Vulnerabilities > Fedoraproject

DATE CVE VULNERABILITY TITLE RISK
2021-02-24 CVE-2021-27645 Double Free vulnerability in multiple products
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system.
local
high complexity
gnu fedoraproject debian CWE-415
2.5
2021-02-23 CVE-2021-3410 Integer Overflow or Wraparound vulnerability in multiple products
A flaw was found in libcaca v0.99.beta19.
7.8
2021-02-23 CVE-2021-3407 Double Free vulnerability in multiple products
A flaw was found in mupdf 1.18.0.
local
low complexity
artifex fedoraproject debian CWE-415
5.5
2021-02-23 CVE-2021-3405 Out-of-bounds Write vulnerability in multiple products
A flaw was found in libebml before 1.4.2.
network
low complexity
matroska fedoraproject debian CWE-787
6.5
2021-02-23 CVE-2021-26927 NULL Pointer Dereference vulnerability in multiple products
A flaw was found in jasper before 2.0.25.
local
low complexity
jasper-project fedoraproject CWE-476
5.5
2021-02-23 CVE-2021-20247 Path Traversal vulnerability in multiple products
A flaw was found in mbsync before v1.3.5 and v1.4.1.
network
high complexity
mbsync-project debian fedoraproject CWE-22
7.4
2021-02-23 CVE-2021-26926 Out-of-bounds Read vulnerability in multiple products
A flaw was found in jasper before 2.0.25.
local
low complexity
jasper-project fedoraproject CWE-125
7.1
2021-02-23 CVE-2021-20229 Incorrect Authorization vulnerability in multiple products
A flaw was found in PostgreSQL in versions before 13.2.
network
low complexity
postgresql redhat fedoraproject CWE-863
4.0
2021-02-22 CVE-2021-21157 Use After Free vulnerability in multiple products
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
microsoft fedoraproject google CWE-416
8.8
2021-02-22 CVE-2021-21156 Out-of-bounds Write vulnerability in multiple products
Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.
network
low complexity
google fedoraproject CWE-787
8.8