← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Module Metadata Project
2Fedora
Module Metadata
Nov 21, 2024
Jan 28, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value.
5Canonical
DebianFedoraproject+2 more
428Celeron 3855u Firmware
Celeron 3865u FirmwareCeleron 3955u Firmware+425 more
Jun 17, 2026
Jan 28, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
4Debian
FedoraprojectNetty+1 more
6Debian Linux
FedoraJboss Enterprise Application Platform+3 more
Jun 17, 2026
Jan 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an inc...Show more
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.Show less
2Fedoraproject
Qt
2Fedora
Qt
Nov 21, 2024
Jan 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
3Apereo
DebianFedoraproject
5.net Cas Client
Debian LinuxFedora+2 more
Nov 21, 2024
Jan 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow rem...Show more
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java or (2) pgtUrl parameter to validation/Cas20ServiceTicketValidator.java.Show less
5Apache
CanonicalDebian+2 more
5Debian Linux
FedoraSoftware Collections+2 more
Jun 17, 2026
Jan 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it...Show more
An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it to execute arbitrary code. Apache XML-RPC is no longer maintained and this issue will not be fixed.Show less
3Arista
FedoraprojectQemu
3Eos
FedoraQemu
Nov 21, 2024
Jan 23, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.
4Arista
CanonicalFedoraproject+1 more
4Eos
FedoraQemu+1 more
Nov 21, 2024
Jan 23, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving p...Show more
The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving packets.Show less
5Arista
CanonicalFedoraproject+2 more
8Eos
FedoraLinux Enterprise Debuginfo+5 more
Nov 21, 2024
Jan 23, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop.
3Arm
DebianFedoraproject
4Debian Linux
FedoraMbed Crypto+1 more
Jun 17, 2026
Jan 23, 2020
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key v...Show more
The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.Show less
7Canonical
DebianFedoraproject+4 more
24Clustered Data Ontap
Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian Linux+21 more
Jun 17, 2026
Jan 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation.
6Debian
FedoraprojectNetapp+3 more
24Cloud Backup
Clustered Data OntapCommunications Cloud Native Core Network Function Cloud Native Environment+21 more
Jun 17, 2026
Jan 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak.
2Fedoraproject
Owasp
2Fedora
Modsecurity
Jun 17, 2026
Jan 21, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw i...Show more
Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeader in transaction.cc.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
Directory ServerDiskstation Manager+7 more
Jun 17, 2026
Jan 21, 2020
N/A· v4
6.5 MEDIUM· v3
2.6 LOW· v2
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character c...Show more
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, this may cause a long-lived process(such as the RPC server) to terminate. (In the file server case, the most likely target, smbd, operates as process-per-client and so a crash there is harmless).Show less
5Canonical
FedoraprojectNetapp+2 more
7Active Iq Unified Manager
Cloud BackupFedora+4 more
Jun 17, 2026
Jan 21, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
5Cacti
DebianFedoraproject+2 more
7Backports Sle
CactiDebian Linux+4 more
Jun 17, 2026
Jan 16, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in dat...Show more
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).Show less
3Debian
FedoraprojectRedislabs
3Debian Linux
FedoraHiredis
Jun 17, 2026
Jan 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.
4Fedoraproject
OpensuseOracle+1 more
5Fedora
LeapSolaris+2 more
Jun 17, 2026
Jan 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
2Fedoraproject
Symantec
2Endpoint Detection And Response
Fedora
Jun 17, 2026
Jan 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages vie...Show more
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.Show less
2Fedoraproject
Symonics
2Fedora
Libmysofa
Jun 17, 2026
Jan 13, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.