Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Sensiolabs2Fedora SymfonyNov 21, 2024 Jan 2, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Symfony 2.0.X before 2.0.24, 2.1.X before 2.1.12, 2.2.X before 2.2.5, and 2.3.X before 2.3.3 have an issue in the HttpFoundation component. The Host header can be manipulated by an attacker when the framework is generati...Show more |
5Canonical DebianEglibc+2 more5Debian Linux EglibcFedora+2 moreNov 21, 2024 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service. |
2Fedoraproject Gksu Polkit Project2Fedora Gksu PolkitNov 21, 2024 Dec 31, 2019 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue. |
2Fedoraproject Pureftpd2Fedora Pure FtpdJun 17, 2026 Dec 31, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c. |
2Fedoraproject Freeciv2Fedora FreecivNov 21, 2024 Dec 30, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exha...Show more |
4Debian FedoraprojectOpenstack+1 more4Debian Linux FedoraHorizon+1 moreNov 21, 2024 Dec 30, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value. |
2Fedoraproject Podofo Project2Fedora PodofoJun 17, 2026 Dec 30, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp. |
2Fedoraproject Upx2Fedora UpxJun 17, 2026 Dec 27, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service. |
2Fedoraproject Upx2Fedora UpxJun 17, 2026 Dec 27, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file. |
A flaw was found in SSSD version 1.9.0. The SSSD's access-provider logic causes the result of the HBAC rule processing to be ignored in the event that the access-provider is also handling the setup of the user's SELinux...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 26, 2019 N/A· v4 8.2 HIGH· v3 6.4 MEDIUM· v2 In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential fo...Show more |
7Canonical DebianFedoraproject+4 more12Active Iq Unified Manager Clustered Data OntapClustered Data Ontap Antivirus Connector+9 moreJun 17, 2026 Dec 24, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs. |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will caus...Show more |
4Debian FedoraprojectPhp+1 more4Debian Linux FedoraPhp+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowerc...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraPhp+1 moreJun 17, 2026 Dec 23, 2019 N/A· v4 6.5 MEDIUM· v3 6.4 MEDIUM· v2 When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will caus...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP bcmath extension functions on some systems, including Windows, can be tricked into reading beyond the allocated space by supplying it with string cont...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Dec 23, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0, PHP DirectoryIterator class accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabiliti...Show more |
3Fedoraproject PhpTenable3Fedora PhpSecuritycenterJun 17, 2026 Dec 23, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabil...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to...Show more |
5Agendaless DebianFedoraproject+2 more5Communications Cloud Native Core Network Function Cloud Native Environment Debian LinuxFedora+2 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a lin...Show more |