Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject LibreofficeOpensuse3Fedora LeapLibreofficeJun 17, 2026 Jun 8, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 ODF documents can contain forms to be filled out by the user. Similar to HTML forms, the contained form data can be submitted to a URI, for example, to an external web server. To create submittable forms, ODF implements...Show more |
3Fedoraproject LibreofficeOpensuse3Fedora LeapLibreofficeJun 17, 2026 Jun 8, 2020 N/A· v4 5.3 MEDIUM· v3 4.3 MEDIUM· v2 LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreO...Show more |
6Debian FedoraprojectNetapp+3 more12Cloud Backup Communications Messaging ServerCommunications Network Charging And Control+9 moreJun 17, 2026 Jun 6, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 SQLite 3.32.2 has a use-after-free in resetAccumulator in select.c because the parse tree rewrite for window functions is too late. |
2Fedoraproject Targetcli Fb Project2Fedora Targetcli FbJun 17, 2026 Jun 5, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files). |
2Fedoraproject Kubernetes2Fedora KubernetesJun 17, 2026 Jun 5, 2020 N/A· v4 6.3 MEDIUM· v3 3.5 LOW· v2 The Kubernetes kube-controller-manager in versions v1.0-1.14, versions prior to v1.15.12, v1.16.9, v1.17.5, and version v1.18.0 are vulnerable to a Server Side Request Forgery (SSRF) that allows certain authorized users...Show more |
5Fedoraproject NetappOpensuse+2 more16Communications Billing And Revenue Management Communications Diameter Signaling RouterCommunications Eagle Application Processor+13 moreJun 17, 2026 Jun 5, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls. |
5Fedoraproject NetappOpensuse+2 more17Communications Billing And Revenue Management Communications Diameter Signaling RouterCommunications Eagle Application Processor+14 moreJun 17, 2026 Jun 5, 2020 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection. |
4Fedoraproject OpensuseOracle+1 more15Communications Billing And Revenue Management Communications Diameter Signaling RouterCommunications Eagle Application Processor+12 moreJun 17, 2026 Jun 5, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow. |
5Debian FedoraprojectNetapp+2 more5Debian Linux FedoraPostgresql Jdbc Driver+2 moreJun 17, 2026 Jun 4, 2020 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraGnutls+1 moreJun 17, 2026 Jun 4, 2020 N/A· v4 7.4 HIGH· v3 5.8 MEDIUM· v2 GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24)...Show more |
6Debian FedoraprojectNghttp2+3 more10Banking Extensibility Workbench Blockchain PlatformDebian Linux+7 moreJun 17, 2026 Jun 3, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 byt...Show more |
4Fedoraproject GrafanaNetapp+1 more5Backports Sle E Series Performance AnalyzerFedora+2 moreJun 17, 2026 Jun 3, 2020 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result...Show more |
6Canonical DebianDjangoproject+3 more7Debian Linux DjangoFedora+4 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack. |
6Canonical DebianDjangoproject+3 more7Debian Linux DjangoFedora+4 moreJun 17, 2026 Jun 3, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential da...Show more |
3Fedoraproject LinuxfoundationRedhat4Cni Network Plugins Enterprise LinuxFedora+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.0 MEDIUM· v3 6.0 MEDIUM· v2 A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container ca...Show more |
3Fedoraproject NetappSystemd Project4Active Iq Unified Manager FedoraSolidfire & Hci Management Node+1 moreJun 17, 2026 Jun 3, 2020 N/A· v4 6.7 MEDIUM· v3 6.2 MEDIUM· v2 systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. N...Show more |
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network. |
4Broadcom DebianDocker+1 more4Debian Linux EngineFedora+1 moreJun 17, 2026 Jun 2, 2020 N/A· v4 6.0 MEDIUM· v3 6.0 MEDIUM· v2 An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive in...Show more |
3Canonical FedoraprojectPython Rsa Project3Fedora Python RsaUbuntu LinuxJun 17, 2026 Jun 1, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if t...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Jun 1, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A NULL pointer dereference in sanei_epson_net_read in SANE Backends before 1.0.30 allows a malicious device connected to the same local network as the victim to cause a denial of service, aka GHSL-2020-075. |