← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Ckeditor
DrupalFedoraproject+1 more
10Agile Plm
Application ExpressBanking Apis+7 more
Jun 17, 2026
Nov 17, 2021
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allow...Show more
CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malformed HTML bypassing content sanitization, which could result in executing JavaScript code. It affects all users using the CKEditor 4 at version < 4.17.0. The problem has been recognized and patched. The fix will be available in version 4.17.0.Show less
5Debian
FedoraprojectLinux+2 more
15Cloud Backup
Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+12 more
Jun 17, 2026
Nov 17, 2021
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).
4Debian
FedoraprojectLinux+1 more
11Cloud Backup
Debian LinuxFedora+8 more
Jun 17, 2026
Nov 17, 2021
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a...Show more
In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value.Show less
2Fedoraproject
Schedmd
2Fedora
Slurm
Jun 17, 2026
Nov 17, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scrip...Show more
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.Show less
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function
2Busybox
Fedoraproject
2Busybox
Fedora
Jun 17, 2026
Nov 15, 2021
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used f...Show more
An attacker-controlled pointer free in Busybox's hush applet leads to denial of service and possible code execution when processing a crafted shell command, due to the shell mishandling the &&& string. This may be used for remote code execution under rare conditions of filtered command input.Show less
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare...Show more
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.Show less
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.5 MEDIUM· v3
1.9 LOW· v2
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be u...Show more
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.Show less
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.3 MEDIUM· v3
3.3 LOW· v2
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
3Busybox
FedoraprojectNetapp
12Busybox
Cloud BackupFedora+9 more
Jun 17, 2026
Nov 15, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
3Fedoraproject
NetappNpmjs
3Fedora
Next Generation Application Programming InterfaceNpm
Jun 17, 2026
Nov 13, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and m...Show more
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was supposed to have been blocked by an exact version match requirement in package-lock.json. NOTE: The npm team believes this is not a vulnerability. It would require someone to socially engineer package.json which has different dependencies than package-lock.json. That user would have to have file system or write access to change dependencies. The npm team states preventing malicious actors from socially engineering or gaining file system access is outside the scope of the npm CLI.Show less
2Fedoraproject
Xiph
2Fedora
Speex
Jun 17, 2026
Nov 10, 2021
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.