← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Fedoraproject
OpensuseRubyonrails
4Fedora
Jquery RailsJquery Ujs+1 more
May 6, 2026
Jul 26, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transm...Show more
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value.Show less
3Fedoraproject
OpensuseWvware
3Fedora
LibwmfOpensuse
May 6, 2026
Jul 1, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a W...Show more
Heap-based buffer overflow in the DecodeImage function in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted "run-length count" in an image in a WMF file.Show less
3Fedoraproject
OpensuseWvware
3Fedora
LibwmfOpensuse
May 6, 2026
Jul 1, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
2Cacti
Fedoraproject
2Cacti
Fedora
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templ...Show more
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.Show less
2Cacti
Fedoraproject
2Cacti
Fedora
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.
2Cacti
Fedoraproject
2Cacti
Fedora
May 6, 2026
Jun 17, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
8Arista
CanonicalDebian+5 more
18Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+15 more
May 6, 2026
Jun 15, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the PCNET controller in QEMU allows remote attackers to execute arbitrary code by sending a packet with TXSTATUS_STARTPACKET set and then a crafted packet with TXSTATUS_DEVICEOWNS set.
6Canonical
CitrixDebian+3 more
8Debian Linux
FedoraLinux Enterprise Desktop+5 more
May 6, 2026
Jun 3, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensiti...Show more
QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.Show less
5Canonical
DebianF5+2 more
25Big Ip Access Policy Manager
Big Ip Advanced Firewall ManagerBig Ip Analytics+22 more
May 6, 2026
May 29, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
5Debian
FedoraprojectLinux+2 more
6Debian Linux
Enterprise MrgFedora+3 more
May 6, 2026
May 27, 2015
N/A· v4
N/A· v3
3.3 LOW· v2
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit settin...Show more
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.Show less
2Fedoraproject
Linux
2Fedora
Linux Kernel
May 6, 2026
May 27, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing...Show more
Stack-based buffer overflow in the get_matching_model_microcode function in arch/x86/kernel/cpu/microcode/intel_early.c in the Linux kernel before 4.0 allows context-dependent attackers to gain privileges by constructing a crafted microcode header and leveraging root privileges for write access to the initrd.Show less
2Dcraw Project
Fedoraproject
2Dcraw
Fedora
May 6, 2026
May 19, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
3Fedoraproject
OracleSquid Cache
4Fedora
LinuxSolaris+1 more
May 6, 2026
May 18, 2015
N/A· v4
N/A· v3
2.6 LOW· v2
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which...Show more
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.Show less
2Fedoraproject
Powerdns
3Authoritative
FedoraRecursor
May 6, 2026
May 18, 2015
N/A· v4
N/A· v3
7.8 HIGH· v2
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to ca...Show more
The label decompression functionality in PowerDNS Recursor 3.5.x, 3.6.x before 3.6.3, and 3.7.x before 3.7.2 and Authoritative (Auth) Server 3.2.x, 3.3.x before 3.3.2, and 3.4.x before 3.4.4 allows remote attackers to cause a denial of service (CPU consumption or crash) via a request with a name that refers to itself.Show less
3Fedoraproject
Libuv ProjectNodejs
3Fedora
LibuvNode.js
May 6, 2026
May 18, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.
3Fedoraproject
GnuOpensuse
3Fedora
Libtasn1Opensuse
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraOpensuse+2 more
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) loa...Show more
The _clone function in XML::LibXML before 2.0119 does not properly set the expand_entities option, which allows remote attackers to conduct XML external entity (XXE) attacks via crafted XML data to the (1) new or (2) load_xml function.Show less
3Digia
FedoraprojectQt
3Fedora
QtQt
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary...Show more
Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image.Show less
3Digia
FedoraprojectQt
3Fedora
QtQt
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and po...Show more
Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted ICO image.Show less
3Digia
FedoraprojectQt
3Fedora
QtQt
May 6, 2026
May 12, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute...Show more
Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted BMP image.Show less