← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Fedoraproject
OraclePcre+1 more
4Fedora
LinuxPerl Compatible Regular Expression Library+1 more
May 6, 2026
Dec 2, 2015
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other imp...Show more
PCRE before 8.38 mishandles the interaction of lookbehind assertions and mutually recursive subpatterns, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.Show less
3Fedoraproject
PcrePhp
3Fedora
Perl Compatible Regular Expression LibraryPhp
May 6, 2026
Dec 2, 2015
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as...Show more
PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.Show less
2Fedoraproject
Pcre
2Fedora
Perl Compatible Regular Expression Library
May 6, 2026
Dec 2, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified ot...Show more
The pcre_exec function in pcre_exec.c in PCRE before 8.38 mishandles a // pattern with a \01 string, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.Show less
2Fedoraproject
Gnome
2Fedora
Gnome Display Manager
May 6, 2026
Nov 24, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.
2Fedoraproject
Sddm Project
2Fedora
Sddm
May 6, 2026
Nov 24, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspa...Show more
daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.Show less
9Apple
CanonicalDebian+6 more
20Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+17 more
May 6, 2026
Nov 13, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow r...Show more
Multiple buffer overflows in the (1) png_set_PLTE and (2) png_get_PLTE functions in libpng before 1.0.64, 1.1.x and 1.2.x before 1.2.54, 1.3.x and 1.4.x before 1.4.17, 1.5.x before 1.5.24, and 1.6.x before 1.6.19 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a small bit-depth value in an IHDR (aka image header) chunk in a PNG image.Show less
3Debian
FedoraprojectQemu
3Debian Linux
FedoraQemu
May 6, 2026
Nov 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via...Show more
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.Show less
6Arista
CanonicalDebian+3 more
7Debian Linux
EosFedora+4 more
May 6, 2026
Nov 6, 2015
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demo...Show more
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.Show less
3Fedoraproject
QemuRedhat
3Fedora
OpenstackQemu
May 6, 2026
Nov 6, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute a...Show more
Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.Show less
6Arm
DebianFedoraproject+3 more
6Debian Linux
FedoraMbed Tls+3 more
Jun 5, 2026
Nov 2, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long...Show more
Heap-based buffer overflow in ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long session ticket name to the session ticket extension, which is not properly handled when creating a ClientHello message to resume a session. NOTE: this identifier was SPLIT from CVE-2015-5291 per ADT3 due to different affected version ranges.Show less
6Arm
DebianFedoraproject+3 more
7Debian Linux
FedoraLeap+4 more
Jun 5, 2026
Nov 2, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly ex...Show more
Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is not properly handled when creating a ClientHello message. NOTE: this identifier has been SPLIT per ADT3 due to different affected version ranges. See CVE-2015-8036 for the session ticket issue that was introduced in 1.3.0.Show less
3Apache
CanonicalFedoraproject
3Fedora
HttpclientUbuntu Linux
May 6, 2026
Oct 27, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denia...Show more
http/conn/ssl/SSLConnectionSocketFactory.java in Apache HttpComponents HttpClient before 4.3.6 ignores the http.socket.timeout configuration setting during an SSL handshake, which allows remote attackers to cause a denial of service (HTTPS call hang) via unspecified vectors.Show less
3Fedoraproject
OpensusePolkit Project
3Fedora
OpensusePolkit
May 6, 2026
Oct 26, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a du...Show more
Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.Show less
7Canonical
DebianFedoraproject+4 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+12 more
May 6, 2026
Oct 22, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-...Show more
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraMariadb+2 more
May 6, 2026
Oct 21, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
6Canonical
DebianFedoraproject+3 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+10 more
May 6, 2026
Oct 21, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to DML.
7Canonical
DebianFedoraproject+4 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+12 more
May 6, 2026
Oct 21, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : Parser.
7Canonical
DebianFedoraproject+4 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+12 more
May 6, 2026
Oct 21, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
7Canonical
DebianFedoraproject+4 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+12 more
May 6, 2026
Oct 21, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2015-49...Show more
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2015-4913.Show less
7Canonical
DebianFedoraproject+4 more
15Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+12 more
May 6, 2026
Oct 21, 2015
N/A· v4
N/A· v3
2.8 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : SP.