Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Mar 20, 2021 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-cha...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLinux Kernel+1 moreJun 17, 2026 Mar 20, 2021 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and o...Show more |
3Fedoraproject LinuxNetapp7A250 Firmware Aff 500f FirmwareCloud Backup+4 moreJun 17, 2026 Mar 20, 2021 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been...Show more |
3Fedoraproject LinuxNetapp7A250 Firmware Aff 500f FirmwareCloud Backup+4 moreJun 17, 2026 Mar 20, 2021 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL t...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Mar 20, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1. |
3Fedoraproject Http Proxy Agent ProjectRedhat4Enterprise Linux FedoraHttp Proxy Agent+1 moreJun 17, 2026 Mar 19, 2021 N/A· v4 9.8 CRITICAL· v3 9.0 HIGH· v2 A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service throu...Show more |
3Apache FedoraprojectOracle19Banking Corporate Lending Process Management Banking Credit Facilities Process ManagementBanking Supply Chain Finance+16 moreJun 17, 2026 Mar 19, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. |
3Apache FedoraprojectOracle15Banking Trade Finance Process Management Banking Treasury ManagementBanking Virtual Account Management+12 moreJun 17, 2026 Mar 19, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions. |
3Debian FedoraprojectKramdown Project3Debian Linux FedoraKramdownJun 17, 2026 Mar 19, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated. |
3Busybox DebianFedoraproject3Busybox Debian LinuxFedoraJun 17, 2026 Mar 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data. |
2Fedoraproject Torproject2Fedora TorJun 17, 2026 Mar 19, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002. |
2Fedoraproject Torproject2Fedora TorJun 17, 2026 Mar 19, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001. |
4Debian FedoraprojectNetapp+1 more4Cloud Manager Debian LinuxFedora+1 moreJun 17, 2026 Mar 19, 2021 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security...Show more |
4Debian FedoraprojectQemu+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 18, 2021 N/A· v4 6.0 MEDIUM· v3 2.1 LOW· v2 A potential stack overflow via infinite loop issue was found in various NIC emulators of QEMU in versions up to and including 5.2.0. The issue occurs in loopback mode of a NIC wherein reentrant DMA checks get bypassed. A...Show more |
2Fedoraproject Mediaarea2Fedora MediainfoJun 17, 2026 Mar 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping. |
5Fedoraproject Lldpd ProjectOpenvswitch+2 more17Enterprise Linux FedoraLldpd+14 moreJun 17, 2026 Mar 18, 2021 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest...Show more |
4Debian FedoraprojectLinux+1 more12Cloud Backup Debian LinuxFedora+9 moreJun 17, 2026 Mar 17, 2021 N/A· v4 8.8 HIGH· v3 8.3 HIGH· v2 rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not...Show more |
3Debian FedoraprojectPygments3Debian Linux FedoraPygmentsJun 17, 2026 Mar 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to...Show more |
2Fedoraproject Gnome2Fedora Gnome AutoarJun 17, 2026 Mar 17, 2021 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 autoar-extractor.c in GNOME gnome-autoar before 0.3.1, as used by GNOME Shell, Nautilus, and other software, allows Directory Traversal during extraction because it lacks a check of whether a file's parent is a symlink i...Show more |
2Fedoraproject Varnish Cache3Fedora Varnish ModulesVarnish Modules KlarlackJun 17, 2026 Mar 16, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however,...Show more |