← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Canonical
FedoraprojectNetapp+2 more
7Active Iq Unified Manager
Cloud BackupFedora+4 more
Jun 17, 2026
Jan 21, 2020
N/A· v4
2.4 LOW· v3
2.1 LOW· v2
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
5Cacti
DebianFedoraproject+2 more
7Backports Sle
CactiDebian Linux+4 more
Jun 17, 2026
Jan 16, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in dat...Show more
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).Show less
3Debian
FedoraprojectRedislabs
3Debian Linux
FedoraHiredis
Jun 17, 2026
Jan 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
async.c and dict.c in libhiredis.a in hiredis through 0.14.0 allow a NULL pointer dereference because malloc return values are unchecked.
4Fedoraproject
OpensuseOracle+1 more
5Fedora
LeapSolaris+2 more
Jun 17, 2026
Jan 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
2Fedoraproject
Symantec
2Endpoint Detection And Response
Fedora
Jun 17, 2026
Jan 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages vie...Show more
Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access controls such as the same-origin policy.Show less
2Fedoraproject
Symonics
2Fedora
Libmysofa
Jun 17, 2026
Jan 13, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.
5Debian
FedoraprojectOracle+2 more
12Debian Linux
Enterprise LinuxEnterprise Linux Desktop+9 more
Jun 17, 2026
Jan 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
OpenJPEG through 2.3.1 has a heap-based buffer overflow in opj_t1_clbl_decode_processor in openjp2/t1.c because of lack of opj_j2k_update_image_dimensions validation.
5Debian
FedoraprojectGoogle+2 more
7Backports Sle
ChromeDebian Linux+4 more
Jun 17, 2026
Jan 10, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
4Debian
FedoraprojectGoogle+1 more
4Backports Sle
ChromeDebian Linux+1 more
Jun 17, 2026
Jan 10, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
3Fedoraproject
HpRedhat
4389 Directory Server
Directory ServerHp Ux Directory Server+1 more
Nov 21, 2024
Jan 9, 2020
N/A· v4
3.3 LOW· v3
1.9 LOW· v2
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when c...Show more
389 Directory Server before 1.2.7.1 (aka Red Hat Directory Server 8.2) and HP-UX Directory Server before B.08.10.03, when audit logging is enabled, logs the Directory Manager password (nsslapd-rootpw) in cleartext when changing cn=config:nsslapd-rootpw, which might allow local users to obtain sensitive information by reading the log.Show less
2Fedoraproject
Gnome
2Fedora
Glib
Jun 17, 2026
Jan 9, 2020
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is...Show more
GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy is used to help with privacy/anonymity, even though there is no technical barrier to a direct connection. NOTE: versions before 2.60 are unaffected.Show less
6Canonical
DebianE2fsprogs Project+3 more
7Debian Linux
E2fsprogsFedora+4 more
Jun 17, 2026
Jan 8, 2020
N/A· v4
6.7 MEDIUM· v3
4.4 MEDIUM· v2
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An...Show more
A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.Show less
2Fedoraproject
Thekelleys
2Dnsmasq
Fedora
Jun 17, 2026
Jan 7, 2020
N/A· v4
3.7 LOW· v3
4.3 MEDIUM· v2
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraPillow+1 more
Jun 17, 2026
Jan 5, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results...Show more
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being terminated by the OOM killer.Show less
3Fedoraproject
FontforgeOpensuse
3Fedora
FontforgeLeap
Jun 17, 2026
Jan 3, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.
3Fedoraproject
RedhatZend
3Enterprise Linux
FedoraZend Framework
Nov 21, 2024
Jan 3, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Fo...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Zend Framework 2.0.x before 2.0.1 allow remote attackers to inject arbitrary web script or HTML via unspecified input to (1) Debug, (2) Feed\PubSubHubbub, (3) Log\Formatter\Xml, (4) Tag\Cloud\Decorator, (5) Uri, (6) View\Helper\HeadStyle, (7) View\Helper\Navigation\Sitemap, or (8) View\Helper\Placeholder\Container\AbstractStandalone, related to Escaper.Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraPillow+1 more
Jun 17, 2026
Jan 3, 2020
N/A· v4
7.1 HIGH· v3
5.8 MEDIUM· v2
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraPillow+1 more
Jun 17, 2026
Jan 3, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraPillow+1 more
Jun 17, 2026
Jan 3, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.
3Canonical
FedoraprojectPython
3Fedora
PillowUbuntu Linux
Jun 17, 2026
Jan 3, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.