Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Pikepdf Project2Fedora PikepdfJun 17, 2026 Apr 1, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 models/metadata.py in the pikepdf package 1.3.0 through 2.9.2 for Python allows XXE when parsing XMP metadata entries. |
2Fedoraproject Redhat3Ansible Ansible TowerFedoraJun 17, 2026 Apr 1, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in several ansible modules, where parameters containing credentials, such as secrets, were being logged in plain-text on managed nodes, as well as being made visible on the controller node when run in ve...Show more |
8Broadcom DebianFedoraproject+5 more11Communications Billing And Revenue Management Debian LinuxEssbase+8 moreJun 17, 2026 Apr 1, 2021 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confus...Show more |
8Broadcom DebianFedoraproject+5 more12Communications Billing And Revenue Management Debian LinuxEssbase+9 moreJun 17, 2026 Apr 1, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 curl 7.1.1 to and including 7.75.0 is vulnerable to an "Exposure of Private Personal Information to an Unauthorized Actor" by leaking credentials in the HTTP Referer: header. libcurl does not strip off user credentials f...Show more |
3Fedoraproject RedhatStorage Project4Enterprise Linux FedoraOpenshift Container Platform+1 moreJun 17, 2026 Apr 1, 2021 N/A· v4 6.5 MEDIUM· v3 7.1 HIGH· v2 A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archiv...Show more |
5Apache EclipseFedoraproject+2 more23Autovue For Agile Product Lifecycle Management Banking ApisBanking Digital Experience+20 moreJun 17, 2026 Apr 1, 2021 N/A· v4 2.7 LOW· v3 4.0 MEDIUM· v2 In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadverte...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Mar 30, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.11.11. The netfilter subsystem allows attackers to cause a denial of service (panic) because net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a ful...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Mar 30, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak, related to a lack of cleanup steps in kernel/usermode_driver.c and kernel/bpf/preload/bpf_preload_k...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Mar 30, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF), which ca...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Mar 30, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Mar 30, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes, aka CID-0217ed2848e8. |
4Debian FedoraprojectTenable+1 more4Debian Linux FedoraTenable.sc+1 moreJun 17, 2026 Mar 29, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Mar 26, 2021 N/A· v4 6.1 MEDIUM· v3 2.6 LOW· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails se...Show more |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Mar 26, 2021 N/A· v4 8.2 HIGH· v3 4.3 MEDIUM· v2 Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset endpoin...Show more |
4Fedoraproject RedhatRpm+1 more4Enterprise Linux FedoraRpm+1 moreJun 17, 2026 Mar 26, 2021 N/A· v4 7.0 HIGH· v3 5.1 MEDIUM· v2 A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified,...Show more |
2Fedoraproject Jasper Project2Fedora JasperJun 17, 2026 Mar 25, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder. A specially crafted JP2 image file could cause an application u...Show more |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraLibmicrohttpdJun 17, 2026 Mar 25, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd....Show more |
3Fedoraproject Libtpms ProjectRedhat3Enterprise Linux FedoraLibtpmsJun 17, 2026 Mar 25, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were...Show more |
3Fedoraproject Jasper ProjectRedhat3Enterprise Linux FedoraJasperJun 17, 2026 Mar 25, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jas...Show more |
10Fedoraproject FreebsdMcafee+7 more33Capture Client Cloud Volumes Ontap MediatorCommerce Guided Search+30 moreJun 17, 2026 Mar 25, 2021 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain. It is not set by default. Starting from OpenSSL version 1.1.1h a check to disallow certificates in t...Show more |