Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 17, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confid...Show more |
5Debian FedoraprojectGnu+2 more5Binutils Debian LinuxEnterprise Linux+2 moreJun 17, 2026 Dec 15, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds wr...Show more |
2Fedoraproject Teeworlds2Fedora TeeworldsJun 17, 2026 Dec 15, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted...Show more |
7Apache CvatDebian+4 more556bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+52 moreJun 17, 2026 Dec 14, 2021 N/A· v4 9.0 CRITICAL· v3 5.1 MEDIUM· v2 It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the...Show more |
4Apache FedoraprojectOracle+1 more46Advanced Supply Chain Planning Business IntelligenceBusiness Process Management Suite+43 moreJun 17, 2026 Dec 14, 2021 N/A· v4 7.5 HIGH· v3 6.0 MEDIUM· v2 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName c...Show more |
5Debian FedoraprojectLxml+2 more11Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Exposure FunctionCommunications Cloud Native Core Policy+8 moreJun 17, 2026 Dec 13, 2021 N/A· v4 7.1 HIGH· v3 6.8 MEDIUM· v2 lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedde...Show more |
2Fedoraproject Perl2Comprehensive Perl Archive Network FedoraJun 17, 2026 Dec 13, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 CPAN 2.28 allows Signature Verification Bypass. |
The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass. |
2Fedoraproject Toktok2Fedora ToxcoreJun 17, 2026 Dec 13, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows...Show more |
12Apache AppleBentley+9 more1436bk1602 0aa12 0tp0 Firmware 6bk1602 0aa22 0tp0 Firmware6bk1602 0aa32 0tp0 Firmware+140 moreJun 17, 2026 Dec 10, 2021 N/A· v4 10.0 CRITICAL· v3 9.3 HIGH· v2 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other J...Show more |
5Fedoraproject JulialangLapack Project+2 more8Ceph Storage Enterprise LinuxFedora+5 moreJun 17, 2026 Dec 8, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these function...Show more |
5Canonical DebianDjangoproject+2 more5Debian Linux DjangoFedora+2 moreJun 17, 2026 Dec 8, 2021 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths. |
2Calibre Ebook Fedoraproject2Calibre FedoraJun 17, 2026 Dec 7, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py. |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Dec 6, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Use After Free |
3Debian FedoraprojectVim3Debian Linux FedoraVimJun 17, 2026 Dec 1, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Heap-based Buffer Overflow |
4Debian FedoraprojectNeovim+1 more4Debian Linux FedoraNeovim+1 moreJun 17, 2026 Dec 1, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 vim is vulnerable to Heap-based Buffer Overflow |
3Fedoraproject RedhatUdisks Project3Enterprise Linux FedoraUdisksJun 17, 2026 Nov 29, 2021 N/A· v4 4.2 MEDIUM· v3 6.3 MEDIUM· v2 A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability. |
2Fedoraproject Keepalived2Fedora KeepalivedJun 17, 2026 Nov 26, 2021 N/A· v4 5.4 MEDIUM· v3 5.5 MEDIUM· v2 In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in wh...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 Nov 24, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Symfony/Serializer handles serializing and deserializing data structures for Symfony, a PHP framework for web and console applications and a set of reusable PHP components. Symfony versions 4.1.0 before 4.4.35 and versio...Show more |
3Debian FedoraprojectXen3Debian Linux FedoraXenJun 17, 2026 Nov 24, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started i...Show more |