Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Fedoraproject OpensusePhpmyadmin4Backports Sle FedoraLeap+1 moreJun 17, 2026 Nov 22, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 22, 2019 N/A· v4 4.7 MEDIUM· v3 3.3 LOW· v2 libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibarchive+1 moreJun 17, 2026 Nov 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Libarchive 3.4.0, archive_wstring_append_from_mbs in archive_string.c has an out-of-bounds read because of an incorrect mbrtowc or mbtowc call. For example, bsdtar crashes via a crafted archive. |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 Nov 21, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation sho...Show more |
2Fedoraproject Sensiolabs2Fedora SymfonyJun 17, 2026 Nov 21, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. The UriSigner was subject to timing attacks. This is related to symfony/http-kernel. |
3Debian FedoraprojectOniguruma Project3Debian Linux FedoraOnigurumaJun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-...Show more |
2Fedoraproject Oniguruma Project2Fedora OnigurumaJun 17, 2026 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function gb18030_mbc_enc_len in file gb18030.c, a UChar pointer is dereferenced without checking if it passed the end of the matched string. This leads to...Show more |
2Fedoraproject Ikiwiki2Fedora IkiwikiNov 21, 2024 Nov 21, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify actio...Show more |
2Fedoraproject Sillycycle2Fedora XlockmoreNov 21, 2024 Nov 21, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 xlockmore before 5.43 'dclock' security bypass vulnerability |
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information. |
4Debian FedoraprojectMediawiki+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 20, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request. |
3Debian FedoraprojectRedhat7Debian Linux Enterprise LinuxEnterprise Linux Desktop+4 moreNov 21, 2024 Nov 20, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 tuned 2.10.0 creates its PID file with insecure permissions which allows local users to kill arbitrary processes. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraGlibc+1 moreJun 17, 2026 Nov 19, 2019 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 On the x86-64 architecture, the GNU C Library (aka glibc) before 2.31 fails to ignore the LD_PREFER_MAP_32BIT_EXEC environment variable during program execution after a security transition, allowing local attackers to re...Show more |
3Debian FedoraprojectLinuxfoundation3Debian Linux FedoraFoomatic FiltersNov 21, 2024 Nov 19, 2019 N/A· v4 5.5 MEDIUM· v3 3.3 LOW· v2 foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduc...Show more |
3Fedoraproject NlnetlabsOpensuse3Fedora LeapUnboundJun 17, 2026 Nov 19, 2019 N/A· v4 7.3 HIGH· v3 6.8 MEDIUM· v2 Unbound 1.6.4 through 1.9.4 contain a vulnerability in the ipsec module that can cause shell code execution after receiving a specially crafted answer. This issue can only be triggered if unbound was compiled with `--ena...Show more |
3Fedoraproject RedhatTrusted Boot Project3Enterprise Linux FedoraTrusted BootNov 21, 2024 Nov 18, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability |
3Fedoraproject LinuxOpensuse3Fedora LeapLinux KernelJun 17, 2026 Nov 18, 2019 N/A· v4 4.0 MEDIUM· v3 2.1 LOW· v2 Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This aff...Show more |
4Canonical FedoraprojectLinux+1 more4Enterprise Linux FedoraLinux Kernel+1 moreJun 17, 2026 Nov 18, 2019 N/A· v4 4.4 MEDIUM· v3 4.9 MEDIUM· v2 A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6. |
2Fedoraproject Linux2Fedora Linux KernelJun 17, 2026 Nov 18, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 A memory leak in the spi_gpio_probe() function in drivers/spi/spi-gpio.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering devm_add_action_or_reset() fail...Show more |