Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectSamba3Debian Linux FedoraSambaJun 17, 2026 May 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a...Show more |
3Debian FedoraprojectSamba3Debian Linux FedoraSambaJun 17, 2026 May 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest thr...Show more |
3Debian FedoraprojectRedhat4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 11, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which w...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 May 11, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST sup...Show more |
2Fedoraproject Microsoft4.net .net CoreFedora+1 moreJun 17, 2026 May 11, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 .NET and Visual Studio Elevation of Privilege Vulnerability |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 May 11, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify co...Show more |
3Fedoraproject NetappSystemd Project4Active Iq Unified Manager Cloud BackupFedora+1 moreJun 17, 2026 May 10, 2021 N/A· v4 6.1 MEDIUM· v3 2.9 LOW· v2 An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can...Show more |
2Cyrus Fedoraproject2Fedora ImapJun 17, 2026 May 10, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cyrus IMAP before 3.2.7, and 3.3.x and 3.4.x before 3.4.1, allows remote authenticated users to bypass intended access restrictions on server annotations and consequently cause replication to stall. |
2Eventlet Fedoraproject2Eventlet FedoraJun 17, 2026 May 7, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Eventlet is a concurrent networking library for Python. A websocket peer may exhaust memory on Eventlet side by sending very large websocket frames. Malicious peer may exhaust memory on Eventlet side by sending highly co...Show more |
2Djangoproject Fedoraproject2Django FedoraJun 17, 2026 May 6, 2021 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with new...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 May 6, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecti...Show more |
2Aomedia Fedoraproject2Aomedia FedoraJun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap. |
3Debian FedoraprojectGetdata Project3Debian Linux FedoraGetdataJun 17, 2026 May 6, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party...Show more |
4Fedoraproject LinuxNetapp+1 more19Cloud Backup Enterprise LinuxEnterprise Linux For Real Time+16 moreJun 17, 2026 May 6, 2021 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-boun...Show more |
2Fedoraproject Osgeo2Fedora MapserverJun 17, 2026 May 6, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to contr...Show more |
3Debian DjangoprojectFedoraproject3Debian Linux DjangoFedoraJun 17, 2026 May 5, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 5, 2021 N/A· v4 6.8 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in samba. The Samba smbd file server must map Windows group identities (SIDs) into unix group ids (gids). The code that performs this had a flaw that could allow it to read data beyond the end of the arr...Show more |
2Fedoraproject Secureauth2Fedora ImpacketJun 17, 2026 May 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This...Show more |
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attack...Show more |
2Fedoraproject Redislabs2Fedora RedisJun 17, 2026 May 4, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentia...Show more |