← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectQemu
3Debian Linux
FedoraQemu
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.0 MEDIUM· v3
4.9 MEDIUM· v2
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or...Show more
A flaw was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest and may result in a crash of QEMU or cause undefined behavior due to the access of an uninitialized pointer. The highest threat from this vulnerability is to system availability.Show less
3Debian
FedoraprojectQemu
3Debian Linux
FedoraQemu
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.0 MEDIUM· v3
4.9 MEDIUM· v2
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input v...Show more
An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service. The highest threat from this vulnerability is to system availability.Show less
4Debian
FedoraprojectImagemagick+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and u...Show more
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.Show less
3Fedoraproject
Htmldoc ProjectRedhat
3Enterprise Linux
FedoraHtmldoc
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
3Audiofile
DebianFedoraproject
3Audiofile
Debian LinuxFedora
Jun 17, 2026
Feb 24, 2022
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function cal...Show more
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.Show less
5Cyrusimap
DebianFedoraproject+2 more
8Active Iq Unified Manager
Communications Cloud Native Core ConsoleCommunications Cloud Native Core Network Function Cloud Native Environment+5 more
Jun 17, 2026
Feb 24, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
2Fedoraproject
Libreoffice
2Fedora
Libreoffice
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper...Show more
LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice allowed an attacker to create a digitally signed ODF document, by manipulating the documentsignatures.xml or macrosignatures.xml stream within the document to contain both "X509Data" and "KeyValue" children of the "KeyInfo" tag, which when opened caused LibreOffice to verify using the "KeyValue" but to report verification with the unrelated "X509Data" value. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.5.Show less
3Debian
FedoraprojectUsbguard Project
3Debian Linux
FedoraUsbguard
Jun 17, 2026
Feb 24, 2022
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Feb 24, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Feb 23, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
4Apple
DebianFedoraproject+1 more
4Debian Linux
FedoraMacos+1 more
Jun 17, 2026
Feb 23, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
4Apple
DebianFedoraproject+1 more
4Debian Linux
FedoraMacos+1 more
Jun 17, 2026
Feb 22, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Feb 22, 2022
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Feb 22, 2022
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Feb 22, 2022
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
6Canonical
DebianFedoraproject+3 more
6Debian Linux
Enterprise LinuxFedora+3 more
Jun 17, 2026
Feb 21, 2022
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outa...Show more
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawnedShow less
4Apple
DebianFedoraproject+1 more
4Debian Linux
FedoraMacos+1 more
Jun 17, 2026
Feb 21, 2022
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
3Fedoraproject
RedhatSamba
3Fedora
SambaStorage
Jun 17, 2026
Feb 21, 2022
N/A· v4
4.3 MEDIUM· v3
3.5 LOW· v2
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. S...Show more
All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for this attack to succeed.Show less
6Canonical
DebianFedoraproject+3 more
23Codeready Linux Builder
Debian LinuxDiskstation Manager+20 more
Jun 17, 2026
Feb 21, 2022
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4...Show more
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP fileserver." Samba versions prior to 4.13.17, 4.14.12 and 4.15.5 with vfs_fruit configured allow out-of-bounds heap read and write via specially crafted extended file attributes. A remote attacker with write access to extended file attributes can execute arbitrary code with the privileges of smbd, typically root.Show less
2Cobbler Project
Fedoraproject
2Cobbler
Fedora
Jun 17, 2026
Feb 20, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the se...Show more
An issue was discovered in Cobbler before 3.3.1. Files in /etc/cobbler are world readable. Two of those files contain some sensitive information that can be exposed to a local user who has non-privileged access to the server. The users.digest file contains the sha2-512 digest of users in a Cobbler local installation. In the case of an easy-to-guess password, it's trivial to obtain the plaintext string. The settings.yaml file contains secrets such as the hashed default password.Show less