Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectFlatpak3Debian Linux FedoraFlatpakJun 17, 2026 Mar 11, 2021 N/A· v4 8.2 HIGH· v3 5.8 MEDIUM· v2 Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which ca...Show more |
2Fedoraproject Golang2Fedora GoJun 17, 2026 Mar 11, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename. |
2Fedoraproject Linuxfoundation2Containerd FedoraJun 17, 2026 Mar 10, 2021 N/A· v4 6.3 MEDIUM· v3 4.3 MEDIUM· v2 In containerd (an industry-standard container runtime) before versions 1.3.10 and 1.4.4, containers launched through containerd's CRI implementation (through Kubernetes, crictl, or any other pod/container client that use...Show more |
33mf DebianFedoraproject3Debian Linux FedoraLib3mfJun 17, 2026 Mar 10, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious...Show more |
2Fedoraproject Libjpeg Turbo2Fedora Libjpeg TurboJun 17, 2026 Mar 10, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image. |
3Debian FedoraprojectSquid Cache3Debian Linux FedoraSquidJun 17, 2026 Mar 9, 2021 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution a...Show more |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraGit+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Git is an open-source distributed revision control system. In affected versions of Git a specially crafted repository that contains symbolic links as well as files using a clean/smudge filter such as Git LFS, may cause j...Show more |
5Debian FedoraprojectLibtiff+2 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Mar 9, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerabi...Show more |
4Fedoraproject LibtiffNetapp+1 more4Enterprise Linux FedoraLibtiff+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In LibTIFF, there is a memory malloc failure in tif_pixarlog.c. A crafted TIFF document can lead to an abort, resulting in a remote denial of service attack. |
4Fedoraproject LibtiffNetapp+1 more4Enterprise Linux FedoraLibtiff+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service. |
4Debian FedoraprojectImagemagick+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat...Show more |
4Debian FedoraprojectImagemagick+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from thi...Show more |
4Debian FedoraprojectImagemagick+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Mar 9, 2021 N/A· v4 5.5 MEDIUM· v3 7.1 HIGH· v2 A flaw was found in ImageMagick in MagickCore/visual-effects.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest t...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Uninitialized data in PDFium in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in payments in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in URL formatting in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in QR scanning in Google Chrome on iOS prior to 89.0.4389.72 allowed an attacker who convinced the user to scan a QR code to bypass navigation restrictions via a crafted QR code. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extensio...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. |