Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
5Canonical DebianFedoraproject+2 more6Debian Linux FedoraJboss Amq Clients+3 moreJun 17, 2026 Jan 29, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 HttpObjectDecoder.java in Netty before 4.1.44 allows an HTTP header that lacks a colon, which might be interpreted as a separate header with an incorrect syntax, or might be interpreted as an "invalid fold." |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraOpensmtpd+1 moreJun 17, 2026 Jan 29, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session, as demonstrated by shell metacharacte...Show more |
3Debian FedoraprojectLldpd Project3Debian Linux FedoraLldpdNov 21, 2024 Jan 28, 2020 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving l...Show more |
2Fedoraproject Pyrad Project2Fedora PyradNov 21, 2024 Jan 28, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack. |
2Fedoraproject Smb4k Project2Fedora Smb4kNov 21, 2024 Jan 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit. |
2Fedoraproject Python2Fedora Py BcryptNov 21, 2024 Jan 28, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be ov...Show more |
2Fedoraproject Module Metadata Project2Fedora Module MetadataNov 21, 2024 Jan 28, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Eval injection vulnerability in the Module-Metadata module before 1.000015 for Perl allows remote attackers to execute arbitrary Perl code via the $Version value. |
5Canonical DebianFedoraproject+2 more428Celeron 3855u Firmware Celeron 3865u FirmwareCeleron 3955u Firmware+425 moreJun 17, 2026 Jan 28, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Cleanup errors in some data cache evictions for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |
4Debian FedoraprojectNetty+1 more6Debian Linux FedoraJboss Enterprise Application Platform+3 moreJun 17, 2026 Jan 27, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an inc...Show more |
Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564. |
3Apereo DebianFedoraproject5.net Cas Client Debian LinuxFedora+2 moreNov 21, 2024 Jan 24, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow rem...Show more |
5Apache CanonicalDebian+2 more5Debian Linux FedoraSoftware Collections+2 moreJun 17, 2026 Jan 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An untrusted deserialization was found in the org.apache.xmlrpc.parser.XmlRpcResponseParser:addResult method of Apache XML-RPC (aka ws-xmlrpc) library. A malicious XML-RPC server could target a XML-RPC client causing it...Show more |
3Arista FedoraprojectQemu3Eos FedoraQemuNov 21, 2024 Jan 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message. |
4Arista CanonicalFedoraproject+1 more4Eos FedoraQemu+1 moreNov 21, 2024 Jan 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The ne2000_receive function in hw/net/ne2000.c in QEMU before 2.4.0.1 allows attackers to cause a denial of service (infinite loop and instance crash) or possibly execute arbitrary code via vectors related to receiving p...Show more |
5Arista CanonicalFedoraproject+2 more8Eos FedoraLinux Enterprise Debuginfo+5 moreNov 21, 2024 Jan 23, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Integer overflow in the VNC display driver in QEMU before 2.1.0 allows attachers to cause a denial of service (process crash) via a CLIENT_CUT_TEXT message, which triggers an infinite loop. |
3Arm DebianFedoraproject4Debian Linux FedoraMbed Crypto+1 moreJun 17, 2026 Jan 23, 2020 N/A· v4 4.7 MEDIUM· v3 1.9 LOW· v2 The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key v...Show more |
7Canonical DebianFedoraproject+4 more24Clustered Data Ontap Communications Cloud Native Core Network Function Cloud Native EnvironmentDebian Linux+21 moreJun 17, 2026 Jan 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlStringLenDecodeEntities in parser.c in libxml2 2.9.10 has an infinite loop in a certain end-of-file situation. |
6Debian FedoraprojectNetapp+3 more24Cloud Backup Clustered Data OntapCommunications Cloud Native Core Network Function Cloud Native Environment+21 moreJun 17, 2026 Jan 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlSchemaPreRun in xmlschemas.c in libxml2 2.9.10 allows an xmlSchemaValidateStream memory leak. |
2Fedoraproject Owasp2Fedora ModsecurityJun 17, 2026 Jan 21, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw i...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux Directory ServerDiskstation Manager+7 moreJun 17, 2026 Jan 21, 2020 N/A· v4 6.5 MEDIUM· v3 2.6 LOW· v2 All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character c...Show more |