreJun 17, 2026 Mar 23, 2022 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an...Show more |