Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Feb 12, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in alloc_targets) allocate more than INT_MAX bytes, and crash, because of a missing check for struct dm_ioctl.target_count. |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Feb 11, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stac...Show more |
3Fedoraproject RedhatX.org8Enterprise Linux Enterprise Linux AusEnterprise Linux Eus+5 moreJun 17, 2026 Feb 9, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 An out-of-bounds memory access flaw was found in the X.Org server. This issue can be triggered when a device frozen by a sync grab is reattached to a different master device. This issue may lead to an application crash,...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Feb 8, 2024 N/A· v4 4.7 MEDIUM· v3 N/A· v2 A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same time with a fail in the mas_prev_slot function. This issue could allow a local user to crash the sy...Show more |
2Cisco Fedoraproject3Fedora Secure EndpointSecure Endpoint Private CloudJun 17, 2026 Feb 7, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect ch...Show more |
Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGrub2Jun 17, 2026 Feb 6, 2024 N/A· v4 3.3 LOW· v3 N/A· v2 A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If th...Show more |
2Fedoraproject Redhat6Ansible Ansible Automation PlatformAnsible Developer+3 moreJun 17, 2026 Feb 6, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. D...Show more |
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions. |
2Fedoraproject Linuxfoundation2Fedora RuncJul 20, 2026 Jan 31, 2024 N/A· v4 8.6 HIGH· v3 N/A· v2 runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. In runc 1.1.11 and earlier, due to an internal file descriptor leak, an attacker could cause a newly-spawned container p...Show more |
An integer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called with a very long messa...Show more |
An off-by-one heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when these functions are called w...Show more |
A heap-based buffer overflow was found in the __vsyslog_internal function of the glibc library. This function is called by the syslog and vsyslog functions. This issue occurs when the openlog function was not called, or...Show more |
5Debian FedoraprojectLinux+2 more12500f Firmware A250 FirmwareC250 Firmware+9 moreJun 17, 2026 Jan 31, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the...Show more |
Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High) |
Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High) |
2Aiohttp Fedoraproject2Aiohttp FedoraJun 17, 2026 Jan 29, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. Security-sensitive parts of the Python HTTP parser retained minor differences in allowable character sets, that must trigger error handling...Show more |
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python. When using aiohttp as a web server and configuring static routes, it is necessary to specify the root path for static files. Additionally, t...Show more |