Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Freerdp2Fedora FreerdpJun 17, 2026 Nov 16, 2022 N/A· v4 5.7 MEDIUM· v3 N/A· v2 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client t...Show more |
2Fedoraproject Freerdp2Fedora FreerdpJun 17, 2026 Nov 16, 2022 N/A· v4 4.6 MEDIUM· v3 N/A· v2 FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP may attempt integer addition on too narrow types leads to allocation of a buffer too small holding the data written. A malicious...Show more |
2Fedoraproject Freerdp2Fedora FreerdpJun 17, 2026 Nov 16, 2022 N/A· v4 5.7 MEDIUM· v3 N/A· v2 FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of b...Show more |
2Fedoraproject Gnome2Fedora NautilusJun 17, 2026 Nov 14, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive. |
3Debian FedoraprojectNetatalk3Debian Linux FedoraNetatalkJun 17, 2026 Nov 12, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS). |
2Fedoraproject Snakeyaml Project2Fedora SnakeyamlJun 17, 2026 Nov 11, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by...Show more |
2Fedoraproject Invisible Island2Fedora XtermJun 17, 2026 Nov 10, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the...Show more |
4Fedoraproject MicrosoftNetapp+1 more9Fedora Management Services For Element SoftwareManagement Services For Netapp Hci+6 moreJun 17, 2026 Nov 9, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 Netlogon RPC Elevation of Privilege Vulnerability |
4Fedoraproject MicrosoftNetapp+1 more9Fedora Management Services For Element SoftwareManagement Services For Netapp Hci+6 moreJun 17, 2026 Nov 9, 2022 N/A· v4 7.2 HIGH· v3 N/A· v2 Windows Kerberos Elevation of Privilege Vulnerability |
4Fedoraproject MicrosoftNetapp+1 more9Fedora Management Services For Element SoftwareManagement Services For Netapp Hci+6 moreJun 17, 2026 Nov 9, 2022 N/A· v4 8.1 HIGH· v3 N/A· v2 Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability |
3Amd FedoraprojectXen169A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+166 moreJun 17, 2026 Nov 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure. |
3Debian FedoraprojectXfce3Debian Linux FedoraXfce4 SettingsJun 17, 2026 Nov 9, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper. |
3Fedoraproject NetappPython9Active Iq Unified Manager Bootstrap OsE Series Performance Analyzer+6 moreJun 17, 2026 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being present...Show more |
4Debian FedoraprojectVarnish Software+1 more5Debian Linux FedoraVarnish Cache+2 moreJun 17, 2026 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in th...Show more |
2Fedoraproject Varnish Cache Project2Fedora Varnish CacheJun 17, 2026 Nov 9, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing th...Show more |
3Fedoraproject RedhatSystemd Project3Enterprise Linux FedoraSystemdJun 17, 2026 Nov 8, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading...Show more |
3Debian FedoraprojectSysstat Project3Debian Linux FedoraSysstatJun 17, 2026 Nov 8, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocat...Show more |
2Apache Fedoraproject2Commons Bcel FedoraJun 17, 2026 Nov 7, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This...Show more |
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allo...Show more |
3Debian FedoraprojectTuxera3Debian Linux FedoraNtfs 3gJun 17, 2026 Nov 6, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A buffer overflow was discovered in NTFS-3G before 2022.10.3. Crafted metadata in an NTFS image can cause code execution. A local attacker can exploit this if the ntfs-3g binary is setuid root. A physically proximate att...Show more |