Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Kubernetes2Fedora KubernetesJun 17, 2026 Mar 27, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests. |
2Fedoraproject Kubernetes2Fedora KubernetesJun 17, 2026 Mar 27, 2020 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typica...Show more |
2Fedoraproject Mozilla2Bleach FedoraJun 17, 2026 Mar 24, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False. |
2Fedoraproject Mozilla2Bleach FedoraJun 17, 2026 Mar 24, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option. |
3Arm DebianFedoraproject4Debian Linux FedoraMbed Crypto+1 moreJun 17, 2026 Mar 24, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import. |
4Fedoraproject OpensuseOracle+1 more4Communications Cloud Native Core Network Function Cloud Native Environment FedoraLeap+1 moreJun 17, 2026 Mar 24, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability was discovered in the PyYAML library in versions before 5.3.1, where it is susceptible to arbitrary code execution when it processes untrusted YAML files through the full_load method or with the FullLoade...Show more |
3Debian FedoraprojectKde3Debian Linux FedoraOkularJun 17, 2026 Mar 24, 2020 N/A· v4 5.3 MEDIUM· v3 6.8 MEDIUM· v2 KDE Okular before 1.10.0 allows code execution via an action link in a PDF document. |
3Debian FedoraprojectRedhat5Ansible Ansible TowerDebian Linux+2 moreJun 17, 2026 Mar 24, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled,...Show more |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Inappropriate implementation in V8 in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more4Backports ChromeDebian Linux+1 moreJun 17, 2026 Mar 23, 2020 N/A· v4 5.4 MEDIUM· v3 5.8 MEDIUM· v2 Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
5Debian FedoraprojectGoogle+2 more6Backports Sle ChromeDebian Linux+3 moreJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Use after free in WebGL in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Mar 23, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page. |
5Debian FedoraprojectOpensuse+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Mar 22, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.ph...Show more |
5Debian FedoraprojectOpensuse+2 more6Backports Sle Debian LinuxFedora+3 moreJun 17, 2026 Mar 22, 2020 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/cla...Show more |
4Fedoraproject OpensusePhpmyadmin+1 more5Backports Sle FedoraLeap+2 moreJun 17, 2026 Mar 22, 2020 N/A· v4 8.0 HIGH· v3 6.0 MEDIUM· v2 In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A mal...Show more |