CVEs (5,353)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject GolangRedhat6Enterprise Linux Server Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 13, 2026 Oct 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers. |
3Fedoraproject GolangRedhat6Enterprise Linux Server Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 13, 2026 Oct 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as dem...Show more |
2Fedoraproject Openbsd2Fedora OpensmtpdMay 13, 2026 Oct 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta. |
3Canonical FedoraprojectLibjpeg Turbo3Fedora Libjpeg TurboUbuntu LinuxMay 13, 2026 Oct 10, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker. |
6Canonical DebianFedoraproject+3 more8Debian Linux DnsmasqEnterprise Linux Desktop+5 moreMay 13, 2026 Oct 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xff...Show more |
2Fedoraproject Wesnoth2Battle For Wesnoth FedoraMay 13, 2026 Sep 26, 2017 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is u...Show more |
2Fedoraproject Wesnoth2Battle For Wesnoth FedoraMay 13, 2026 Sep 26, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensiti...Show more |
2Devscripts Devel Team Fedoraproject2Devscripts FedoraMay 13, 2026 Sep 25, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands. |
2Fedoraproject Pureftpd2Fedora Pure FtpdMay 13, 2026 Sep 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. Thi...Show more |
2Fedoraproject Ipython2Fedora IpythonMay 13, 2026 Sep 20, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery in the REST API in IPython 2 and 3. |
2Dovecot Fedoraproject2Dovecot FedoraMay 13, 2026 Sep 19, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures. |
2Debian Fedoraproject3389 Directory Server Debian LinuxFedoraMay 13, 2026 Sep 19, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call. |
2Fedoraproject Mit2Fedora Kerberos 5May 13, 2026 Sep 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibgd+1 moreMay 13, 2026 Sep 7, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors. |
2Devscripts Devel Team Fedoraproject2Devscripts FedoraMay 13, 2026 Sep 6, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename. |
2Fedoraproject Jasper Project2Fedora JasperMay 13, 2026 Aug 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack. |
2Fedoraproject Jasper Project2Fedora JasperMay 13, 2026 Aug 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack. |
2Fedoraproject Jasper Project2Fedora JasperMay 13, 2026 Aug 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial of service attack. |
2Fedoraproject Jasper Project2Fedora JasperMay 13, 2026 Aug 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of service attack. |
3Debian FedoraprojectJasper Project3Debian Linux FedoraJasperMay 13, 2026 Aug 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack. |