Vulnerabilities > Fedoraproject > Fedora > 34

DATE CVE VULNERABILITY TITLE RISK
2021-03-30 CVE-2021-29648 Improper Restriction of Excessive Authentication Attempts vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.11.11.
local
low complexity
linux fedoraproject CWE-307
5.5
2021-03-30 CVE-2021-29647 Missing Initialization of Resource vulnerability in multiple products
An issue was discovered in the Linux kernel before 5.11.11.
local
low complexity
linux fedoraproject debian CWE-909
5.5
2021-03-30 CVE-2021-29646 An issue was discovered in the Linux kernel before 5.11.11.
local
low complexity
linux fedoraproject
5.5
2021-03-29 CVE-2021-23358 Code Injection vulnerability in multiple products
The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
7.2
2021-03-26 CVE-2021-21333 Cross-site Scripting vulnerability in multiple products
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse).
network
high complexity
matrix fedoraproject CWE-79
6.1
2021-03-26 CVE-2021-21332 Cross-site Scripting vulnerability in multiple products
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse).
network
low complexity
matrix fedoraproject CWE-79
8.2
2021-03-26 CVE-2021-20271 Insufficient Verification of Data Authenticity vulnerability in multiple products
A flaw was found in RPM's signature check functionality when reading a package file.
7.0
2021-03-25 CVE-2021-3467 NULL Pointer Dereference vulnerability in multiple products
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.26 handled component references in CDEF box in the JP2 image format decoder.
local
low complexity
jasper-project fedoraproject CWE-476
5.5
2021-03-25 CVE-2021-3466 Classic Buffer Overflow vulnerability in multiple products
A flaw was found in libmicrohttpd.
network
low complexity
gnu redhat fedoraproject CWE-120
critical
9.8
2021-03-25 CVE-2021-3450 Improper Certificate Validation vulnerability in multiple products
The X509_V_FLAG_X509_STRICT flag enables additional security checks of the certificates present in a certificate chain.
7.4