Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 8, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2. |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 8, 2022 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2. |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 8, 2022 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2. |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 8, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use After Free in NPM radare2.js prior to 5.6.2. |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 8, 2022 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2. |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Feb 8, 2022 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2. |
3Fedoraproject GrafanaNetapp3E Series Performance Analyzer FedoraGrafanaJun 17, 2026 Feb 8, 2022 N/A· v4 5.4 MEDIUM· v3 2.1 LOW· v2 Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a...Show more |
2Fedoraproject Neutrinolabs2Fedora XrdpJun 17, 2026 Feb 7, 2022 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a...Show more |
3Debian FedoraprojectTwisted3Debian Linux FedoraTwistedJun 17, 2026 Feb 7, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 twisted is an event-driven networking engine written in Python. In affected versions twisted exposes cookies and authorization headers when following cross-origin redirects. This issue is present in the `twited.web.Redir...Show more |
2Fedoraproject Ruby Lang2Cgi FedoraJun 17, 2026 Feb 6, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integer overflow and resultant buffer overflow via a long string on platforms (such as Windows) where size_t and long have different numbers of bytes. This...Show more |
3Debian FedoraprojectKicad3Debian Linux FedoraKicad EdaJun 17, 2026 Feb 4, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file c...Show more |
3Debian FedoraprojectKicad3Debian Linux FedoraKicad EdaJun 17, 2026 Feb 4, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file c...Show more |
3Debian FedoraprojectSymfony3Debian Linux FedoraTwigJun 17, 2026 Feb 4, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions th...Show more |
3Debian FedoraprojectGerbv Project3Debian Linux FedoraGerbvJun 17, 2026 Feb 4, 2022 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit th...Show more |
3Debian FedoraprojectGerbv Project3Debian Linux FedoraGerbvJun 17, 2026 Feb 4, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execut...Show more |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Feb 3, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in MultiPartParser in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2. Passing certain inputs to multipart forms could result in an infinite loop when parsing files. |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 Feb 3, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The {% debug %} template tag in Django 2.2 before 2.2.27, 3.2 before 3.2.12, and 4.0 before 4.0.2 does not properly encode the current context. This may lead to XSS. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Feb 2, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Use After Free in GitHub repository vim/vim prior to 8.2. |
4Debian FedoraprojectPostgresql+1 more4Debian Linux FedoraPostgresql Jdbc Driver+1 moreJun 17, 2026 Feb 2, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 pgjdbc is the offical PostgreSQL JDBC Driver. A security hole was found in the jdbc driver for postgresql database while doing security research. The system using the postgresql library will be attacked when attacker con...Show more |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Feb 1, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. |