Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject GnuRedhat3Binutils Enterprise LinuxFedoraJun 17, 2026 Jan 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-...Show more |
A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts. |
4Apple DebianFedoraproject+1 more4Debian Linux FedoraMacos+1 moreJun 17, 2026 Jan 18, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries...Show more |
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objec...Show more |
2Fedoraproject Pgadmin2Fedora Pgadmin 4Jun 17, 2026 Jan 17, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially c...Show more |
3Debian FedoraprojectRuby Git Project3Debian Linux FedoraRuby GitJun 17, 2026 Jan 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability...Show more |
3Debian FedoraprojectTorproject3Debian Linux FedoraTorJun 17, 2026 Jan 14, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002. |
A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service. |
A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file. |
A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the...Show more |
A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Jan 12, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are create...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Jan 11, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties. |
2Fedoraproject Microsoft3.net FedoraPowershellJun 17, 2026 Jan 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 .NET Denial of Service Vulnerability |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Jan 10, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A use-after-free vulnerability was found in __nfs42_ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allows an attacker to conduct a remote denial |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Jan 10, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiJun 17, 2026 Jan 10, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are sl...Show more |
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143. |
JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 do...Show more |
4Fedoraproject HaxxNetapp+1 more7Active Iq Unified Manager CurlFedora+4 moreJun 17, 2026 Dec 23, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability exists in curl <7.87.0 HSTS check that could be bypassed to trick it to keep using HTTP. Using its HSTS support, curl can be instructed to use HTTPS instead of using an insecure clear-text HTTP step even...Show more |