Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 May 14, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value. |
2Fedoraproject Virustotal2Fedora YaraJun 17, 2026 May 14, 2021 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 An integer overflow and several buffer overflow reads in libyara/modules/macho/macho.c in YARA v4.0.3 and earlier could allow an attacker to either cause denial of service or information disclosure via a malicious Mach-O...Show more |
A heap buffer overflow read was discovered in upx 4.0.0, because the check in p_lx_elf.cpp is not perfect. |
6Debian FedoraprojectNetapp+3 more19Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+16 moreJun 17, 2026 May 14, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability found in libxml2 in versions before 2.9.11 shows that it did not propagate errors while parsing XML mixed content, causing a NULL dereference. If an untrusted XML document was parsed in recovery mode and...Show more |
3Fedoraproject ImagemagickRedhat3Enterprise Linux Desktop FedoraImagemagickJun 17, 2026 May 14, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c. |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 May 14, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS. |
2Fedoraproject Pydantic2Fedora PydanticJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes vali...Show more |
2Exiv2 Fedoraproject2Exiv2 FedoraJun 17, 2026 May 13, 2021 N/A· v4 3.3 LOW· v3 4.3 MEDIUM· v2 Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a comma...Show more |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. It does not use a constant-time algorithm for comparing certain secret strings when running under Lua 5.2 or later. This can potentially be used in a timing attack to rev...Show more |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests. |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate...Show more |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3. |
3Debian FedoraprojectProsody3Debian Linux FedoraProsodyJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandw...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 May 13, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether th...Show more |
3Debian FedoraprojectUclouvain3Debian Linux FedoraOpenjpegJun 17, 2026 May 13, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integr...Show more |
3Debian FedoraprojectLibrdf3Debian Linux FedoraRaptor Rdf Syntax LibraryJun 17, 2026 May 13, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 13, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in OpenJPEG’s encoder in the opj_dwt_calc_explicit_stepsizes() function. This flaw allows an attacker who can supply crafted input to decomposition levels to cause a buffer overflow. The highest threat f...Show more |
2C Ares Fedoraproject2C Ares FedoraJun 17, 2026 May 13, 2021 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 A possible use-after-free and double-free in c-ares lib version 1.16.0 if ares_destroy() is called prior to ares_getaddrinfo() completing. This flaw possibly allows an attacker to crash the service that uses c-ares lib....Show more |
3Debian FedoraprojectSchedmd3Debian Linux FedoraSlurmJun 17, 2026 May 13, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SchedMD Slurm before 20.02.7 and 20.03.x through 20.11.x before 20.11.7 allows remote code execution as SlurmUser because use of a PrologSlurmctld or EpilogSlurmctld script leads to environment mishandling. |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 May 12, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with...Show more |