Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian Djvulibre ProjectFedoraproject3Debian Linux DjvulibreFedoraJun 17, 2026 Jun 30, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An out-of-bounds write vulnerability was found in DjVuLibre in DJVU::DjVuTXT::decode() in DjVuText.cpp via a crafted djvu file which may lead to crash and segmentation fault. This flaw affects DjVuLibre versions prior to...Show more |
3Fedoraproject OraclePython5Enterprise Manager Ops Center FedoraInstantis Enterprisetrack+2 moreJun 17, 2026 Jun 29, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of...Show more |
3Debian DovecotFedoraproject3Debian Linux DovecotFedoraJun 17, 2026 Jun 28, 2021 N/A· v4 4.8 MEDIUM· v3 5.8 MEDIUM· v2 The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address. |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Jun 28, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Sieve engine in Dovecot before 2.3.15 allows Uncontrolled Resource Consumption, as demonstrated by a situation with a complex regular expression for the regex extension. |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Jun 28, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during...Show more |
2Fedoraproject Thephpleague2Fedora FlysystemJun 17, 2026 Jun 24, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 Flysystem is an open source file storage library for PHP. The whitespace normalisation using in 1.x and 2.x removes any unicode whitespace. Under certain specific conditions this could potentially allow a malicious user...Show more |
3Debian FedoraprojectGoogle3Android Debian LinuxFedoraJun 17, 2026 Jun 22, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges ne...Show more |
2Fedoraproject Mpmath2Fedora MpmathJun 17, 2026 Jun 21, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called. |
3Debian FedoraprojectGdraheim3Debian Linux FedoraZziplibJun 17, 2026 Jun 18, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file". |
2Fedoraproject Quassel Irc2Fedora QuasselJun 17, 2026 Jun 17, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system. |
2Fedoraproject Phpmailer Project2Fedora PhpmailerJun 17, 2026 Jun 17, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddre...Show more |
2Fedoraproject Phpmailer Project2Fedora PhpmailerJun 17, 2026 Jun 16, 2021 N/A· v4 8.1 HIGH· v3 5.1 MEDIUM· v2 PHPMailer before 6.5.0 on Windows allows remote code execution if lang_path is untrusted data and has a UNC pathname. |
5Apache DebianFedoraproject+2 more6Communications Messaging Server Debian LinuxFedora+3 moreJun 17, 2026 Jun 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Network service in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Type confusion in V8 in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Loader in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more4Chrome Debian LinuxFedora+1 moreJun 17, 2026 Jun 15, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. |