Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Procps Project2Fedora ProcpsJun 17, 2026 Aug 2, 2023 N/A· v4 3.3 LOW· v3 N/A· v2 Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap. |
4Artifex DebianFedoraproject+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 23, 2026 Aug 1, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with...Show more |
5Debian FedoraprojectLinux+2 more8Debian Linux Enterprise LinuxFedora+5 moreJun 17, 2026 Jul 31, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove function with the element, without a NFT_SET_EXT_KEY_END. This issue could allow a local user to crash the...Show more |
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) |
Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low) |
3Debian FedoraprojectGoogle3Chrome Debian LinuxFedoraJun 17, 2026 Jul 29, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium) |
3Certifi FedoraprojectNetapp8Active Iq Unified Manager CertifiFedora+5 moreJun 17, 2026 Jul 25, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certifi...Show more |
4Debian FedoraprojectLinux+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jul 25, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to cause a 4 byte out-of-bounds read of XFRMA_MTIMER_THRE...Show more |
4Debian FedoraprojectLinux+1 more6Debian Linux Enterprise LinuxEnterprise Linux For Real Time+3 moreJun 17, 2026 Jul 25, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicious user with CAP_NET_ADMIN privileges to directly dereference a NULL pointer in xfrm_update_ae_...Show more |
3Fedoraproject KeylimeRedhat9Enterprise Linux Enterprise Linux EusEnterprise Linux For Ibm Z Systems+6 moreJun 17, 2026 Jul 24, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections. |
A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a resul...Show more |
3Debian FedoraprojectGnome3Debian Linux FedoraLibrsvgJun 17, 2026 Jul 22, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?.....Show more |
3Fedoraproject RedhatSamba4Enterprise Linux FedoraSamba+1 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 pack...Show more |
4Debian FedoraprojectRedhat+1 more5Debian Linux Enterprise LinuxFedora+2 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A Type Confusion vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets, one encoded data structure is a key-value style dictionary where the keys are character str...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jul 20, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An infinite loop vulnerability was found in Samba's mdssvc RPC service for Spotlight. When parsing Spotlight mdssvc RPC packets sent by the client, the core unmarshalling function sl_unpack_loop() did not validate a fiel...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Jul 20, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An out-of-bounds read vulnerability was found in Samba due to insufficient length checks in winbindd_pam_auth_crap.c. When performing NTLM authentication, the client replies to cryptographic challenges back to the server...Show more |
2Fedoraproject Openbsd2Fedora OpensshJun 17, 2026 Jul 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not...Show more |
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the...Show more |
3Fedoraproject NetappOracle6Active Iq Unified Manager FedoraMysql Server+3 moreJun 17, 2026 Jul 18, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with netw...Show more |