← Back

Fedora

fedora

Vendor: Fedoraproject • 5,353 CVEs

CVEs (5,353)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
10Fedoraproject
FreebsdHp+7 more
12Bind
Business ServerDnsco Bind+9 more
Apr 29, 2026
Jul 29, 2013
N/A· v4
N/A· v3
7.8 HIGH· v2
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause...Show more
The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during construction of a log message, as exploited in the wild in July 2013.Show less
2F5
Fedoraproject
2Fedora
Nginx
Apr 29, 2026
Jul 20, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request wi...Show more
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request with a large chunk size, which triggers an integer signedness error and a stack-based buffer overflow.Show less
3Fedoraproject
MoxiecodeWordpress
3Fedora
PluploadWordpress
Apr 29, 2026
Jul 8, 2013
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id...Show more
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.Show less
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLibxcb+3 more
Apr 29, 2026
Jun 15, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
6Canonical
DebianFedoraproject+3 more
10Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+7 more
Apr 29, 2026
May 29, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and ba...Show more
schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and bandwidth consumption) via a forged packet that triggers a communication loop, as demonstrated by krb_pingpong.nasl, a related issue to CVE-1999-0103.Show less
4Debian
FedoraprojectOpensuse+1 more
4Debian Linux
FedoraModsecurity+1 more
Apr 29, 2026
Apr 25, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjun...Show more
ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjunction with an entity reference, aka an XML External Entity (XXE) vulnerability.Show less
4Fedoraproject
MitOpensuse+1 more
8Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+5 more
Apr 29, 2026
Apr 19, 2013
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticate...Show more
The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.Show less
3Canonical
FedoraprojectTransmissionbt
3Fedora
TransmissionUbuntu Linux
Apr 29, 2026
Apr 3, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via craf...Show more
Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."Show less
2Fedoraproject
Moodle
2Fedora
Moodle
Apr 29, 2026
Mar 25, 2013
N/A· v4
N/A· v3
5.0 MEDIUM· v2
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile...Show more
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile information by leveraging the guest role, as demonstrated by a Google search.Show less
2Fedoraproject
Redhat
2Enterprise Linux
Fedora
Apr 29, 2026
Mar 1, 2013
N/A· v4
N/A· v3
1.9 LOW· v2
The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, wh...Show more
The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, which makes it easier for context-dependent attackers to bypass the ASLR protection mechanism by leveraging a predictable base address for one of these libraries.Show less
3Debian
FedoraprojectZend
3Debian Linux
FedoraZend Framework
Apr 29, 2026
Feb 13, 2013
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external...Show more
Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external entity reference in a DOCTYPE element in an XML-RPC request, aka an XML external entity (XXE) injection attack.Show less
7Canonical
DebianFedoraproject+4 more
12Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+9 more
Apr 29, 2026
Feb 13, 2013
N/A· v4
N/A· v3
9.3 HIGH· v2
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (g...Show more
Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (guest OS crash) and possibly execute arbitrary guest code via a large packet.Show less
5Canonical
FedoraprojectOpensuse+2 more
11Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+8 more
Apr 29, 2026
Feb 8, 2013
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers t...Show more
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which causes a message to be freed without being removed from the message queue.Show less
4Canonical
FedoraprojectInkscape+1 more
4Fedora
InkscapeOpensuse+1 more
Apr 29, 2026
Jan 18, 2013
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
3Fedoraproject
OpensuseTrustwave
3Fedora
ModsecurityOpensuse
Apr 29, 2026
Dec 28, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes th...Show more
The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.Show less
2Dokuwiki
Fedoraproject
2Dokuwiki
Fedora
Apr 29, 2026
Nov 20, 2012
N/A· v4
N/A· v3
4.3 MEDIUM· v2
doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an e...Show more
doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.Show less
3Fedoraproject
OpenstackRedhat
7Enterprise Linux Server
FedoraGluster Storage Management Console+4 more
Apr 29, 2026
Oct 22, 2012
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a cra...Show more
OpenStack Object Storage (swift) before 1.7.0 uses the loads function in the pickle Python module unsafely when storing and loading metadata in memcached, which allows remote attackers to execute arbitrary code via a crafted pickle object.Show less
3Dracut Project
FedoraprojectRedhat
5Dracut
Enterprise Linux DesktopEnterprise Linux Server+2 more
Apr 29, 2026
Oct 9, 2012
N/A· v4
N/A· v3
2.1 LOW· v2
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive infor...Show more
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.Show less
2Fedoraproject
Guac Dev
2Fedora
Guacamole
Apr 29, 2026
Oct 1, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the guac_client_plugin_open function in libguac in Guacamole before 0.6.3 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long protocol name.
5Apache
DebianFedoraproject+2 more
10Debian Linux
Enterprise LinuxEnterprise Linux Desktop+7 more
Apr 29, 2026
Jun 21, 2012
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly ex...Show more
Integer overflow in the vclmi.dll module in OpenOffice.org (OOo) 3.3, 3.4 Beta, and possibly earlier, and LibreOffice before 3.5.3, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted embedded image object, as demonstrated by a JPEG image in a .DOC file, which triggers a heap-based buffer overflow.Show less