← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectFirejail Project+1 more
4Debian Linux
FedoraFirejail+1 more
Jun 17, 2026
Aug 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
4Debian
FedoraprojectFirejail Project+1 more
4Debian Linux
FedoraFirejail+1 more
Jun 17, 2026
Aug 11, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
2F2fs Tools Project
Fedoraproject
2F2fs Tools
Fedora
Jun 17, 2026
Aug 10, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code...Show more
An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to trigger this vulnerability.Show less
7Apache
CanonicalDebian+4 more
25Communications Element Manager
Communications Session Report ManagerCommunications Session Route Manager+22 more
Jun 17, 2026
Aug 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Confi...Show more
Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers.Show less
7Apache
CanonicalDebian+4 more
13Clustered Data Ontap
Communications Element ManagerCommunications Session Report Manager+10 more
Jun 17, 2026
Aug 7, 2020
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory...Show more
Apache HTTP Server versions 2.4.20 to 2.4.43 When trace/debug was enabled for the HTTP/2 module and on certain traffic edge patterns, logging statements were made on the wrong connection, causing concurrent use of memory pools. Configuring the LogLevel of mod_http2 above "info" will mitigate this vulnerability for unpatched servers.Show less
7Apache
CanonicalDebian+4 more
13Clustered Data Ontap
Communications Element ManagerCommunications Session Report Manager+10 more
Jun 17, 2026
Aug 7, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache HTTP server 2.4.32 to 2.4.44 mod_proxy_uwsgi info disclosure and possible RCE
2Fedoraproject
Redhat
2Etcd
Fedora
Jun 17, 2026
Aug 6, 2020
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified i...Show more
In ectd before versions 3.4.10 and 3.3.23, gateway TLS authentication is only applied to endpoints detected in DNS SRV records. When starting a gateway, TLS authentication will only be attempted on endpoints identified in DNS SRV records for a given domain, which occurs in the discoverEndpoints function. No authentication is performed against endpoints provided in the --endpoints flag. This has been fixed in versions 3.4.10 and 3.3.23 with improved documentation and deprecation of the functionality.Show less
2Fedoraproject
Redhat
2Etcd
Fedora
Jun 17, 2026
Aug 6, 2020
N/A· v4
7.7 HIGH· v3
4.0 MEDIUM· v2
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a...Show more
In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descriptors to accept connections on the gateway.Show less
2Fedoraproject
Redhat
2Etcd
Fedora
Jun 17, 2026
Aug 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users'...Show more
etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.Show less
4Debian
FedoraprojectGolang+1 more
4Debian Linux
FedoraGo+1 more
Jun 17, 2026
Aug 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Go before 1.13.15 and 14.x before 1.14.7 can have an infinite read loop in ReadUvarint and ReadVarint in encoding/binary via invalid inputs.
2Etcd
Fedoraproject
2Etcd
Fedora
Jun 17, 2026
Aug 5, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients...Show more
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given directory path exists already. A possible workaround is to ensure the directories have the desired permission (700).Show less
2Etcd
Fedoraproject
2Etcd
Fedora
Jun 17, 2026
Aug 5, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during cons...Show more
In etcd before versions 3.3.23 and 3.4.10, it is possible to have an entry index greater then the number of entries in the ReadAll method in wal/wal.go. This could cause issues when WAL entries are being read during consensus as an arbitrary etcd consensus participant could go down from a runtime panic when reading the entry.Show less
2Etcd
Fedoraproject
2Etcd
Fedora
Jun 17, 2026
Aug 5, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on this data. Therefore,...Show more
In etcd before versions 3.3.23 and 3.4.10, a large slice causes panic in decodeRecord method. The size of a record is stored in the length field of a WAL file and no additional validation is done on this data. Therefore, it is possible to forge an extremely large frame size that can unintentionally panic at the expense of any RAFT participant trying to decode the WAL.Show less
4Debian
FedoraprojectLilypond+1 more
5Backports Sle
Debian LinuxFedora+2 more
Jun 17, 2026
Aug 5, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
4Canonical
FedoraprojectOpensuse+1 more
4Fedora
LeapLibx11+1 more
Jun 17, 2026
Aug 5, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM...Show more
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.Show less
5Canonical
DebianFedoraproject+2 more
5Ark
Debian LinuxFedora+2 more
Jun 17, 2026
Aug 3, 2020
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Aug 3, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.
7Canonical
DebianFedoraproject+4 more
15Active Iq Unified Manager
Cloud Volumes Ontap MediatorDebian Linux+12 more
Jun 17, 2026
Jul 30, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/ra...Show more
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.Show less
5Canonical
DebianFedoraproject+2 more
5Communications Cloud Native Core Policy
Debian LinuxFedora+2 more
Jun 17, 2026
Jul 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
libssh 0.9.4 has a NULL pointer dereference in tftpserver.c if ssh_buffer_new returns NULL.
2Claws Mail
Fedoraproject
2Claws Mail
Fedora
Jun 17, 2026
Jul 28, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.