Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FedoraprojectOpensuse+1 more4Fedora LeapQemu+1 moreNov 21, 2024 Mar 21, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value. |
5Debian FasterxmlFedoraproject+2 more11Automation Manager Debian LinuxDecision Manager+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpa...Show more |
5Debian FasterxmlFedoraproject+2 more11Automation Manager Debian LinuxDecision Manager+8 moreNov 21, 2024 Mar 21, 2019 N/A· v4 7.5 HIGH· v3 5.1 MEDIUM· v2 An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database acce...Show more |
3Fedoraproject OpensuseOpenwsman Project3Fedora LeapOpenwsmanJun 17, 2026 Mar 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by se...Show more |
4Fedoraproject OpensuseOpenwsman Project+1 more11Enterprise Linux Enterprise Linux DesktopEnterprise Linux Eus+8 moreJun 17, 2026 Mar 14, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Openwsman, versions up to and including 2.6.9, are vulnerable to arbitrary file disclosure because the working directory of openwsmand daemon was set to root directory. A remote, unauthenticated attacker can exploit this...Show more |
4Debian FedoraprojectGolang+1 more5Debian Linux Developer ToolsEnterprise Linux+2 moreJun 17, 2026 Mar 13, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a R...Show more |
3Cron Project DebianFedoraproject3Cron Debian LinuxFedoraJun 17, 2026 Mar 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted. |
3Cron Project DebianFedoraproject3Cron Debian LinuxFedoraJun 17, 2026 Mar 12, 2019 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked. |
2Fedoraproject Podofo Project2Fedora PodofoJun 17, 2026 Mar 11, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp. |
3Checkstyle DebianFedoraproject3Checkstyle Debian LinuxFedoraJun 17, 2026 Mar 11, 2019 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Checkstyle before 8.18 loads external DTDs by default. |
7Canonical DebianFedoraproject+4 more16Debian Linux Enterprise LinuxEnterprise Linux Desktop+13 moreJun 17, 2026 Mar 8, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Python 2.7.x through 2.7.16 and 3.x through 3.7.2 is affected by: Improper Handling of Unicode Encoding (with an incorrect netloc) during NFKC normalization. The impact is: Information disclosure (credentials, cookies, e...Show more |
3Debian FedoraprojectFreedesktop3Debian Linux FedoraPopplerJun 17, 2026 Mar 8, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function. |
5Debian FedoraprojectLibjpeg Turbo+2 more5Debian Linux FedoraLeap+2 moreNov 21, 2024 Mar 7, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or...Show more |
13Canonical DebianF5+10 more82A220 Firmware A320 FirmwareA800 Firmware+79 moreJun 17, 2026 Feb 27, 2019 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte r...Show more |
3Fedoraproject GnuSuse3Backports FedoraPsppJun 17, 2026 Feb 27, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service. |
4Advancemame CanonicalDebian+1 more4Advancecomp Debian LinuxFedora+1 moreJun 17, 2026 Feb 27, 2019 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-b...Show more |
2Fedoraproject Podofo Project2Fedora PodofoJun 17, 2026 Feb 26, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an at...Show more |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 19, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 19, 2019 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Incorrect handling of a confusable character in Omnibox in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. |
4Debian FedoraprojectGoogle+1 more6Chrome Debian LinuxEnterprise Linux Desktop+3 moreJun 17, 2026 Feb 19, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Insufficient restrictions on what can be done with Apple Events in Google Chrome on macOS prior to 72.0.3626.81 allowed a local attacker to execute JavaScript via Apple Events. |