Vulnerabilities > Fedoraproject > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-26 CVE-2021-30498 Out-of-bounds Write vulnerability in multiple products
A flaw was found in libcaca.
local
low complexity
libcaca-project fedoraproject CWE-787
7.8
2021-05-26 CVE-2021-3561 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An Out of Bounds flaw was found fig2dev version 3.2.8a.
7.1
2021-05-26 CVE-2021-33194 Infinite Loop vulnerability in multiple products
golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
network
low complexity
golang fedoraproject CWE-835
7.5
2021-05-26 CVE-2020-25670 Use After Free vulnerability in multiple products
A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.
local
low complexity
linux fedoraproject netapp debian CWE-416
7.8
2021-05-26 CVE-2020-25671 Use After Free vulnerability in multiple products
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.
local
low complexity
linux fedoraproject netapp debian CWE-416
7.8
2021-05-26 CVE-2021-22543 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest.
local
low complexity
linux fedoraproject debian netapp CWE-119
7.8
2021-05-25 CVE-2020-25672 Memory Leak vulnerability in multiple products
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
network
low complexity
linux fedoraproject debian netapp CWE-401
7.5
2021-05-20 CVE-2021-33477 Improper Handling of Exceptional Conditions vulnerability in multiple products
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q).
8.8
2021-05-20 CVE-2021-3480 NULL Pointer Dereference vulnerability in multiple products
A flaw was found in slapi-nis in versions before 0.56.7.
network
low complexity
slapi-nis-project fedoraproject CWE-476
7.5
2021-05-20 CVE-2021-20718 Resource Exhaustion vulnerability in multiple products
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.
network
low complexity
openidc fedoraproject oracle CWE-400
7.5