← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Mozilla
2Bugzilla
Fedora
May 6, 2026
Feb 1, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and tr...Show more
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.Show less
3Fedoraproject
OpensuseXiph
3Fedora
OpensuseVorbis Tools
May 6, 2026
Jan 23, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.
3Fedoraproject
OpensuseXiph
3Fedora
OpensuseVorbis Tools
May 6, 2026
Jan 23, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (divide-by-zero error and crash) via a WAV file with the number of channels set to zero.
7Canonical
DebianFedoraproject+4 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+11 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DDL : Foreign Key.
6Canonical
DebianFedoraproject+3 more
8Communications Policy Management
Debian LinuxEnterprise Linux+5 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security...Show more
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.Show less
37 Zip
FedoraprojectOracle
3Fedora
P7zipSolaris
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
p7zip 9.20.1 allows remote attackers to write to arbitrary files via a symlink attack in an archive.
5Canonical
DebianFedoraproject+2 more
6Debian Linux
Enterprise LinuxFedora+3 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
7Canonical
DebianFedoraproject+4 more
10Debian Linux
Enterprise LinuxFedora+7 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
5.4 MEDIUM· v2
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related...Show more
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot.Show less
7Canonical
DebianFedoraproject+4 more
17Communications Policy Management
Debian LinuxEnterprise Linux Desktop+14 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability tha...Show more
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0381.Show less
7Canonical
DebianFedoraproject+4 more
17Communications Policy Management
Debian LinuxEnterprise Linux Desktop+14 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability tha...Show more
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.Show less
7Canonical
DebianFedoraproject+4 more
16Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+13 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Forei...Show more
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.Show less
7Canonical
DebianFedoraproject+4 more
16Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+13 more
May 6, 2026
Jan 21, 2015
N/A· v4
N/A· v3
3.5 LOW· v2
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
4Fedoraproject
OpensuseOracle+1 more
4Fedora
OpensusePillow+1 more
May 6, 2026
Jan 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Pillow before 2.7.0 allows remote attackers to cause a denial of service via a compressed text chunk in a PNG image that has a large size when it is decompressed.
2Context Project
Fedoraproject
2Context
Fedora
May 6, 2026
Jan 15, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the...Show more
Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.Show less
4Canonical
DebianFedoraproject+1 more
4Binutils
Debian LinuxFedora+1 more
May 6, 2026
Jan 15, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended nam...Show more
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.Show less
7Canonical
DebianFedoraproject+4 more
19Debian Linux
Enterprise Linux AusEnterprise Linux Desktop+16 more
May 6, 2026
Jan 9, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism...Show more
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.Show less
6Canonical
DebianFedoraproject+3 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+8 more
May 6, 2026
Jan 9, 2015
N/A· v4
N/A· v3
6.9 MEDIUM· v2
Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other i...Show more
Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger access to a key structure member during garbage collection of a key.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraOpensuse+2 more
May 6, 2026
Jan 7, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
strongSwan 4.5.x through 5.2.x before 5.2.1 allows remote attackers to cause a denial of service (invalid pointer dereference) via a crafted IKEv2 Key Exchange (KE) message with Diffie-Hellman (DH) group 1025.
2Apache
Fedoraproject
2Fedora
Poi
May 6, 2026
Jan 6, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
2Exiv2
Fedoraproject
2Exiv2
Fedora
May 6, 2026
Jan 2, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cause a denial of service (crash) via a long IKEY INFO tag value in an AVI file.