Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Zabbix2Fedora ZabbixJun 17, 2026 Jan 13, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for gr...Show more |
2Fedoraproject Zabbix2Fedora ZabbixJun 17, 2026 Jan 13, 2022 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permi...Show more |
2Fedoraproject Phoronix Media2Fedora Phoronix Test SuiteJun 17, 2026 Jan 13, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) |
2Fedoraproject Phoronix Media2Fedora Phoronix Test SuiteJun 17, 2026 Jan 13, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) |
4Debian FedoraprojectFlatpak+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jan 12, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the...Show more |
3Debian FedoraprojectGnome3Debian Linux FedoraGdkpixbufJun 17, 2026 Jan 12, 2022 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12. |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Jan 11, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 radare2 is vulnerable to Out-of-bounds Read |
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service. |
2Fedoraproject Pypa2Fedora PipenvJun 17, 2026 Jan 10, 2022 N/A· v4 8.6 HIGH· v3 9.3 HIGH· v2 pipenv is a Python development workflow tool. Starting with version 2018.10.9 and prior to version 2022.1.8, a flaw in pipenv's parsing of requirements files allows an attacker to insert a specially crafted string inside...Show more |
3Debian FedoraprojectSmarty3Debian Linux FedoraSmartyJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.42 and 4.0.2, template authors could run arbitrary PHP code by crafting a maliciou...Show more |
3Debian FedoraprojectSmarty3Debian Linux FedoraSmartyJun 17, 2026 Jan 10, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.43 and 4.0.3, template authors could run restricted static php methods. Users shou...Show more |
3Apple FedoraprojectVim3Fedora MacosVimJun 17, 2026 Jan 10, 2022 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 vim is vulnerable to Heap-based Buffer Overflow |
2Fedoraproject Phoronix Media2Fedora Phoronix Test SuiteJun 17, 2026 Jan 10, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') |
3Apple FedoraprojectVim3Fedora MacosVimJun 17, 2026 Jan 10, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 vim is vulnerable to Use After Free |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jan 6, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to b...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jan 6, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditio...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jan 6, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to improper sanitization in WP_Query, there can be cases where SQL injection is possible through plugin...Show more |
4Debian FedoraprojectOpensuse+1 more7Backports Debian LinuxExtra Packages For Enterprise Linux+4 moreJun 17, 2026 Jan 6, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. |
4Debian FedoraprojectOpensuse+1 more7Backports Debian LinuxExtra Packages For Enterprise Linux+4 moreJun 17, 2026 Jan 6, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. |
2Fedoraproject Linuxfoundation2Containerd FedoraJun 17, 2026 Jan 5, 2022 N/A· v4 9.1 CRITICAL· v3 6.0 MEDIUM· v2 containerd is an open source container runtime. On installations using SELinux, such as EL8 (CentOS, RHEL), Fedora, or SUSE MicroOS, with containerd since v1.5.0-beta.0 as the backing container runtime interface (CRI), a...Show more |