Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Canonical DebianFedoraproject+5 more20Active Iq Unified Manager Communications Design StudioDebian Linux+17 moreJun 17, 2026 Sep 9, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner." |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLeap+2 moreJun 17, 2026 Sep 9, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 sysstat before 12.1.6 has memory corruption due to an Integer Overflow in remap_struct() in sa_common.c. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraOniguruma+1 moreJun 17, 2026 Sep 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c. |
4Debian FedoraprojectNic+1 more4Backports Sle BirdDebian Linux+1 moreJun 17, 2026 Sep 9, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 BIRD Internet Routing Daemon 1.6.x through 1.6.7 and 2.x through 2.0.5 has a stack-based buffer overflow. The BGP daemon's support for RFC 8203 administrative shutdown communication messages included an incorrect logical...Show more |
4Debian FedoraprojectImapfilter Project+1 more5Backports Sle Debian LinuxFedora+2 moreNov 21, 2024 Sep 8, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. |
6Canonical DebianFedoraproject+3 more6Debian Linux Enterprise LinuxFedora+3 moreJun 17, 2026 Sep 6, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the sha...Show more |
7Canonical DebianFedoraproject+4 more10Communications Operations Monitor Debian LinuxFedora+7 moreJun 17, 2026 Sep 6, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Python through 2.7.16, 3.x through 3.5.7, 3.6.x through 3.6.9, and 3.7.x through 3.7.4. The email module wrongly parses email addresses that contain multiple @ characters. An application that u...Show more |
5Artifex DebianFedoraproject+2 more12Debian Linux Enterprise LinuxEnterprise Linux Desktop+9 moreJun 17, 2026 Sep 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A flaw was found in ghostscript, versions 9.x before 9.50, in the setsystemparams procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted Po...Show more |
3Debian FedoraprojectOpensc Project3Debian Linux FedoraOpenscJun 17, 2026 Sep 5, 2019 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c. |
3Debian FedoraprojectOpensc Project3Debian Linux FedoraOpenscJun 17, 2026 Sep 5, 2019 N/A· v4 6.4 MEDIUM· v3 4.4 MEDIUM· v2 OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c. |
3Fedoraproject RedhatSystemd Project14Enterprise Linux Enterprise Linux EusEnterprise Linux For Ibm Z Systems 8 S390x+11 moreJun 17, 2026 Sep 4, 2019 N/A· v4 4.4 MEDIUM· v3 3.6 LOW· v2 In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incomin...Show more |
5Artifex DebianFedoraproject+2 more5Debian Linux FedoraGhostscript+2 moreJun 17, 2026 Sep 3, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in, ghostscript versions prior to 9.50, in the .pdfexectoken and other procedures where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially cra...Show more |
5Artifex DebianFedoraproject+2 more5Debian Linux FedoraGhostscript+2 moreJun 17, 2026 Sep 3, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafte...Show more |
3Apache FedoraprojectOracle19Banking Payments Banking PlatformCommons Compress+16 moreJun 17, 2026 Aug 30, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The file name encoding algorithm used internally in Apache Commons Compress 1.15 to 1.18 can get into an infinite loop when faced with specially crafted inputs. This can lead to a denial of service attack if an attacker...Show more |
3Debian DovecotFedoraproject4Debian Linux DovecotFedora+1 moreJun 17, 2026 Aug 29, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Dovecot before 2.2.36.4 and 2.3.x before 2.3.7.2 (and Pigeonhole before 0.5.7.2), protocol processing can fail for quoted strings. This occurs because '\0' characters are mishandled, and can lead to out-of-bounds writ...Show more |
6Canonical DebianFedoraproject+3 more18Aff A700s Firmware Data Availability ServicesDebian Linux+15 moreJun 17, 2026 Aug 25, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlo...Show more |
3Debian FedoraprojectGnu3Debian Linux FedoraLibextractorJun 17, 2026 Aug 23, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c. |
3Fedoraproject Mixin Deep ProjectOracle3Communications Cloud Native Core Network Function Cloud Native Environment FedoraMixin DeepJun 17, 2026 Aug 23, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload. |
6Apache DebianFedoraproject+3 more60Agile Plm Agile Product Lifecycle Management Integration PackApplication Testing Suite+57 moreJun 17, 2026 Aug 20, 2019 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added which allows suppressing the ability for an attacker to access the classloader via the class property available on all Java objects. We, howev...Show more |
4Canonical FedoraprojectGoogle+1 more4Android FedoraLeap+1 moreJun 17, 2026 Aug 20, 2019 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User inter...Show more |