Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject Lout ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. |
3Fedoraproject Lout ProjectOpensuse4Backports Sle FedoraLeap+1 moreJun 17, 2026 Dec 20, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c. |
7Apache AppleCanonical+4 more19Bookkeeper Cyrus SaslDebian Linux+16 moreJun 17, 2026 Dec 19, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in...Show more |
3Fedoraproject OpensuseRack3Fedora LeapRackJun 17, 2026 Dec 18, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing att...Show more |
5Apache DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreNov 4, 2025 Dec 18, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current m...Show more |
2Elog Project Fedoraproject2Elog FedoraJun 17, 2026 Dec 17, 2019 N/A· v4 6.5 MEDIUM· v3 7.5 HIGH· v2 ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests. |
2Elog Project Fedoraproject2Elog FedoraJun 17, 2026 Dec 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request. |
2Elog Project Fedoraproject2Elog FedoraJun 17, 2026 Dec 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multiple HTTP POST requests which causes the E...Show more |
2Elog Project Fedoraproject2Elog FedoraJun 17, 2026 Dec 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP POST request. |
2Elog Project Fedoraproject2Elog FedoraJun 17, 2026 Dec 17, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration...Show more |
4Canonical CyrusDebian+1 more4Debian Linux FedoraImap+1 moreJun 17, 2026 Dec 16, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 An issue was discovered in Cyrus IMAP before 2.5.15, 3.0.x before 3.0.13, and 3.1.x through 3.1.8. If sieve script uploading is allowed (3.x) or certain non-default sieve options are enabled (2.x), a user with a mail acc...Show more |
3Debian FedoraprojectXfig Project3Debian Linux FedoraFig2devJun 17, 2026 Dec 15, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. |
2Dovecot Fedoraproject2Dovecot FedoraJun 17, 2026 Dec 13, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the s...Show more |
2Atasm Project Fedoraproject2Atasm FedoraJun 17, 2026 Dec 13, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file. |
2Atasm Project Fedoraproject2Atasm FedoraJun 17, 2026 Dec 13, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file. |
2Atasm Project Fedoraproject2Atasm FedoraJun 17, 2026 Dec 13, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file. |
5Fedoraproject NpmjsOpensuse+2 more6Enterprise Linux Enterprise Linux EusFedora+3 moreJun 17, 2026 Dec 13, 2019 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 Versions of the npm CLI prior to 6.13.4 are vulnerable to an Arbitrary File Overwrite. It fails to prevent existing globally-installed binaries to be overwritten by other package installations. For example, if a package...Show more |
5Fedoraproject NpmjsOpensuse+2 more6Enterprise Linux Enterprise Linux EusFedora+3 moreJun 17, 2026 Dec 13, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It fails to prevent access to folders outside of the intended node_modules folder through the bin field. A properly constructed entry in...Show more |
5Fedoraproject NpmjsOpensuse+2 more6Enterprise Linux Enterprise Linux EusFedora+3 moreJun 17, 2026 Dec 13, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A prop...Show more |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Dec 12, 2019 N/A· v4 6.7 MEDIUM· v3 6.5 MEDIUM· v2 In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h). |