Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject NetappOracle6Active Iq Unified Manager FedoraMysql+3 moreJun 17, 2026 Jan 20, 2021 N/A· v4 3.8 LOW· v3 5.5 MEDIUM· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with n...Show more |
3Debian FedoraprojectLibsdl3Debian Linux FedoraSimple Directmedia LayerJun 17, 2026 Jan 19, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file. |
4Debian FedoraprojectLibsdl+1 more4Debian Linux FedoraSimple Directmedia Layer+1 moreJun 17, 2026 Jan 19, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file. |
3Debian FedoraprojectMutt3Debian Linux FedoraMuttJun 17, 2026 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 rfc822.c in Mutt through 2.0.4 allows remote attackers to cause a denial of service (mailbox unavailability) by sending email messages with sequences of semicolon characters in RFC822 address fields (aka terminators of e...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Jan 19, 2021 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 fs/nfsd/nfs3xdr.c in the Linux kernel through 5.10.8, when there is an NFS export of a subdirectory of a filesystem, allows remote attackers to traverse to other parts of the filesystem via READDIRPLUS. NOTE: some partie...Show more |
5Debian FedoraprojectNetapp+2 more10Active Iq Unified Manager Communications Cloud Native Core Network Function Cloud Native EnvironmentCommunications Offline Mediation Controller+7 moreJun 17, 2026 Jan 19, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Python 3.x through 3.9.1 has a buffer overflow in PyCArg_repr in _ctypes/callproc.c, which may lead to remote code execution in certain Python applications that accept floating-point numbers as untrusted input, as demons...Show more |
4Debian DrupalFedoraproject+1 more4Archive Tar Debian LinuxDrupal+1 moreJun 17, 2026 Jan 18, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tar.php in Archive_Tar through 1.4.11 allows write operations with Directory Traversal due to inadequate checking of symbolic links, a related issue to CVE-2020-28948. |
2Erlang Fedoraproject2Erlang/otp FedoraJun 17, 2026 Jan 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority. |
2Coturn Project Fedoraproject2Coturn FedoraJun 17, 2026 Jan 13, 2021 N/A· v4 7.2 HIGH· v3 6.4 MEDIUM· v2 Coturn is free open source implementation of TURN and STUN Server. Coturn before version 4.5.2 by default does not allow peers to connect and relay packets to loopback addresses in the range of `127.x.x.x`. However, it w...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Jan 13, 2021 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an X...Show more |
2Fedoraproject Microsoft3Asp.net Core FedoraVisual Studio 2019Jun 17, 2026 Jan 12, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ASP.NET Core and Visual Studio Denial of Service Vulnerability |
3Fedoraproject M2crypto ProjectRedhat4Enterprise Linux FedoraM2crypto+1 moreJun 17, 2026 Jan 12, 2021 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in all released versions of m2crypto, where they are vulnerable to Bleichenbacher timing attacks in the RSA decryption API via the timed processing of valid PKCS#1 v1.5 Ciphertext. The highest threat fro...Show more |
3Fedoraproject NetappSudo Project4Fedora Hci Management NodeSolidfire+1 moreJun 17, 2026 Jan 12, 2021 N/A· v4 7.8 HIGH· v3 4.4 MEDIUM· v2 selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This aff...Show more |
4Debian FedoraprojectNetapp+1 more6Cloud Backup Debian LinuxFedora+3 moreJun 17, 2026 Jan 12, 2021 N/A· v4 2.5 LOW· v3 1.9 LOW· v2 The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symli...Show more |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Jan 12, 2021 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled. |
2Fedoraproject Python2Fedora PillowJun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode. |
3Debian FedoraprojectPython3Debian Linux FedoraPillowJun 17, 2026 Jan 12, 2021 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 In Pillow before 8.1.0, PcxDecode has a buffer over-read when decoding a crafted PCX file because the user-supplied stride value is trusted for buffer calculations. |
2Cacti Fedoraproject2Cacti FedoraJun 17, 2026 Jan 11, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to r...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jan 8, 2021 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jan 8, 2021 N/A· v4 9.6 CRITICAL· v3 6.8 MEDIUM· v2 User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. |