Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PCI devices can make use of a functionality called phantom functions, that when enabled allows the device to generate requests using the IDs of functions that are otherwise unpopulated. This allows a device to extend th...Show more |
3Fedoraproject Libdwarf ProjectRedhat3Enterprise Linux FedoraLibdwarfJun 17, 2026 Mar 18, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results. |
3Apache DebianFedoraproject3Debian Linux FedoraTomcatJun 17, 2026 Mar 13, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated H...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraTomcatJun 17, 2026 Mar 13, 2024 N/A· v4 6.3 MEDIUM· v3 N/A· v2 Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat...Show more |
Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
2Broadcom Fedoraproject2Fedora TcpreplayJun 17, 2026 Mar 12, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command. |
3Fedoraproject Libexpat ProjectNetapp14Active Iq Unified Manager FedoraH300s Firmware+11 moreJun 17, 2026 Mar 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate). |
WeasyPrint helps web developers to create PDF documents. Since version 61.0, there's a vulnerability which allows attaching content of arbitrary files and URLs to a generated PDF document, even if `url_fetcher` is config...Show more |
2Fedoraproject Go Jose Project2Fedora Go JoseJun 17, 2026 Mar 9, 2024 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when deco...Show more |
2Fedoraproject Jose Project2Fedora JoseJun 17, 2026 Mar 9, 2024 N/A· v4 5.9 MEDIUM· v3 N/A· v2 jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A...Show more |
4Apple FedoraprojectWebkitgtk+1 more10Fedora IpadosIphone Os+7 moreJun 17, 2026 Mar 8, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing...Show more |
4Apple FedoraprojectWebkitgtk+1 more9Fedora Ipad OsIphone Os+6 moreJun 17, 2026 Mar 8, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprin...Show more |
4Apple FedoraprojectWebkitgtk+1 more10Fedora IpadosIphone Os+7 moreJun 17, 2026 Mar 8, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing malic...Show more |
4Apple FedoraprojectWebkitgtk+1 more10Fedora Ipad OsIphone Os+7 moreJun 17, 2026 Mar 8, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cro...Show more |
2Fedoraproject Pgadmin2Fedora Pgadmin 4Jun 17, 2026 Mar 7, 2024 N/A· v4 9.9 CRITICAL· v3 N/A· v2 pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize rem...Show more |
NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature...Show more |
Use after free in FedCM in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Inappropriate implementation in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Out of bounds memory access in V8 in Google Chrome prior to 122.0.6261.111 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) |
3Fedoraproject NetappSquid Cache3Bluexp FedoraSquidJun 17, 2026 Mar 6, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allow...Show more |