Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Fedoraproject RedhatTigervnc+1 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 moreJun 17, 2026 Jan 18, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that...Show more |
4Fedoraproject RedhatTigervnc+1 more12Enterprise Linux Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+9 moreJun 17, 2026 Jan 18, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry...Show more |
4Debian FedoraprojectRedhat+1 more7Debian Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreJun 17, 2026 Jan 18, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server wa...Show more |
3Couchbase FedoraprojectGoogle3Chrome Couchbase ServerFedoraJun 17, 2026 Jan 16, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
Out of bounds write in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
2Fedoraproject Rpm Software Management3Extra Packages For Enterprise Linux FedoraMockJun 17, 2026 Jan 16, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of p...Show more |
4Debian FedoraprojectGnu+1 more4Active Iq Unified Manager Debian LinuxFedora+1 moreJun 17, 2026 Jan 16, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This fla...Show more |
3Fedoraproject RedhatSqlite4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Jan 16, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the appl...Show more |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGnutlsJun 17, 2026 Jan 16, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote...Show more |
3Fedoraproject GnuRedhat3Enterprise Linux FedoraGrub2Jun 17, 2026 Jan 15, 2024 N/A· v4 6.8 MEDIUM· v3 N/A· v2 An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacke...Show more |
4Fedoraproject RedhatRelax And Recover+1 more4Enterprise Linux FedoraLinux Enterprise+1 moreJun 17, 2026 Jan 12, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJul 21, 2026 Jan 12, 2024 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_rel...Show more |
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severi...Show more |
Redis is an in-memory database that persists on disk. Redis incorrectly handles resizing of memory buffers which can result in integer overflow that leads to heap overflow and potential remote code execution. This issue...Show more |
3Fedoraproject FreeipaRedhat21Codeready Linux Builder Enterprise LinuxEnterprise Linux Desktop+18 moreJun 17, 2026 Jan 10, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the...Show more |
4Canonical FedoraprojectLinux+1 more4Enterprise Linux FedoraLinux Kernel+1 moreJun 17, 2026 Jan 8, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execut...Show more |
3Debian FedoraprojectJnunemaker3Debian Linux FedoraHttpartyJul 14, 2026 Jan 4, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could resu...Show more |
3Debian FedoraprojectLinux3Debian Linux FedoraLinux KernelJun 17, 2026 Jan 4, 2024 N/A· v4 7.0 HIGH· v3 N/A· v2 A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the...Show more |
Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |