Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectYajl Project3Debian Linux FedoraYajlJun 17, 2026 Jun 6, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash. |
6Apple CouchbaseDebian+3 more6Chrome Couchbase ServerDebian Linux+3 moreJun 17, 2026 Jun 5, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Type confusion in V8 in Google Chrome prior to 114.0.5735.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
3Debian FedoraprojectQt3Debian Linux FedoraQtJun 17, 2026 Jun 5, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate. |
3Fedoraproject ImagemagickRedhat4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 May 30, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding. |
3Fedoraproject ImagemagickRedhat4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 May 30, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured. |
4Debian FedoraprojectImagemagick+1 more5Debian Linux Enterprise LinuxExtra Packages For Enterprise Linux+2 moreJun 17, 2026 May 30, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546). |
4Apple FedoraprojectHaxx+1 more9Clustered Data Ontap CurlFedora+6 moreJun 17, 2026 May 26, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFI...Show more |
5Apple DebianFedoraproject+2 more10Clustered Data Ontap CurlDebian Linux+7 moreJun 17, 2026 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use...Show more |
2Fedoraproject Python2Fedora RequestsJun 17, 2026 May 26, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to re...Show more |
3Fedoraproject LibsshRedhat3Enterprise Linux FedoraLibsshJun 17, 2026 May 26, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is ins...Show more |
2Fedoraproject Usebottles2Bottles FedoraJun 17, 2026 May 26, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file. |
3Avahi FedoraprojectRedhat3Avahi Enterprise LinuxFedoraJun 17, 2026 May 26, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash. |
4Debian FedoraprojectLibssh+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 May 26, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service. |
3C Ares Project DebianFedoraproject3C Ares Debian LinuxFedoraJun 17, 2026 May 25, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 c-ares is an asynchronous resolver library. c-ares is vulnerable to denial of service. If a target resolver sends a query, the attacker forges a malformed UDP packet with a length of 0 and returns them to the target reso...Show more |
2C Ares Project Fedoraproject2C Ares FedoraJun 17, 2026 May 25, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by sr...Show more |
3C Ares Project DebianFedoraproject3C Ares Debian LinuxFedoraJun 17, 2026 May 25, 2023 N/A· v4 6.4 MEDIUM· v3 N/A· v2 c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function...Show more |
2C Ares Project Fedoraproject2C Ares FedoraJun 17, 2026 May 25, 2023 N/A· v4 3.7 LOW· v3 N/A· v2 c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using...Show more |
3Debian FedoraprojectSysstat Project3Debian Linux FedoraSysstatJun 17, 2026 May 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377. |
3Fedoraproject LibtiffRedhat3Enterprise Linux FedoraLibtiffJun 17, 2026 May 17, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL p...Show more |
3Debian FedoraprojectLinuxfoundation3Cups Filters Debian LinuxFedoraJun 17, 2026 May 17, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible netw...Show more |