Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Pyyaml2Fedora PyyamlNov 21, 2024 Jun 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibi...Show more |
3Debian FedoraprojectRedhat5Debian Linux Enterprise Linux DesktopEnterprise Linux Server+2 moreNov 21, 2024 Jun 26, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The UNIX pipe which sudo uses to contact SSSD and read the available sudo rules from SSSD has too wide permissions, which means that anyone who can send a message using the same raw protocol that sudo and SSSD use can re...Show more |
2Fedoraproject Redhat4389 Directory Server Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Jun 22, 2018 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 389-ds-base before versions 1.3.5.17 and 1.3.6.10 is vulnerable to an invalid pointer dereference in the way LDAP bind requests are handled. A remote unauthenticated attacker could use this flaw to make ns-slapd crash vi...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraStrongswan+1 moreNov 21, 2024 Jun 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable. |
5Canonical DebianFedoraproject+2 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in the difflib.IS_LINE_JUNK method. An attacker could use this flaw to cause denial of service. |
3Fedoraproject PulpprojectRedhat3Fedora PulpSatelliteNov 21, 2024 Jun 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Pulp before version 2.16.2, secrets are passed into override_config when triggering a task and then become readable to all users with read access on the distributor/importer. An attacker with API access can then view...Show more |
5Canonical DebianFedoraproject+2 more8Ansible Tower Debian LinuxEnterprise Linux Desktop+5 moreNov 21, 2024 Jun 18, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 python before versions 2.7.15, 3.4.9, 3.5.6rc1, 3.6.5rc1 and 3.7.0 is vulnerable to catastrophic backtracking in pop3lib's apop() method. An attacker could use this flaw to cause denial of service. |
3Debian FedoraprojectRedhat9389 Directory Server Debian LinuxEnterprise Linux+6 moreNov 21, 2024 Jun 13, 2018 N/A· v4 5.9 MEDIUM· v3 7.1 HIGH· v2 389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attacker could use this fla...Show more |
3Debian FedoraprojectSensiolabs3Debian Linux FedoraSymfonyNov 21, 2024 Jun 13, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in the Security component in Symfony 2.7.x before 2.7.48, 2.8.x before 2.8.41, 3.3.x before 3.3.17, 3.4.x before 3.4.11, and 4.0.x before 4.0.11. A session fixation vulnerability within the "Guard...Show more |
3Canonical FedoraprojectGraphviz3Fedora GraphvizUbuntu LinuxNov 21, 2024 May 30, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted f...Show more |
2Fedoraproject Redhat7Enterprise Linux Enterprise Linux DesktopEnterprise Linux Server+4 moreNov 21, 2024 May 17, 2018 N/A· v4 7.5 HIGH· v3 7.9 HIGH· v2 DHCP packages in Red Hat Enterprise Linux 6 and 7, Fedora 28, and earlier are vulnerable to a command injection flaw in the NetworkManager integration script included in the DHCP client. A malicious DHCP server, or an at...Show more |
3Debian FedoraprojectRedhat5389 Directory Server Debian LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 May 9, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 389-ds-base before versions 1.4.0.9, 1.3.8.1, 1.3.6.15 did not properly handle long search filters with characters needing escapes, possibly leading to buffer overflows. A remote, unauthenticated attacker could potential...Show more |
3Debian FedoraprojectMoinejf3Abcm2ps Debian LinuxFedoraNov 21, 2024 May 7, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. |
3Debian FedoraprojectMoinejf3Abcm2ps Debian LinuxFedoraNov 21, 2024 May 5, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact. |
1Fedoraproject 1389 Directory Server Nov 21, 2024 May 4, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 389 Directory Server 1.2.7.5, when built with mozldap, allows remote attackers to cause a denial of service (replica crash) by sending an empty modify request. |
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fed...Show more |
2Fedoraproject Redhat2389 Directory Server Enterprise LinuxNov 21, 2024 Apr 30, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 389-ds-base before version 1.3.6 is vulnerable to an improperly NULL terminated array in the uniqueness_entry_to_config() function in the "attribute uniqueness" plugin of 389 Directory Server. An authenticated, or possib...Show more |
3Debian FedoraprojectFlac Project3Debian Linux FedoraFlacNov 21, 2024 Apr 25, 2018 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file. |
2Fedoraproject Nasa2Cfitsio FedoraNov 21, 2024 Apr 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulner...Show more |
2Fedoraproject Nasa2Cfitsio FedoraNov 21, 2024 Apr 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulner...Show more |