Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject QemuRedhat4Enterprise Linux Extra Packages For Enterprise LinuxFedora+1 moreJun 17, 2026 Nov 29, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past t...Show more |
2Fedoraproject Linux2Fedora Layer 2 Tunneling ProtocolJun 17, 2026 Nov 28, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potential...Show more |
3Debian FedoraprojectGnu3Debian Linux EmacsFedoraJun 17, 2026 Nov 28, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags progra...Show more |
4Debian FedoraprojectLinux+1 more8Debian Linux FedoraH300s Firmware+5 moreJun 17, 2026 Nov 27, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets. |
2Fedoraproject Moodle3Extra Packages For Enterprise Linux FedoraMoodleJun 17, 2026 Nov 25, 2022 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt...Show more |
2Fedoraproject Nextcloud3Fedora Nextcloud Enterprise ServerNextcloud ServerJun 17, 2026 Nov 25, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a d...Show more |
Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command. |
2Fedoraproject Systemd Project2Fedora SystemdJun 17, 2026 Nov 23, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to cras...Show more |
3Artifex DebianFedoraproject3Debian Linux FedoraMujsJun 17, 2026 Nov 23, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file...Show more |
2Fedoraproject Qpress Project2Fedora QpressJun 17, 2026 Nov 23, 2022 N/A· v4 5.3 MEDIUM· v3 N/A· v2 qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file. |
The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and s...Show more |
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafte...Show more |
A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a cour...Show more |
3Fedoraproject KeylimeRedhat3Enterprise Linux FedoraKeylimeJun 17, 2026 Nov 22, 2022 N/A· v4 5.1 MEDIUM· v3 N/A· v2 A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that...Show more |
4Debian FedoraprojectLibarchive+1 more4Debian Linux FedoraLibarchive+1 moreJun 17, 2026 Nov 22, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the...Show more |
2Fedoraproject Ruby Lang3Cgi FedoraRubyJun 17, 2026 Nov 18, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to cre...Show more |
2Fedoraproject Freerdp2Fedora FreerdpJun 17, 2026 Nov 16, 2022 N/A· v4 4.6 MEDIUM· v3 N/A· v2 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of...Show more |
2Fedoraproject Freerdp2Fedora FreerdpJun 17, 2026 Nov 16, 2022 N/A· v4 5.7 MEDIUM· v3 N/A· v2 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by...Show more |
2Fedoraproject Freerdp2Fedora FreerdpJun 17, 2026 Nov 16, 2022 N/A· v4 4.6 MEDIUM· v3 N/A· v2 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read ou...Show more |
2Fedoraproject Freerdp2Fedora FreerdpJun 17, 2026 Nov 16, 2022 N/A· v4 4.6 MEDIUM· v3 N/A· v2 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in `drive` channel. A malicious server can trick a FreeRDP based client to read out of bound...Show more |