← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Apache
CanonicalFedoraproject+2 more
50Agile Engineering Data Management
AntBanking Enterprise Collections+47 more
Jun 17, 2026
May 14, 2020
N/A· v4
6.3 MEDIUM· v3
3.3 LOW· v2
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replacer...Show more
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.Show less
4Canonical
CiscoDebian+1 more
4Clam Antivirus
Debian LinuxFedora+1 more
Jun 17, 2026
May 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device....Show more
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read. An attacker could exploit this vulnerability by sending a crafted PDF file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.Show less
4Canonical
CiscoDebian+1 more
4Clam Antivirus
Debian LinuxFedora+1 more
Jun 17, 2026
May 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vul...Show more
A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process crash, resulting in a denial of service condition.Show less
4Debian
FedoraprojectInfradead+1 more
4Debian Linux
FedoraLeap+1 more
Jun 17, 2026
May 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
OpenConnect 8.09 has a buffer overflow, causing a denial of service (application crash) or possibly unspecified other impact, via crafted certificate data to get_cert_name in gnutls.c.
2Fedoraproject
Nextcloud
2Fedora
Mail
Jun 17, 2026
May 12, 2020
N/A· v4
7.0 HIGH· v3
6.8 MEDIUM· v2
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
2Fedoraproject
Nextcloud
2Fedora
Group Folders
Jun 17, 2026
May 12, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
2Fedoraproject
Rubyonrails
2Active Resource
Fedora
Jun 17, 2026
May 12, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
4Apache
FedoraprojectNetapp+1 more
7Application Testing Suite
FedoraHospitality Opera 5+4 more
Nov 21, 2024
May 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration...Show more
Apache log4net versions before 2.0.10 do not disable XML external entities when parsing log4net configuration files. This allows for XXE-based attacks in applications that accept attacker-controlled log4net configuration files.Show less
3Fedoraproject
Libemf ProjectOpensuse
3Fedora
LeapLibemf
Jun 17, 2026
May 11, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
3Fedoraproject
Libemf ProjectOpensuse
3Fedora
LeapLibemf
Jun 17, 2026
May 11, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
3Fedoraproject
Libemf ProjectOpensuse
3Fedora
LeapLibemf
Jun 17, 2026
May 11, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 2 of 2).
3Fedoraproject
Libemf ProjectOpensuse
3Fedora
LeapLibemf
Jun 17, 2026
May 11, 2020
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
4Canonical
DebianExim+1 more
4Debian Linux
EximFedora+1 more
Jun 17, 2026
May 11, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Exim through 4.93 has an out-of-bounds read in the SPA authenticator that could result in SPA/NTLM authentication bypass in auths/spa.c and auths/auth-spa.c.
5Canonical
DebianFedoraproject+2 more
23A700s Firmware
Active Iq Unified ManagerBootstrap Os+20 more
Jun 17, 2026
May 9, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraJson C+2 more
Jun 17, 2026
May 9, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
2Broadcom
Fedoraproject
2Fedora
Tcpreplay
Jun 17, 2026
May 8, 2020
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.
2Fedoraproject
Qutebrowser
2Fedora
Qutebrowser
Jun 17, 2026
May 7, 2020
N/A· v4
3.5 LOW· v3
4.3 MEDIUM· v2
In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.war...Show more
In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly displayed as green (colors.statusbar.url.success_https). While the user already has seen a certificate error prompt at this point (or set content.ssl_strict to false, which is not recommended), this could still provide a false sense of security. This has been fixed in 1.11.1 and 1.12.0. All versions of qutebrowser are believed to be affected, though versions before v0.11.x couldn't be tested. Backported patches for older versions (greater than or equal to 1.4.0 and less than or equal to 1.10.2) are available, but no further releases are planned.Show less
5Canonical
DebianFedoraproject+2 more
6Backports Sle
Debian LinuxFedora+3 more
Jun 17, 2026
May 6, 2020
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
/options/mailman in GNU Mailman before 2.1.31 allows Arbitrary Content Injection.
4Debian
FedoraprojectOpensuse+1 more
4Debian Linux
FedoraLeap+1 more
Jun 17, 2026
May 6, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overf...Show more
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.Show less
2Fedoraproject
Go Macaron
2Fedora
Macaron
Jun 17, 2026
May 5, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
macaron before 1.3.7 has an open redirect in the static handler, as demonstrated by the http://127.0.0.1:4000//example.com/ URL.