← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
2.7 LOW· v3
4.0 MEDIUM· v2
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2: Overview report allows users to see hidden courses
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
2Fedoraproject
Moodle
2Fedora
Moodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
3Fedoraproject
MoodleRedhat
3Enterprise Linux
FedoraMoodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
8.2 HIGH· v3
6.4 MEDIUM· v2
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
3Fedoraproject
MoodleRedhat
3Enterprise Linux
FedoraMoodle
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moodle before 2.2.2 has users' private files included in course backups
4Debian
FedoraprojectMoodle+1 more
4Debian Linux
Enterprise LinuxFedora+1 more
Nov 21, 2024
Nov 14, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
5Debian
FedoraprojectOpensuse+2 more
5Debian Linux
Enterprise LinuxFedora+2 more
Nov 21, 2024
Nov 13, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
2Crun Project
Fedoraproject
2Crun
Fedora
Jun 17, 2026
Nov 13, 2019
N/A· v4
8.6 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and lib...Show more
An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.Show less
2Fedoraproject
Oracle
2Fedora
Mysql Gui Tools
Nov 21, 2024
Nov 12, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
3Cor Entertainment
DebianFedoraproject
3Alien Arena
Debian LinuxFedora
Nov 21, 2024
Nov 12, 2019
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.
3Debian
FedoraprojectLibpoe Component Irc Perl Project
3Debian Linux
FedoraLibpoe Component Irc Perl
Nov 21, 2024
Nov 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which...Show more
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraTnef+1 more
Jun 17, 2026
Nov 11, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read...Show more
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.Show less
3Ceph
FedoraprojectRedhat
3Ceph
Ceph StorageFedora
Jun 17, 2026
Nov 8, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connectio...Show more
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.Show less
2Fedoraproject
Redhat
2Fedora
Tuned
Nov 21, 2024
Nov 8, 2019
N/A· v4
5.5 MEDIUM· v3
4.7 MEDIUM· v2
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
3Debian
FedoraprojectOpenttd
3Debian Linux
FedoraOpenttd
Nov 21, 2024
Nov 7, 2019
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
3Fedoraproject
LinuxRedhat
3Enterprise Linux
FedoraLinux Kernel
Jun 17, 2026
Nov 7, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_para...Show more
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Nov 7, 2019
N/A· v4
4.6 MEDIUM· v3
4.9 MEDIUM· v2
A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.
4Canonical
FedoraprojectLinux+1 more
4Fedora
LeapLinux Kernel+1 more
Jun 17, 2026
Nov 7, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.
5Canonical
DebianDjvulibre Project+2 more
5Debian Linux
DjvulibreFedora+2 more
Jun 17, 2026
Nov 7, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.