← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Canonical
DebianFedoraproject+3 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Eus+8 more
Jun 17, 2026
Mar 23, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('l...Show more
urllib in Python 2.x through 2.7.16 supports the local_file: scheme, which makes it easier for remote attackers to bypass protection mechanisms that blacklist file: URIs, as demonstrated by triggering a urllib.urlopen('local_file:///etc/passwd') call.Show less
2Fedoraproject
Powerdns
2Authoritative Server
Fedora
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the...Show more
A vulnerability was found in PowerDNS Authoritative Server before 4.0.7 and before 4.1.7. An insufficient validation of data coming from the user when building a HTTP request from a DNS query in the HTTP Connector of the Remote backend, allowing a remote user to cause a denial of service by making the server connect to an invalid endpoint, or possibly information disclosure by making the server connect to an internal endpoint and somehow extracting meaningful information about the responseShow less
5Debian
FedoraprojectLibssh2+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service...Show more
An out of bounds read flaw was discovered in libssh2 before 1.8.1 when a specially crafted SFTP packet is received from the server. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.Show less
8Apple
DebianFedoraproject+5 more
14Debian Linux
Enterprise LinuxEnterprise Linux Desktop+11 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execut...Show more
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.Show less
5Canonical
DebianFedoraproject+2 more
8Debian Linux
Enterprise LinuxEnterprise Linux Eus+5 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file...Show more
PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.Show less
5Debian
FedoraprojectNetapp+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
5Debian
FedoraprojectNetapp+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
2Fedoraproject
Putty
2Fedora
Putty
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In PuTTY versions before 0.71 on Unix, a remotely triggerable buffer overflow exists in any kind of server-to-client forwarding.
5Debian
FedoraprojectNetapp+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
6.4 MEDIUM· v2
A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
7Canonical
DebianFedoraproject+4 more
18Active Iq Performance Analytics Services
Debian LinuxElement Software Management Node+15 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
7Canonical
DebianFedoraproject+4 more
15Active Iq Performance Analytics Services
Debian LinuxElement Software Management Node+12 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
4Canonical
FedoraprojectOpensuse+1 more
4Fedora
LeapQemu+1 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
In QEMU 3.0.0, tcp_emu in slirp/tcp_subr.c has a heap-based buffer overflow.
2Fedoraproject
Qemu
2Fedora
Qemu
Jun 17, 2026
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
8Canonical
DebianFedoraproject+5 more
22Active Iq Performance Analytics Services
Debian LinuxEnterprise Linux+19 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An un...Show more
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the stack pointer to jump over the stack guard pages into an unmapped memory region and trigger a denial of service (systemd PID1 crash and kernel panic).Show less
6Artifex
CanonicalDebian+3 more
11Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+8 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
In Artifex Ghostscript through 9.26, ephemeral or transient procedures can allow access to system operators, leading to remote code execution.
2Fedoraproject
Matrix
2Fedora
Synapse
Jun 17, 2026
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
5Debian
FedoraprojectLibssh2+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be ab...Show more
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.Show less
5Debian
FedoraprojectLibssh2+2 more
5Debian Linux
FedoraLeap+2 more
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Ser...Show more
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.Show less
3Fedoraproject
OpensuseQt
3Fedora
LeapQt
Nov 21, 2024
Mar 21, 2019
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
4Bestpractical
CanonicalDebian+1 more
4Debian Linux
FedoraRequest Tracker+1 more
Nov 21, 2024
Mar 21, 2019
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.