Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Barton DebianFedoraproject3Debian Linux FedoraNgircdJun 17, 2026 Jun 15, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function. |
2Fedoraproject Libemf Project2Fedora LibemfJun 17, 2026 Jun 15, 2020 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file. |
6Canonical FedoraprojectIntel+3 more694Celeron 1000m Celeron 1005mCeleron 1007u+691 moreJun 17, 2026 Jun 15, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 3.1 LOW· v3 6.0 MEDIUM· v2 In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once in...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 2.4 LOW· v3 3.5 LOW· v2 In affected versions of WordPress, when uploading themes, the name of the theme folder can be crafted in a way that could lead to JavaScript execution in /wp-admin on the themes page. This does require an admin to upload...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 5.7 MEDIUM· v3 4.9 MEDIUM· v2 In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in vers...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 6.8 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the...Show more |
3Debian FedoraprojectWordpress3Debian Linux FedoraWordpressJun 17, 2026 Jun 12, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a hig...Show more |
5Canonical DebianFedoraproject+2 more5Android Debian LinuxFedora+2 moreJun 17, 2026 Jun 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is n...Show more |
3Fedoraproject GoogleLibexif Project3Android FedoraLibexifJun 17, 2026 Jun 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interact...Show more |
2Fedoraproject Katacontainers2Fedora RuntimeJun 17, 2026 Jun 10, 2020 N/A· v4 8.8 HIGH· v3 4.6 MEDIUM· v2 A malicious guest compromised before a container creation (e.g. a malicious guest image or a guest running multiple containers) can trick the kata runtime into mounting the untrusted container filesystem on any host path...Show more |
2Fedoraproject Nagios2Fedora NagiosJun 17, 2026 Jun 9, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, o...Show more |
7Canonical DebianFedoraproject+4 more10Active Iq Unified Manager Cloud BackupDebian Linux+7 moreJun 17, 2026 Jun 9, 2020 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system. |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Jun 9, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. |
3Debian FedoraprojectRoundcube3Debian Linux FedoraWebmailJun 17, 2026 Jun 9, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. include/rcmail_output_html.php allows XSS via the username template object. |
4Fedoraproject MumbleOpensuse+1 more4Fedora LeapMumble+1 moreJun 17, 2026 Jun 9, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS s...Show more |
2Fedoraproject Gnome2Fedora NetworkmanagerJun 17, 2026 Jun 8, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the...Show more |
5Canonical DebianFedoraproject+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Jun 8, 2020 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. T...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhpmailer+1 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 PHPMailer before 6.1.6 contains an output escaping bug when the name of a file attachment contains a double quote character. This can result in the file type being misinterpreted by the receiver or any mail relay process...Show more |
21Asus BroadcomCanon+18 more2175020 Z4a69a 5030 M2u92b5030 Z4a70a+214 moreJun 17, 2026 Jun 8, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscriptio...Show more |