Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apple FedoraprojectVim4Fedora Mac Os XMacos+1 moreJun 17, 2026 Dec 29, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Use After Free |
2Celeryproject Fedoraproject3Celery Extra Packages For Enterprise LinuxFedoraJun 17, 2026 Dec 29, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attack...Show more |
5Apache CiscoDebian+2 more22Cloudcenter Communications Brm Elastic Charging EngineCommunications Diameter Signaling Router+19 moreJun 17, 2026 Dec 28, 2021 N/A· v4 6.6 MEDIUM· v3 8.5 HIGH· v2 Apache Log4j2 versions 2.0-beta7 through 2.17.0 (excluding security fix releases 2.3.2 and 2.12.4) are vulnerable to a remote code execution (RCE) attack when a configuration uses a JDBC Appender with a JNDI LDAP data so...Show more |
3Apple FedoraprojectVim4Fedora Mac Os XMacos+1 moreJun 17, 2026 Dec 27, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Use After Free |
7Apple DebianFedoraproject+4 more8Debian Linux Enterprise LinuxFactory+5 moreJun 17, 2026 Dec 25, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 vim is vulnerable to Out-of-bounds Read |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Dec 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter. |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Dec 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In MediaWiki through 1.37, Wikibase item descriptions allow XSS, which is triggered upon a visit to an action=info URL (aka a page-information sidebar). |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Dec 24, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be us...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Dec 24, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In MediaWiki through 1.37, blocked IP addresses are allowed to edit EntitySchema items. |
2Fedoraproject Redhat4Enterprise Linux Enterprise Linux WorkstationFedora+1 moreJun 17, 2026 Dec 23, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack...Show more |
2Fedoraproject Redhat8Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+5 moreJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 A flaw was found in SSSD, where the sssctl command was vulnerable to shell command injection via the logs-fetch and cache-expire subcommands. This flaw allows an attacker to trick the root user into running a specially c...Show more |
3Fedoraproject Podman ProjectRedhat3Enterprise Linux FedoraPodmanJun 17, 2026 Dec 23, 2021 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on p...Show more |
4Debian FedoraprojectLinux+1 more11Debian Linux FedoraH300e Firmware+8 moreJun 17, 2026 Dec 23, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry. |
4Fedoraproject GeglGimp+1 more4Enterprise Linux FedoraGegl+1 moreJun 17, 2026 Dec 23, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick conv...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in window manager in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer underflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Dec 23, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |