Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue was discovered in the selinux-policy (aka Reference Policy) package 3.14 through 2020-08-24 because the .config/Yubico directory is mishandled. Consequently, when SELinux is in enforced mode, pam-u2f is not allo...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Aug 24, 2020 N/A· v4 7.5 HIGH· v3 7.1 HIGH· v2 Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer...Show more |
3Canonical FedoraprojectTuxfamily3Chrony FedoraUbuntu LinuxJun 17, 2026 Aug 24, 2020 N/A· v4 6.0 MEDIUM· v3 3.6 LOW· v2 A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writ...Show more |
6Canonical DebianFedoraproject+3 more6Bind Debian LinuxFedora+3 moreJun 17, 2026 Aug 21, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has...Show more |
7Canonical DebianFedoraproject+4 more7Bind Debian LinuxDns Server+4 moreJun 17, 2026 Aug 21, 2020 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query p...Show more |
8Canonical DebianFedoraproject+5 more8Bind Communications Diameter Signaling RouterDebian Linux+5 moreJun 17, 2026 Aug 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the serve...Show more |
2Fedoraproject Microsoft4Asp.net Core FedoraVisual Studio 2017+1 moreJun 17, 2026 Aug 17, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A denial of service vulnerability exists when ASP.NET Core improperly handles web requests. An attacker who successfully exploited this vulnerability could cause a denial of service against an ASP.NET Core web applicatio...Show more |
8Canonical DebianFedoraproject+5 more15Debian Linux Directory ServerFedora+12 moreJun 17, 2026 Aug 17, 2020 N/A· v4 10.0 CRITICAL· v3 9.3 HIGH· v2 An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successful...Show more |
3Debian FedoraprojectLua3Debian Linux FedoraLuaJun 17, 2026 Aug 17, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31). |
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row. |
2Fedoraproject Trustedcomputinggroup2Fedora TrousersJun 17, 2026 Aug 13, 2020 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt exis...Show more |
2Fedoraproject Trousers Project2Fedora TrousersJun 17, 2026 Aug 13, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the tss user still has read and write access to the /etc/tcsd.conf file (which contains various settings related to...Show more |
2Fedoraproject Trousers Project2Fedora TrousersJun 17, 2026 Aug 13, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges instead of by the tss user, it fails to drop the root gid privilege when no longer needed. |
4Fedoraproject OpensuseOracle+1 more4Fedora LeapWireshark+1 moreJun 17, 2026 Aug 13, 2020 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression. |
3Debian FedoraprojectQt3Debian Linux FedoraQtJun 17, 2026 Aug 12, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 An issue was discovered in Qt through 5.12.9, and 5.13.x through 5.15.x before 5.15.1. read_xbm_body in gui/image/qxbmhandler.cpp has a buffer over-read. |
4Canonical DebianDovecot+1 more4Debian Linux DovecotFedora+1 moreJun 17, 2026 Aug 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled. |
4Canonical DebianDovecot+1 more4Debian Linux DovecotFedora+1 moreJun 17, 2026 Aug 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Dovecot before 2.3.11.3, sending a specially formatted NTLM request will crash the auth service because of an out-of-bounds read. |
4Canonical DebianDovecot+1 more4Debian Linux DovecotFedora+1 moreJun 17, 2026 Aug 12, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Dovecot before 2.3.11.3, uncontrolled recursion in submission, lmtp, and lda allows remote attackers to cause a denial of service (resource consumption) via a crafted e-mail message with deeply nested MIME parts. |
2Fedoraproject Roundcube2Fedora WebmailJun 17, 2026 Aug 12, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15. |
2Fedoraproject Radare2Fedora Radare2Jun 17, 2026 Aug 11, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECUR...Show more |