Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 9, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
2Fedoraproject Go Proxyproto Project2Fedora Go ProxyprotoJun 17, 2026 Mar 8, 2021 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Reader wrapping a net.Conn. It will read f...Show more |
2Fedoraproject Newlib Project2Fedora NewlibJun 17, 2026 Mar 5, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading t...Show more |
4Fedoraproject NetappOpenbsd+1 more9Cloud Backup Communications Offline Mediation ControllerFedora+6 moreJun 17, 2026 Mar 5, 2021 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-...Show more |
3Fedoraproject RedhatYtnef Project3Enterprise Linux FedoraYtnefJun 17, 2026 Mar 4, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ytnef 1.9.3, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a heap buffer overflow which can be triggered via a crafted file. |
3Fedoraproject RedhatYtnef Project3Enterprise Linux FedoraYtnefJun 17, 2026 Mar 4, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In ytnef 1.9.3, the TNEFSubjectHandler function in lib/ytnef.c allows remote attackers to cause a denial-of-service (and potentially code execution) due to a double free which can be triggered via a crafted file. |
3Fedoraproject LinuxRedhat5Enterprise Linux FedoraLinux Kernel+2 moreJun 17, 2026 Mar 4, 2021 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A NULL pointer dereference flaw was found in the Linux kernel's GPU Nouveau driver functionality in versions prior to 5.12-rc1 in the way the user calls ioctl DRM_IOCTL_NOUVEAU_CHANNEL_ALLOC. This flaw allows a local use...Show more |
3Cgal DebianFedoraproject3Computational Geometry Algorithms Library Debian LinuxFedoraJun 17, 2026 Mar 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->incident_sface. An at...Show more |
3Cgal DebianFedoraproject3Computational Geometry Algorithms Library Debian LinuxFedoraJun 17, 2026 Mar 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin() An attacker ca...Show more |
3Cgal DebianFedoraproject3Computational Geometry Algorithms Library Debian LinuxFedoraJun 17, 2026 Mar 4, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attac...Show more |
5Fedoraproject NetappNodejs+2 more13Active Iq Unified Manager E Series Performance AnalyzerFedora+10 moreJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to DNS rebinding attacks as the whitelist includes “localhost6”. When “localhost6” is not present in /etc/hosts, it is just an ordinary domain that is r...Show more |
5Fedoraproject NetappNodejs+2 more9E Series Performance Analyzer FedoraGraalvm+6 moreJun 17, 2026 Mar 3, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This leads to a leak of file descriptors. If...Show more |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Mar 3, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Mar 3, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet. |
2Fedoraproject Nextcloud2Fedora Nextcloud ServerJun 17, 2026 Mar 3, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured. |
2Fedoraproject Slic3r2Fedora Libslic3rJun 17, 2026 Mar 3, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosur...Show more |