Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectLibpoe Component Irc Perl Project3Debian Linux FedoraLibpoe Component Irc PerlNov 21, 2024 Nov 12, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraTnef+1 moreJun 17, 2026 Nov 11, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read...Show more |
3Debian FedoraprojectRedhat3389 Directory Server Debian LinuxEnterprise LinuxJun 17, 2026 Nov 8, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 A flaw was found in the 'deref' plugin of 389-ds-base where it could use the 'search' permission to display attribute values. In some configurations, this could allow an authenticated attacker to view private attributes,...Show more |
3Ceph FedoraprojectRedhat3Ceph Ceph StorageFedoraJun 17, 2026 Nov 8, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connectio...Show more |
2Fedoraproject Redhat2Fedora TunedNov 21, 2024 Nov 8, 2019 N/A· v4 5.5 MEDIUM· v3 4.7 MEDIUM· v2 tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service. |
3Debian FedoraprojectOpenttd3Debian Linux FedoraOpenttdNov 21, 2024 Nov 7, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server. |
3Fedoraproject LinuxRedhat3Enterprise Linux FedoraLinux KernelJun 17, 2026 Nov 7, 2019 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_para...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Nov 7, 2019 N/A· v4 4.6 MEDIUM· v3 4.9 MEDIUM· v2 A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559. |
4Canonical FedoraprojectLinux+1 more4Fedora LeapLinux Kernel+1 moreJun 17, 2026 Nov 7, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247. |
5Canonical DebianDjvulibre Project+2 more5Debian Linux DjvulibreFedora+2 moreJun 17, 2026 Nov 7, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp. |
2Fedoraproject Redhat3Enterprise Linux FedoraPagureNov 21, 2024 Nov 6, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Pagure: XSS possible in file attachment endpoint |
2Fedoraproject Oracle2Fedora Mysql Gui ToolsNov 21, 2024 Nov 6, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console |
3Fedoraproject OpensuseSamba3Fedora LeapSambaJun 17, 2026 Nov 6, 2019 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A flaw was found in samba 4.0.0 before samba 4.9.15 and samba 4.10.x before 4.10.10. An attacker can crash AD DC LDAP server via dirsync resulting in denial of service. Privilege escalation is not possible with this issu...Show more |
3Fedoraproject OpensuseSamba3Fedora LeapSambaJun 17, 2026 Nov 6, 2019 N/A· v4 5.4 MEDIUM· v3 4.9 MEDIUM· v2 A flaw was found in Samba, all versions starting samba 4.5.0 before samba 4.9.15, samba 4.10.10, samba 4.11.2, in the way it handles a user password change or a new password for a samba user. The Samba Active Directory D...Show more |
2Fedoraproject Samba2Fedora SambaJun 17, 2026 Nov 6, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files...Show more |
5Debian FedoraprojectPypa+2 more6Debian Linux FedoraOpenshift+3 moreNov 21, 2024 Nov 5, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks. |
4Fedoraproject OpensusePhp Gettext Project+1 more4Enterprise Linux FedoraLeap+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code. |
3Fedoraproject RedhatReviewboard4Djblets Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests. |
4Debian FedoraprojectRedhat+1 more4Debian Linux Enterprise LinuxFedora+1 moreNov 21, 2024 Nov 4, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories. |
3Debian FedoraprojectSmokeping3Debian Linux FedoraSmokepingNov 21, 2024 Nov 1, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. |