Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject RedhatUclouvain3Enterprise Linux FedoraOpenjpegJun 17, 2026 Mar 4, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application...Show more |
5Debian FedoraprojectLinux+2 more23Build Of Quarkus Codeready Linux BuilderCodeready Linux Builder Eus+20 moreJun 17, 2026 Mar 4, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak flaw was found in the Linux kernel in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c, which allows attackers to cause a denial of service (memory consumption). This vulnerability is simi...Show more |
4Fedoraproject LinuxNetapp+1 more13Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+10 moreJun 17, 2026 Mar 4, 2022 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash...Show more |
3Fedoraproject PostgresqlRedhat6Enterprise Linux Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Little Endian+3 moreJun 17, 2026 Mar 4, 2022 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established,...Show more |
3Cacti DebianFedoraproject3Cacti Debian LinuxFedoraJun 17, 2026 Mar 3, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. |
5Canonical DebianFedoraproject+2 more12Debian Linux FedoraH300e Firmware+9 moreJun 17, 2026 Mar 3, 2022 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with th...Show more |
An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the dest...Show more |
4Debian FedoraprojectLinux+1 more6Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+3 moreJun 17, 2026 Mar 3, 2022 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages...Show more |
4Debian FedoraprojectOracle+1 more5Debian Linux FedoraHttp Server+2 moreJun 17, 2026 Mar 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 22.2.0, Twisted SSH client and server implement is able to accept an infinite amount of data for the peer's SSH version iden...Show more |
2Fedoraproject Github2Cmark Gfm FedoraJun 17, 2026 Mar 3, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may...Show more |
6Canonical DebianFedoraproject+3 more37Bootstrap Os Codeready Linux BuilderCodeready Linux Builder For Power Little Endian+34 moreJun 17, 2026 Mar 3, 2022 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to esca...Show more |
2Fedoraproject Frrouting2Fedora FrroutingJun 17, 2026 Mar 3, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c. |
3Debian FedoraprojectLinuxfoundation3Containerd Debian LinuxFedoraJun 17, 2026 Mar 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 containerd is a container runtime available as a daemon for Linux and Windows. A bug was found in containerd prior to versions 1.6.1, 1.5.10, and 1.14.12 where containers launched through containerd’s CRI implementation...Show more |
3Fedoraproject PostgresqlRedhat7Enterprise Linux Enterprise Linux For Ibm Z SystemsEnterprise Linux For Power Little Endian+4 moreJun 17, 2026 Mar 2, 2022 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not requi...Show more |
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered o...Show more |
3Fedoraproject Libtpms ProjectRedhat3Enterprise Linux FedoraLibtpmsJun 17, 2026 Mar 2, 2022 N/A· v4 6.1 MEDIUM· v3 3.6 LOW· v2 A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/writt...Show more |
6Apple DebianFedoraproject+3 more35Active Iq Unified Manager Bootstrap OsClustered Data Ontap+32 moreJun 17, 2026 Feb 26, 2022 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. |
3Blender DebianFedoraproject4Blender Debian LinuxExtra Packages For Enterprise Linux+1 moreJun 17, 2026 Feb 24, 2022 N/A· v4 7.8 HIGH· v3 5.1 MEDIUM· v2 A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 24, 2022 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write da...Show more |
3Fedoraproject ImagemagickRedhat3Enterprise Linux FedoraImagemagickJun 17, 2026 Feb 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to...Show more |