← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Debian
FedoraprojectOpensuse+2 more
5Debian Linux
FedoraOpensuse+2 more
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
3Apache
DebianFedoraproject
3Debian Linux
FedoraXerces C++
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.
2Fedoraproject
Xen
2Fedora
Xen
May 6, 2026
Mar 18, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console b...Show more
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.Show less
3Fedoraproject
OpensuseSuse
3Fedora
OpensuseOpensuse Osc
May 6, 2026
Mar 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
3Debian
FedoraprojectLibssh2
3Debian Linux
FedoraLibssh2
May 6, 2026
Mar 13, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The kex_agree_methods function in libssh2 before 1.5.0 allows remote servers to cause a denial of service (crash) or have other unspecified impact via crafted length values in an SSH_MSG_KEXINIT packet.
3Debian
FedoraprojectXen
3Debian Linux
FedoraXen
May 6, 2026
Mar 12, 2015
N/A· v4
N/A· v3
7.2 HIGH· v2
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (m...Show more
The x86 emulator in Xen 3.2.x through 4.5.x does not properly ignore segment overrides for instructions with register operands, which allows local guest users to obtain sensitive information, cause a denial of service (memory corruption), or possibly execute arbitrary code via unspecified vectors.Show less
3Debian
FedoraprojectXen
3Debian Linux
FedoraXen
May 6, 2026
Mar 12, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors.
1Fedoraproject
2389 Directory Server
Fedora
May 6, 2026
Mar 10, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obta...Show more
389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.Show less
1Fedoraproject
2389 Directory Server
Fedora
May 6, 2026
Mar 10, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via...Show more
389 Directory Server before 1.3.2.27 and 1.3.3.x before 1.3.3.9 does not properly restrict access to the "cn=changelog" LDAP sub-tree, which allows remote attackers to obtain sensitive information from the changelog via unspecified vectors.Show less
2Fedoraproject
Phpmyadmin
2Fedora
Phpmyadmin
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may b...Show more
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a CSRF token and may be sent with HTTP compression, which makes it easier for remote attackers to conduct a BREACH attack and determine this token via a series of crafted requests.Show less
2Bestpractical
Fedoraproject
2Fedora
Request Tracker
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
6.4 MEDIUM· v2
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.
3Bestpractical
DebianFedoraproject
3Debian Linux
FedoraRequest Tracker
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
3Bestpractical
DebianFedoraproject
3Debian Linux
FedoraRequest Tracker
May 6, 2026
Mar 9, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.
2Fedoraproject
Mindrot
2Fedora
Jbcrypt
May 6, 2026
Feb 28, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against h...Show more
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.Show less
2Fedoraproject
Zarafa
3Fedora
WebappZarafa Collaboration Platform
May 6, 2026
Feb 19, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attackers to cause a denial of service (/tmp d...Show more
senddocument.php in Zarafa WebApp before 2.0 beta 3 and WebAccess in Zarafa Collaboration Platform (ZCP) 7.x before 7.1.12 beta 1 and 7.2.x before 7.2.0 beta 1 allows remote attackers to cause a denial of service (/tmp disk consumption) by uploading a large number of files.Show less
4Canonical
DebianE2fsprogs Project+1 more
4Debian Linux
E2fsprogsFedora+1 more
May 6, 2026
Feb 17, 2015
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Heap-based buffer overflow in openfs.c in the libext2fs library in e2fsprogs before 1.42.12 allows local users to execute arbitrary code via crafted block group descriptor data in a filesystem image.
2Fedoraproject
Xen
2Fedora
Xen
May 6, 2026
Feb 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The ARM GIC distributor virtualization in Xen 4.4.x and 4.5.x allows local guests to cause a denial of service by causing a large number messages to be logged.
6Canonical
DebianFedoraproject+3 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+8 more
May 6, 2026
Feb 8, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechani...Show more
bdf/bdflib.c in FreeType before 2.5.4 identifies property names by only verifying that an initial substring is present, which allows remote attackers to discover heap pointer values and bypass the ASLR protection mechanism via a crafted BDF font.Show less
6Canonical
FedoraprojectFreetype+3 more
11Enterprise Linux Desktop
Enterprise Linux Hpc NodeEnterprise Linux Hpc Node Eus+8 more
May 6, 2026
Feb 8, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (inte...Show more
The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.Show less
7Canonical
DebianFedoraproject+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+9 more
May 6, 2026
Feb 8, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and applicat...Show more
Multiple integer signedness errors in the pcf_get_encodings function in pcf/pcfread.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (integer overflow, NULL pointer dereference, and application crash) via a crafted PCF file that specifies negative values for the first column and first row.Show less