Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Debian FedoraprojectLinux+2 more13Debian Linux Enterprise LinuxFedora+10 moreJun 17, 2026 Mar 23, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause...Show more |
6Debian FedoraprojectLinux+3 more30Build Of Quarkus Codeready Linux BuilderCommunications Cloud Native Core Binding Support Function+27 moreJun 17, 2026 Mar 18, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way a user triggers write(). This flaw allows a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege...Show more |
3Debian FedoraprojectOpenvpn3Debian Linux FedoraOpenvpnJun 17, 2026 Mar 18, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 OpenVPN 2.1 until v2.4.12 and v2.5.6 may enable authentication bypass in external authentication plug-ins when more than one of them makes use of deferred authentication replies, which allows an external user to be grant...Show more |
3Fedoraproject GolangRedhat4Advanced Cluster Management For Kubernetes Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 18, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey. |
3Debian FedoraprojectParamiko3Debian Linux FedoraParamikoJun 17, 2026 Mar 17, 2022 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure. |
4Ckeditor DrupalFedoraproject+1 more9Application Express CkeditorCommerce Merchandising+6 moreJun 17, 2026 Mar 16, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular...Show more |
4Ckeditor DrupalFedoraproject+1 more9Application Express CkeditorCommerce Merchandising+6 moreJun 17, 2026 Mar 16, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vuln...Show more |
2Fedoraproject Paypal2Braintree/sanitize Url FedoraJun 17, 2026 Mar 16, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function. |
4Debian FedoraprojectQemu+1 more8Codeready Linux Builder Debian LinuxEnterprise Linux+5 moreJun 17, 2026 Mar 16, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. Th...Show more |
2Fedoraproject Nicotine Plus2Fedora Nicotine+Jun 17, 2026 Mar 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character. |
7Debian FedoraprojectMariadb+4 more13500f Firmware A250 FirmwareCloud Volumes Ontap Mediator+10 moreJun 17, 2026 Mar 15, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic cu...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Mar 14, 2022 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563. |
3Debian FedoraprojectFishshell3Debian Linux FedoraFishJun 17, 2026 Mar 14, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including runni...Show more |
4Apache DebianFedoraproject+1 more5Debian Linux FedoraHttp Server+2 moreJun 17, 2026 Mar 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Out-of-bounds Write vulnerability in mod_sed of Apache HTTP Server allows an attacker to overwrite heap memory with possibly attacker provided data. This issue affects Apache HTTP Server 2.4 version 2.4.52 and prior vers...Show more |
5Apache AppleDebian+2 more8Debian Linux Enterprise Manager Ops CenterFedora+5 moreJun 17, 2026 Mar 14, 2022 N/A· v4 9.1 CRITICAL· v3 5.8 MEDIUM· v2 If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52...Show more |
5Apache AppleDebian+2 more8Debian Linux Enterprise Manager Ops CenterFedora+5 moreJun 17, 2026 Mar 14, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Apache HTTP Server 2.4.52 and earlier fails to close inbound connection when errors are encountered discarding the request body, exposing the server to HTTP Request Smuggling |
5Apache AppleDebian+2 more7Debian Linux FedoraHttp Server+4 moreJun 17, 2026 Mar 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A carefully crafted request body can cause a read to a random memory area which could cause the process to crash. This issue affects Apache HTTP Server 2.4.52 and earlier. |
3Apple FedoraprojectLiblouis7Fedora IpadosIphone Os+4 moreJun 17, 2026 Mar 13, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c). |
2Fedoraproject Plugin Planet2Contact Form X FedoraJun 17, 2026 Mar 11, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4). |
2Fedoraproject Weplugins2Fedora Wp MapsJun 17, 2026 Mar 11, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-Site Request Forgery (CSRF) vulnerability affecting Delete Marker Category, Delete Map, and Copy Map functions in WP Google Map plugin (versions <= 4.2.3). |