Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apache FedoraprojectOracle5Enterprise Manager Ops Center FedoraHttp Server+2 moreJun 17, 2026 Jun 10, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Apache HTTP Server versions 2.4.6 to 2.4.46 mod_proxy_wstunnel configured on an URL that is not necessarily Upgraded by the origin server was tunneling the whole connection regardless, thus allowing for subsequent reques...Show more |
3Debian FedoraprojectIntel7Celeron Processors Firmware Core Processors FirmwareDebian Linux+4 moreJun 17, 2026 Jun 9, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. |
2Fedoraproject Intel7Brand Verification Tool Celeron Processors FirmwareCore Processors Firmware+4 moreJun 17, 2026 Jun 9, 2021 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. |
2Fedoraproject Tiangolo2Fastapi FedoraJun 17, 2026 Jun 9, 2021 N/A· v4 8.1 HIGH· v3 5.8 MEDIUM· v2 FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cookies for authentication in path operations that received JSON payloads se...Show more |
4Ckeditor DebianDrupal+1 more4Ckeditor Debian LinuxDrupal+1 moreJun 17, 2026 Jun 9, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross-site scripting (XSS) vulnerability in the HTML Data Processor in CKEditor 4 4.14.0 through 4.16.x before 4.16.1 allows remote attackers to inject executable JavaScript code through a crafted comment because --!>...Show more |
5Arm BroadcomFedoraproject+2 more8Bcm2711 Core I7 10700kCore I7 7700k+5 moreJun 17, 2026 Jun 9, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect...Show more |
2Fedoraproject Microsoft4.net .net CoreFedora+1 moreJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ASP.NET Core Denial of Service Vulnerability |
3Fedoraproject NetappSquid Cache3Cloud Manager FedoraSquidJun 17, 2026 Jun 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. An integer overflow problem allows a remote server to achieve Denial of Service when delivering responses to HTTP Range requests. The issue trigger is a...Show more |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of...Show more |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 Jun 8, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary fi...Show more |
2Fedoraproject Ntpsec2Fedora NtpsecJun 17, 2026 Jun 8, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shortens the key, or fails to load these keys entirely, depending on the ke...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Jun 8, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This...Show more |
3Debian FedoraprojectOpenexr3Debian Linux FedoraOpenexrJun 17, 2026 Jun 8, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different...Show more |
3Debian FedoraprojectOpenexr3Debian Linux FedoraOpenexrJun 17, 2026 Jun 8, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. |
2Fedoraproject Openexr2Fedora OpenexrJun 17, 2026 Jun 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application...Show more |
4Debian FedoraprojectGnupg+1 more8Communications Cloud Native Core Binding Support Function Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Cloud Native Core Network Repository Function+5 moreJun 17, 2026 Jun 8, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for...Show more |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page. |
2Fedoraproject Google2Chrome FedoraJun 17, 2026 Jun 7, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page. |