Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Apache FasterxmlFedoraproject+3 more39Agile Plm Agile Product Lifecycle Management Integration PackBanking Apis+36 moreJun 17, 2026 Dec 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is...Show more |
2Fedoraproject Webkitgtk2Fedora WebkitgtkJun 17, 2026 Dec 3, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs t...Show more |
3Debian FedoraprojectLinuxfoundation3Containerd Debian LinuxFedoraJun 17, 2026 Dec 1, 2020 N/A· v4 5.2 MEDIUM· v3 3.6 LOW· v2 containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network contai...Show more |
2Audacityteam Fedoraproject2Audacity FedoraJun 17, 2026 Nov 30, 2020 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 Audacity through 2.3.3 saves temporary files to /var/tmp/audacity-$USER by default. After Audacity creates the temporary directory, it sets its permissions to 755. Any user on the system can read and play the temporary a...Show more |
3Debian FedoraprojectLibslirp Project3Debian Linux FedoraLibslirpJun 17, 2026 Nov 26, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. |
3Debian FedoraprojectLibslirp Project3Debian Linux FedoraLibslirpJun 17, 2026 Nov 26, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length. |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 6.3 MEDIUM· v3 5.4 MEDIUM· v2 A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly r...Show more |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local gu...Show more |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 26, 2020 N/A· v4 6.4 MEDIUM· v3 3.3 LOW· v2 A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from othe...Show more |
3Debian FedoraprojectX11vnc Project3Debian Linux FedoraX11vncJun 17, 2026 Nov 25, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user. |
3Debian FedoraprojectSpice Space3Debian Linux FedoraSpice VdagentJun 17, 2026 Nov 25, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/...Show more |
4Debian FedoraprojectMusl Libc+1 more4Debian Linux FedoraGraalvm+1 moreJun 17, 2026 Nov 24, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow). |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Nov 24, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federa...Show more |
2Fedoraproject Redhat4Ceph Ceph StorageFedora+1 moreJun 17, 2026 Nov 23, 2020 N/A· v4 8.8 HIGH· v3 5.8 MEDIUM· v2 A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows a...Show more |
2Fedoraproject Xpdfreader2Fedora XpdfJun 17, 2026 Nov 21, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Xpdf 4.02, SplashOutputDev::endType3Char(GfxState *state) SplashOutputDev.cc:3079 is trying to use the freed `t3GlyphStack->cache`, which causes an `heap-use-after-free` problem. The codes of a previous fix for nested...Show more |
3Debian FedoraprojectPdfresurrect Project3Debian Linux FedoraPdfresurrectJun 17, 2026 Nov 20, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version(). |
3Debian FedoraprojectLibvips3Debian Linux FedoraLibvipsJun 17, 2026 Nov 20, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address. |
2Drupal Fedoraproject2Drupal FedoraJun 17, 2026 Nov 20, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting co...Show more |
3Fedoraproject IbmOracle6Aix Communications Cloud Native Core Binding Support FunctionCommunications Cloud Native Core Network Exposure Function+3 moreJun 17, 2026 Nov 20, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296. |
2Fedoraproject Rclone2Fedora RcloneJun 17, 2026 Nov 19, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords...Show more |