Vulnerabilities > Fedoraproject

DATE CVE VULNERABILITY TITLE RISK
2021-02-26 CVE-2020-24455 Missing Initialization of Resource vulnerability in multiple products
Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access.
6.7
2021-02-25 CVE-2021-26701 .NET Core Remote Code Execution Vulnerability
network
high complexity
microsoft fedoraproject
8.1
2021-02-25 CVE-2021-3406 Improper Certificate Validation vulnerability in multiple products
A flaw was found in keylime 5.8.1 and older.
network
low complexity
keylime fedoraproject CWE-295
critical
9.8
2021-02-25 CVE-2021-20203 Integer Overflow or Wraparound vulnerability in multiple products
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0.
local
low complexity
qemu fedoraproject debian CWE-190
3.2
2021-02-24 CVE-2020-11988 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser.
network
low complexity
apache fedoraproject CWE-918
8.2
2021-02-24 CVE-2020-11987 Server-Side Request Forgery (SSRF) vulnerability in multiple products
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel.
network
low complexity
apache fedoraproject oracle debian CWE-918
8.2
2021-02-24 CVE-2020-28599 Out-of-bounds Write vulnerability in multiple products
A stack-based buffer overflow vulnerability exists in the import_stl.cc:import_stl() functionality of Openscad openscad-2020.12-RC2.
local
low complexity
openscad fedoraproject CWE-787
7.8
2021-02-24 CVE-2021-27645 Double Free vulnerability in multiple products
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system.
local
high complexity
gnu fedoraproject debian CWE-415
2.5
2021-02-23 CVE-2021-3410 Integer Overflow or Wraparound vulnerability in multiple products
A flaw was found in libcaca v0.99.beta19.
7.8
2021-02-23 CVE-2021-3407 Double Free vulnerability in multiple products
A flaw was found in mupdf 1.18.0.
local
low complexity
artifex fedoraproject debian CWE-415
5.5