← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Libming
2Fedora
Ming
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation fault and leads to denial of service.
2Fedoraproject
Libming
2Fedora
Ming
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
2Fedoraproject
Libming
2Fedora
Ming
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
2Fedoraproject
Libming
2Fedora
Ming
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
3Abcm2ps Project
DebianFedoraproject
3Abcm2ps
Debian LinuxFedora
Jun 17, 2026
Mar 10, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
3Abcm2ps Project
DebianFedoraproject
3Abcm2ps
Debian LinuxFedora
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Stack-based buffer overflow in the function get_key in parse.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
3Abcm2ps Project
DebianFedoraproject
3Abcm2ps
Debian LinuxFedora
Jun 17, 2026
Mar 10, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c.
3Debian
FedoraprojectZabbix
3Debian Linux
FedoraFrontend
Jun 17, 2026
Mar 9, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed...Show more
An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.Show less
2Fedoraproject
Zabbix
2Fedora
Frontend
Jun 17, 2026
Mar 9, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed...Show more
An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.Show less
3Debian
FedoraprojectZabbix
3Debian Linux
FedoraFrontend
Jun 17, 2026
Mar 9, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is chang...Show more
An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim during social engineering attacks.Show less
3Debian
FedoraprojectZabbix
3Debian Linux
FedoraFrontend
Jun 17, 2026
Mar 9, 2022
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modi...Show more
An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented with the help of social engineering and expiration of a number of factors - an attacker should have authorized access to the Zabbix Frontend and allowed network connection between a malicious server and victim’s computer, understand attacked infrastructure, be recognized by the victim as a trustee and use trusted communication channel.Show less
2Fedoraproject
Microsoft
6.net
.net CoreFedora+3 more
Jun 17, 2026
Mar 9, 2022
N/A· v4
6.3 MEDIUM· v3
6.8 MEDIUM· v2
.NET and Visual Studio Remote Code Execution Vulnerability
2Fedoraproject
Microsoft
5.net
.net CoreFedora+2 more
Jun 17, 2026
Mar 9, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
.NET and Visual Studio Denial of Service Vulnerability
3Debian
FedoraprojectRust Lang
3Debian Linux
FedoraRegex
Jun 17, 2026
Mar 8, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trust...Show more
regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's considered part of the crate's API. Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. All versions of the regex crate before or equal to 1.5.4 are affected by this issue. The fix is include starting from regex 1.5.5. All users accepting user-controlled regexes are recommended to upgrade immediately to the latest version of the regex crate. Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, it us not recommend to deny known problematic regexes.Show less
2Fedoraproject
Httpie
2Fedora
Httpie
Jun 17, 2026
Mar 7, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for fu...Show more
HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for further usage. Before 3.1.0, HTTPie didn‘t distinguish between cookies and hosts they belonged. This behavior resulted in the exposure of some cookies when there are redirects originating from the actual host to a third party website. Users are advised to upgrade. There are no known workarounds.Show less
3Debian
FedoraprojectNetwork Block Device Project
3Debian Linux
FedoraNetwork Block Device
Jun 17, 2026
Mar 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large val...Show more
In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.Show less
3Debian
FedoraprojectNetwork Block Device Project
3Debian Linux
FedoraNetwork Block Device
Jun 17, 2026
Mar 6, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resu...Show more
In nbd-server in nbd before 3.24, there is an integer overflow with a resultant heap-based buffer overflow. A value of 0xffffffff in the name length field will cause a zero-sized buffer to be allocated for the name, resulting in a write to a dangling pointer. This issue exists for the NBD_OPT_INFO, NBD_OPT_GO, and NBD_OPT_EXPORT_NAME messages.Show less
4Debian
FedoraprojectLinux+1 more
11Debian Linux
FedoraH300e Firmware+8 more
Jun 17, 2026
Mar 6, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
6Canonical
FedoraprojectNetapp+3 more
17Codeready Linux Builder
Codeready Linux Builder For Ibm Z SystemsCodeready Linux Builder For Power Little Endian+14 more
Jun 17, 2026
Mar 4, 2022
N/A· v4
7.5 HIGH· v3
7.1 HIGH· v2
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU...Show more
A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.Show less
3Fedoraproject
LinuxRedhat
263scale Api Management
Codeready Linux BuilderEnterprise Linux+23 more
Jun 17, 2026
Mar 4, 2022
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due...Show more
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape.Show less