Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Oct 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Exten...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Oct 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical) |
3Fedoraproject GolangNetapp5Astra Trident Astra Trident AutosupportFedora+2 moreJun 17, 2026 Oct 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams...Show more |
Use After Free in GitHub repository vim/vim prior to v9.0.2010. |
3Apache FedoraprojectHcltech3Bigfix Platform FedoraXerces C++Jun 17, 2026 Oct 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 An integer overflow in xerces-c++ 3.2.3 in BigFix Platform allows remote attackers to cause out-of-bound access via HTTP request. |
2Fedoraproject Matrix2Fedora SynapseJun 17, 2026 Oct 10, 2023 N/A· v4 4.9 MEDIUM· v3 N/A· v2 Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persis...Show more |
33Akka AmazonApache+30 more165.net 3scale Api Management PlatformAdvanced Cluster Management For Kubernetes+162 moreJun 17, 2026 Oct 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. |
3Fedoraproject RedhatX.org3Enterprise Linux FedoraLibxpmJun 17, 2026 Oct 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in libXpm due to a boundary condition within the XpmCreateXpmImageFromBuffer() function. This flaw allows a local attacker to trigger an out-of-bounds read error and read the contents of memory...Show more |
3Fedoraproject RedhatX.org3Enterprise Linux FedoraLibx11Jun 17, 2026 Oct 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges. |
3Fedoraproject RedhatX.org3Enterprise Linux FedoraLibx11Jun 17, 2026 Oct 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in libX11 due to an infinite loop within the PutSubImage() function. This flaw allows a local user to consume all available system resources and cause a denial of service condition. |
3Fedoraproject RedhatX.org3Enterprise Linux FedoraLibx11Jun 17, 2026 Oct 10, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system. |
3Debian FedoraprojectLipnitsk3Debian Linux FedoraLibcueJun 17, 2026 Oct 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 libcue provides an API for parsing and extracting data from CUE sheets. Versions 2.2.1 and prior are vulnerable to out-of-bounds array access. A user of the GNOME desktop environment can be exploited by downloading a cue...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Oct 9, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privil...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Oct 9, 2023 N/A· v4 6.0 MEDIUM· v3 N/A· v2 A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, lea...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Oct 9, 2023 N/A· v4 6.0 MEDIUM· v3 N/A· v2 A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by set...Show more |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Oct 9, 2023 N/A· v4 6.0 MEDIUM· v3 N/A· v2 A flaw was found in the Netfilter subsystem in the Linux kernel. The nfnl_osf_add_callback function did not validate the user mode controlled opt_num field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to...Show more |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 17, 2026 Oct 7, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow. |
2Facebook Fedoraproject2Fedora Tac PlusJun 17, 2026 Oct 6, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A lack of input validation exists in tac_plus prior to commit 4fdf178 which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr, or NAC address sent to tac_plus to injec...Show more |
3Debian FedoraprojectWebkitgtk3Debian Linux FedoraWebkitgtkJun 17, 2026 Oct 6, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A...Show more |
NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960. |