CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Redhat2Etcd FedoraNov 21, 2024 Apr 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theore...Show more |
2Fedoraproject Redhat2Ceph FedoraJun 17, 2026 Mar 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service. |
2Fedoraproject Sddm Project2Fedora SddmNov 21, 2024 Mar 8, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in...Show more |
2Fedoraproject Sddm Project2Fedora SddmNov 21, 2024 Mar 8, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. |
4Debian FedoraprojectMit+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Mar 6, 2018 N/A· v4 3.8 LOW· v3 5.5 MEDIUM· v2 MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument,...Show more |
4Debian FedoraprojectMit+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Mar 6, 2018 N/A· v4 4.7 MEDIUM· v3 6.5 MEDIUM· v2 MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagg...Show more |
2Fedoraproject Opensuse2Fedora ZypperNov 21, 2024 Mar 1, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used. |
2Fedoraproject Fishshell2Fedora FishNov 21, 2024 Feb 9, 2018 N/A· v4 7.8 HIGH· v3 4.3 MEDIUM· v2 fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER. |
2Fedoraproject Zabbix2Fedora ZabbixNov 21, 2024 Feb 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbit...Show more |
3Fedoraproject MariadbPercona3Fedora MariadbXtradb ClusterNov 21, 2024 Jan 25, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass i...Show more |
3Debian FedoraprojectGnu3Debian Linux FedoraLibtasn1Jun 17, 2026 Jan 22, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS. |
5Canonical DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Jan 12, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file. |
4Canonical FedoraprojectLinux+1 more20Enterprise Linux Enterprise Linux Compute Node EusEnterprise Linux Desktop+17 moreNov 21, 2024 Jan 9, 2018 N/A· v4 4.7 MEDIUM· v3 4.9 MEDIUM· v2 A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it...Show more |
3Fedoraproject NumpyRedhat3Enterprise Linux FedoraNumpyNov 21, 2024 Jan 8, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary f...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiMay 13, 2026 Dec 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an exist...Show more |
3Fedoraproject Netcf ProjectRedhat3Enterprise Linux FedoraNetcfMay 13, 2026 Dec 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions. |
2Fedoraproject Rawstudio2Fedora RawstudioMay 13, 2026 Dec 29, 2017 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph. |
2Fedoraproject Mistune Project2Fedora MistuneMay 13, 2026 Dec 29, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument. |
2Fedoraproject Redhat2Ceph FedoraMay 13, 2026 Dec 20, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an inval...Show more |
5Debian FedoraprojectOpensuse+2 more6Debian Linux FedoraLeap+3 moreMay 13, 2026 Dec 5, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor. |