← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectFlightgear
3Debian Linux
FedoraFlightgear
May 13, 2026
Feb 22, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
2Fedoraproject
Teeworlds
2Fedora
Teeworlds
May 13, 2026
Feb 22, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involvin...Show more
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling.Show less
2Fedoraproject
Gnu
2Ed
Fedora
May 13, 2026
Feb 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.
2Fedoraproject
Zend
2Fedora
Zend Framework
May 13, 2026
Feb 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regu...Show more
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.Show less
2Fedoraproject
Zend
2Fedora
Zend Framework
May 13, 2026
Feb 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement befo...Show more
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.Show less
3Fedoraproject
Jasper ProjectOpensuse
3Fedora
JasperOpensuse
May 13, 2026
Feb 15, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the...Show more
Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the imginfo command.Show less
3Debian
FedoraprojectJasper Project
3Debian Linux
FedoraJasper
May 13, 2026
Feb 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP im...Show more
The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP image to the imginfo command.Show less
3Debian
FedoraprojectJasper Project
3Debian Linux
FedoraJasper
May 13, 2026
Feb 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP im...Show more
The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command.Show less
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Feb 15, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted BMP image in an imginfo command.
2Fedoraproject
Suckless
2Fedora
Slock
May 13, 2026
Feb 15, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
slock allows attackers to bypass the screen lock via vectors involving an invalid password hash, which triggers a NULL pointer dereference and crash.
2Dlitz
Fedoraproject
2Fedora
Pycrypto
May 13, 2026
Feb 15, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg....Show more
Heap-based buffer overflow in the ALGnew function in block_templace.c in Python Cryptography Toolkit (aka pycrypto) allows remote attackers to execute arbitrary code as demonstrated by a crafted iv parameter to cryptmsg.py.Show less
2Fedoraproject
Uclouvain
2Fedora
Openjpeg
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists be...Show more
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.Show less
2Fedoraproject
Uclouvain
2Fedora
Openjpeg
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.
2Artifex
Fedoraproject
2Fedora
Mujs
May 13, 2026
Feb 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafte...Show more
Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.Show less
2Fedoraproject
Webmproject
2Fedora
Libwebp
May 13, 2026
Feb 3, 2017
N/A· v4
3.3 LOW· v3
2.1 LOW· v2
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
4Fedoraproject
Libgit2 ProjectOpensuse+1 more
5Fedora
LeapLibgit2+2 more
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
4Fedoraproject
Libgit2 ProjectOpensuse+1 more
5Fedora
LeapLibgit2+2 more
May 13, 2026
Feb 3, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
8Canonical
DebianFedoraproject+5 more
10Clustered Data Ontap
Debian LinuxFedora+7 more
May 13, 2026
Jan 30, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
4Fedoraproject
GstreamerGstreamer Project+1 more
9Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+6 more
May 13, 2026
Jan 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the...Show more
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.Show less
2Fedoraproject
Marked Project
2Fedora
Marked
May 13, 2026
Jan 23, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular...Show more
The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (ReDoS)."Show less