Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraLeap+1 moreJun 17, 2026 Jul 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 SchedMD Slurm 17.11.x, 18.08.0 through 18.08.7, and 19.05.0 allows SQL Injection. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibzmq+1 moreJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In ZeroMQ libzmq before 4.0.9, 4.1.x before 4.1.7, and 4.2.x before 4.3.2, a remote, unauthenticated client connecting to a libzmq application, running with a socket listening with CURVE encryption/authentication enabled...Show more |
2Fedoraproject Oniguruma Project2Fedora OnigurumaJun 17, 2026 Jul 10, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A NULL Pointer Dereference in match_at() in regexec.c in Oniguruma 6.9.2 allows attackers to potentially cause denial of service by providing a crafted regular expression. Oniguruma issues often affect Ruby, as well as c...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraOniguruma+2 moreJun 17, 2026 Jul 10, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression....Show more |
3Fedoraproject LibosinfoRedhat6Enterprise Linux Enterprise Linux EusEnterprise Linux Server Aus+3 moreJun 17, 2026 Jul 5, 2019 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line. |
2Fedoraproject Glyphandcog2Fedora XpdfreaderJun 17, 2026 Jul 4, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 In Xpdf 4.01.01, there is a heap-based buffer over-read in the function JBIG2Stream::readTextRegionSeg() located at JBIG2Stream.cc. It can, for example, be triggered by sending a crafted PDF document to the pdftoppm tool...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderJun 17, 2026 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. I...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderJun 17, 2026 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to...Show more |
2Fedoraproject Glyphandcog2Fedora XpdfreaderJun 17, 2026 Jul 4, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftot...Show more |
2Deepin Fedoraproject2Deepin Clone FedoraJun 17, 2026 Jul 4, 2019 N/A· v4 7.0 HIGH· v3 6.9 MEDIUM· v2 deepin-clone before 1.1.3 uses a predictable path /tmp/.deepin-clone/mount/<block-dev-basename> in the Helper::temporaryMountDevice() function to temporarily mount a file system as root. An unprivileged user can prepare...Show more |
3Debian DosboxFedoraproject3Debian Linux DosboxFedoraJun 17, 2026 Jul 3, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code. |
7Apple CanonicalFedoraproject+4 more25Active Iq Unified Manager Cloud BackupClustered Data Ontap+22 moreJun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In numbers.c in libxslt 1.1.33, a type holding grouping characters of an xsl:number instruction was too narrow and an invalid character/length combination could be passed to xsltNumberFormatDecimal, leading to a read of...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLeap+3 moreJun 17, 2026 Jul 1, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains...Show more |
4Canonical DebianExiv2+1 more4Debian Linux Exiv2Fedora+1 moreJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 http.c in Exiv2 through 0.27.1 allows a malicious http server to cause a denial of service (crash due to a NULL pointer dereference) by returning a crafted response that lacks a space character. |
3Canonical Exiv2Fedoraproject3Exiv2 FedoraUbuntu LinuxJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file. |
4Canonical DebianExiv2+1 more4Debian Linux Exiv2Fedora+1 moreJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file. |
2Exiv2 Fedoraproject2Exiv2 FedoraJun 17, 2026 Jun 30, 2019 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 A WebPImage::decodeChunks integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (large heap allocation followed by a very long running loop) via a crafted WEBP image file. |
4Canonical DebianExiv2+1 more4Debian Linux Exiv2Fedora+1 moreJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file. |
2Exiv2 Fedoraproject2Exiv2 FedoraJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction. |
2Exiv2 Fedoraproject2Exiv2 FedoraJun 17, 2026 Jun 30, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset. |