← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Elog Project
Fedoraproject
2Elog
Fedora
May 13, 2026
Jun 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
2Fedoraproject
Libreswan
2Fedora
Libreswan
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
2Fedoraproject
Pulpproject
2Fedora
Pulp
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
2Fedoraproject
Pulpproject
2Fedora
Pulp
May 13, 2026
Jun 13, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
2Fedoraproject
Pulpproject
2Fedora
Pulp
May 13, 2026
Jun 8, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
5Fedoraproject
Game Music Emu ProjectNovell+2 more
7Fedora
Game Music EmuLeap+4 more
May 13, 2026
Jun 6, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
game-music-emu before 0.6.1 mishandles unspecified integer values.
5Fedoraproject
Game Music Emu ProjectNovell+2 more
7Fedora
Game Music EmuLeap+4 more
May 13, 2026
Jun 6, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraGit Shell+2 more
May 13, 2026
Jun 1, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote...Show more
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.Show less
5Debian
FedoraprojectGoogle+2 more
7Chrome
Debian LinuxEnterprise Linux Server Supplementary+4 more
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
5Debian
FedoraprojectGoogle+2 more
7Chrome
Debian LinuxEnterprise Linux Server Supplementary+4 more
May 13, 2026
May 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via unknown vectors.
3Debian
FedoraprojectTug
3Debian Linux
FedoraTex Live
May 13, 2026
May 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
2Fedoraproject
Vmware
2Fedora
Spring Advanced Message Queuing Protocol
May 13, 2026
Apr 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
3Clusterlabs
FedoraprojectRedhat
3Enterprise Linux
FedoraPcs
May 13, 2026
Apr 21, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Session fixation vulnerability in pcsd in pcs before 0.9.157.
3Clusterlabs
FedoraprojectRedhat
3Enterprise Linux
FedoraPcs
May 13, 2026
Apr 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
2Fedoraproject
Mock Project
2Fedora
Scm Plugin
May 13, 2026
Apr 14, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraLeap+7 more
May 13, 2026
Apr 13, 2017
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
2Fedoraproject
Saltstack
2Fedora
Salt
May 13, 2026
Apr 13, 2017
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
2Fedoraproject
Saltstack
2Fedora
Salt
May 13, 2026
Apr 13, 2017
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
3Fedoraproject
KernelOpensuse
3Fedora
OpensuseUtil Linux
May 13, 2026
Mar 31, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Mar 28, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vu...Show more
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8690.Show less