← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
DjangoprojectFedoraproject
3Debian Linux
DjangoFedora
Jun 17, 2026
Aug 9, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and...Show more
An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField, were subject to SQL injection. This could, for example, be exploited via crafted use of "OR 1=1" in a key or index name to return all records, using a suitably crafted dictionary, with dictionary expansion, as the **kwargs passed to the QuerySet.filter() function.Show less
2Fedoraproject
Radare
2Fedora
Radare2
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the vi...Show more
In radare2 before 3.7.0, a command injection vulnerability exists in bin_symbols() in libr/core/cbin.c. By using a crafted executable file, it's possible to execute arbitrary shell commands with the permissions of the victim. This vulnerability is due to improper handling of symbol names embedded in executables.Show less
6Canonical
DebianFedoraproject+3 more
8Backports Sle
Debian LinuxEnterprise Linux Desktop+5 more
Jun 17, 2026
Aug 7, 2019
N/A· v4
7.8 HIGH· v3
5.1 MEDIUM· v2
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .dir...Show more
In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.Show less
2Adplug Project
Fedoraproject
2Adplug
Fedora
Jun 17, 2026
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.
2Adplug Project
Fedoraproject
2Adplug
Fedora
Jun 17, 2026
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
AdPlug 2.3.1 has multiple heap-based buffer overflows in CradLoader::load() in rad.cpp.
2Adplug Project
Fedoraproject
2Adplug
Fedora
Jun 17, 2026
Aug 7, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
AdPlug 2.3.1 has multiple heap-based buffer overflows in Ca2mLoader::load() in a2m.cpp.
2Adplug Project
Fedoraproject
2Adplug
Fedora
Jun 17, 2026
Aug 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.
2Adplug Project
Fedoraproject
2Adplug
Fedora
Jun 17, 2026
Aug 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
AdPlug 2.3.1 has a heap-based buffer overflow in CdtmLoader::load() in dtm.cpp.
2Adplug Project
Fedoraproject
2Adplug
Fedora
Jun 17, 2026
Aug 6, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
AdPlug 2.3.1 has a heap-based buffer overflow in CxadbmfPlayer::__bmf_convert_stream() in bmf.cpp.
2Enigmail
Fedoraproject
2Enigmail
Fedora
Jun 17, 2026
Aug 5, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters...Show more
In Enigmail below 2.1, an attacker in possession of PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, he unknowingly leaks the plaintext of the encrypted message part(s) back to the attacker. This attack variant bypasses protection mechanisms implemented after the "EFAIL" attacks.Show less
2Fedoraproject
Sleuthkit
2Fedora
The Sleuth Kit
Jun 17, 2026
Aug 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table.
2Fedoraproject
Redhat
2389 Directory Server
Enterprise Linux Server Eus
Jun 17, 2026
Aug 2, 2019
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial...Show more
It was found that the fix for CVE-2018-14648 in 389-ds-base, versions 1.4.0.x before 1.4.0.17, was incorrectly applied in RHEL 7.5. An attacker would still be able to provoke excessive CPU consumption leading to a denial of service.Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
Enterprise LinuxFedora+2 more
Jun 17, 2026
Aug 1, 2019
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
An issue was discovered in Poppler through 0.78.0. There is a divide-by-zero error in the function SplashOutputDev::tilingPatternFill at SplashOutputDev.cc.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraMilkytracker+1 more
Jun 17, 2026
Jul 31, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.
3Debian
FedoraprojectLibmodbus
3Debian Linux
FedoraLibmodbus
Jun 17, 2026
Jul 31, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_REGISTERS case, aka VD-1301.
3Debian
FedoraprojectLibmodbus
3Debian Linux
FedoraLibmodbus
Jun 17, 2026
Jul 31, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An issue was discovered in libmodbus before 3.0.7 and 3.1.x before 3.1.5. There is an out-of-bounds read for the MODBUS_FC_WRITE_MULTIPLE_COILS case, aka VD-1302.
3Debian
FedoraprojectNfdump Project
3Debian Linux
FedoraNfdump
Jun 17, 2026
Jul 31, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service).
6Apache
DebianFasterxml+3 more
18Banking Platform
Communications Diameter Signaling RouterCommunications Instant Messaging Server+15 more
Jun 17, 2026
Jul 30, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint...Show more
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.Show less
2Fedoraproject
Pdfresurrect Project
2Fedora
Pdfresurrect
Jun 17, 2026
Jul 29, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
PDFResurrect 0.15 has a buffer overflow via a crafted PDF file because data associated with startxref and %%EOF is mishandled.
3Canonical
DockerFedoraproject
3Credential Helpers
FedoraUbuntu Linux
Jun 17, 2026
Jul 29, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
docker-credential-helpers before 0.6.3 has a double free in the List functions.