Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Openatom2Fedora OpeneulerJun 17, 2026 Dec 19, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released me...Show more |
3Debian FedoraprojectFfmpeg3Debian Linux FedoraFfmpegJun 17, 2026 Dec 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability. |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 17, 2026 Dec 15, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL...Show more |
3Arm FedoraprojectTrustedfirmware3Fedora Mbed TlsMbed TlsJun 17, 2026 Dec 15, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) c...Show more |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreJun 17, 2026 Dec 14, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. T...Show more |
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 14, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIChangeProperty request has a length-validation issues, resulting in out-of-bounds memory reads and potential information disclos...Show more |
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 14, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on...Show more |
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 14, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on sy...Show more |
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 14, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to loca...Show more |
3Debian FedoraprojectX.org3Debian Linux FedoraX ServerJun 17, 2026 Dec 14, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are se...Show more |
3Fedoraproject GnuRedhat8Enterprise Linux Eus Enterprise Linux For Power Little Endian EusEnterprise Linux Server Aus+5 moreJun 17, 2026 Dec 14, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 A buffer overflow was found in grub_font_construct_glyph(). A malicious crafted pf2 font can lead to an overflow when calculating the max_glyph_size value, allocating a smaller than needed buffer for the glyph, this furt...Show more |
2Fedoraproject Pgadmin2Fedora Pgadmin 4Jun 17, 2026 Dec 13, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the server to determine...Show more |
2Fedoraproject Rxvt Unicode Project3Extra Packages For Enterprise Linux FedoraRxvt UnicodeJun 17, 2026 Dec 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set. |
An attacker can cause excessive memory growth in a Go server accepting HTTP/2 requests. HTTP/2 server connections contain a cache of HTTP header keys sent by the client. While the total number of entries in this cache is...Show more |
2Fedoraproject Podman Project2Fedora PodmanJun 17, 2026 Dec 8, 2022 N/A· v4 3.3 LOW· v3 N/A· v2 A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality. |
2Fedoraproject Podman Project2Fedora PodmanJun 17, 2026 Dec 8, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure. |
3Debian FedoraprojectGitpython Project3Debian Linux FedoraGitpythonJun 17, 2026 Dec 6, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 All versions of package gitpython are vulnerable to Remote Code Execution (RCE) due to improper user input validation, which makes it possible to inject a maliciously crafted remote URL into the clone command. Exploiting...Show more |
3Awstats DebianFedoraproject3Awstats Debian LinuxFedoraJun 17, 2026 Dec 4, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks. |
2Capnproto Fedoraproject3Capnp CapnprotoFedoraJun 17, 2026 Nov 30, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Cap'n Proto is a data interchange format and remote procedure call (RPC) system. Cap'n Proro prior to versions 0.7.1, 0.8.1, 0.9.2, and 0.10.3, as well as versions of Cap'n Proto's Rust implementation prior to 0.13.7, 0....Show more |
An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to...Show more |