Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chr...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in Skia in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security s...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Heap buffer overflow in ANGLE in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Type confusion in V8 in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium securi...Show more |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Aug 15, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental p...Show more |
A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass w...Show more |
2Fedoraproject Nodejs2Fedora Node.jsJun 17, 2026 Aug 15, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 `fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor coul...Show more |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Aug 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. |
3Debian FedoraprojectPhp3Debian Linux FedoraPhpJun 17, 2026 Aug 11, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In PHP version 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading po...Show more |
3Debian FedoraprojectPhp3Debian Linux FedoraPhpJun 17, 2026 Aug 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 In PHP versions 8.0.* before 8.0.30, 8.1.* before 8.1.22, and 8.2.* before 8.2.8 various XML functions rely on libxml global state to track configuration variables, like whether external entities are loaded. This state i...Show more |
3Debian FedoraprojectIntel139Debian Linux FedoraMicrocode+136 moreJun 17, 2026 Aug 11, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access. |
2Fedoraproject Intel2Fedora Onevpl Gpu RuntimeJun 17, 2026 Aug 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable denial of service via local access. |
2Fedoraproject Intel2Fedora Onevpl Gpu RuntimeJun 17, 2026 Aug 11, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable information disclosure via local access. |
3Debian FedoraprojectIntel5Debian Linux FedoraKiller+2 moreJun 17, 2026 Aug 11, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. |