Vulnerabilities > Fedoraproject

DATE CVE VULNERABILITY TITLE RISK
2021-02-26 CVE-2021-21274 Allocation of Resources Without Limits or Throttling vulnerability in multiple products
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse).
network
low complexity
matrix fedoraproject CWE-770
6.5
2021-02-26 CVE-2021-21273 Open Redirect vulnerability in multiple products
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse).
network
low complexity
matrix fedoraproject CWE-601
6.1
2021-02-26 CVE-2021-21330 Open Redirect vulnerability in multiple products
aiohttp is an asynchronous HTTP client/server framework for asyncio and Python.
network
low complexity
aiohttp debian fedoraproject CWE-601
6.1
2021-02-26 CVE-2020-24455 Missing Initialization of Resource vulnerability in multiple products
Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access.
6.7
2021-02-25 CVE-2021-26701 .NET Core Remote Code Execution Vulnerability
network
high complexity
microsoft fedoraproject
8.1
2021-02-25 CVE-2021-3406 Improper Certificate Validation vulnerability in multiple products
A flaw was found in keylime 5.8.1 and older.
network
low complexity
keylime fedoraproject CWE-295
critical
9.8
2021-02-25 CVE-2021-20203 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0.
local
low complexity
qemu fedoraproject debian CWE-190
3.2
2021-02-24 CVE-2020-11988 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser.
network
low complexity
apache fedoraproject CWE-918
8.2
2021-02-24 CVE-2020-11987 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel.
network
low complexity
apache fedoraproject oracle debian CWE-918
8.2
2021-02-24 CVE-2020-28599 Out-of-bounds Write vulnerability in multiple products
A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2.
local
low complexity
openscad fedoraproject CWE-787
7.8