Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Nasa2Cfitsio FedoraNov 21, 2024 Apr 16, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger...Show more |
2Entity Api Project Fedoraproject2Entity Api FedoraNov 21, 2024 Apr 10, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors. |
2Entity Api Project Fedoraproject2Entity Api FedoraNov 21, 2024 Apr 10, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors. |
2Entity Api Project Fedoraproject2Entity Api FedoraNov 21, 2024 Apr 10, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via u...Show more |
DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address). |
2Fedoraproject Redhat2Etcd FedoraNov 21, 2024 Apr 3, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theore...Show more |
2Fedoraproject Redhat2Ceph FedoraJun 17, 2026 Mar 19, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service. |
2Fedoraproject Sddm Project2Fedora SddmNov 21, 2024 Mar 8, 2018 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in...Show more |
2Fedoraproject Sddm Project2Fedora SddmNov 21, 2024 Mar 8, 2018 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication. |
2Fedoraproject Redhat4389 Directory Server Enterprise Linux DesktopEnterprise Linux Server+1 moreNov 21, 2024 Mar 7, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An out-of-bounds memory read flaw was found in the way 389-ds-base handled certain LDAP search filters, affecting all versions including 1.4.x. A remote, unauthenticated attacker could potentially use this flaw to make n...Show more |
4Debian FedoraprojectMit+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Mar 6, 2018 N/A· v4 3.8 LOW· v3 5.5 MEDIUM· v2 MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument,...Show more |
4Debian FedoraprojectMit+1 more6Debian Linux Enterprise Linux DesktopEnterprise Linux Server+3 moreJun 17, 2026 Mar 6, 2018 N/A· v4 4.7 MEDIUM· v3 6.5 MEDIUM· v2 MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagg...Show more |
2Fedoraproject Redhat5389 Directory Server Enterprise LinuxEnterprise Linux Desktop+2 moreNov 21, 2024 Mar 1, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 A stack buffer overflow flaw was found in the way 389-ds-base 1.3.6.x before 1.3.6.13, 1.3.7.x before 1.3.7.9, 1.4.x before 1.4.0.5 handled certain LDAP search filters. A remote, unauthenticated attacker could potentiall...Show more |
2Fedoraproject Opensuse2Fedora ZypperNov 21, 2024 Mar 1, 2018 N/A· v4 3.3 LOW· v3 2.1 LOW· v2 The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used. |
2Fedoraproject Fishshell2Fedora FishNov 21, 2024 Feb 9, 2018 N/A· v4 7.8 HIGH· v3 4.3 MEDIUM· v2 fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER. |
2Fedoraproject Zabbix2Fedora ZabbixNov 21, 2024 Feb 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbit...Show more |
3Fedoraproject MariadbPercona3Fedora MariadbXtradb ClusterNov 21, 2024 Jan 25, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass i...Show more |
1Fedoraproject 1389 Directory Server Nov 21, 2024 Jan 24, 2018 N/A· v4 8.1 HIGH· v3 4.3 MEDIUM· v2 It was found that 389-ds-base since 1.3.6.1 up to and including 1.4.0.3 did not always handle internal hash comparison operations correctly during the authentication process. A remote, unauthenticated attacker could pote...Show more |
3Debian FedoraprojectGnu3Debian Linux FedoraLibtasn1Jun 17, 2026 Jan 22, 2018 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in the _asn1_decode_simple_ber function in decoding.c in GNU Libtasn1 before 4.13. Unlimited recursion in the BER decoder leads to stack exhaustion and DoS. |
5Canonical DebianFedoraproject+2 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Server+7 moreNov 21, 2024 Jan 12, 2018 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 A stack-based buffer overflow within GNOME gcab through 0.7.4 can be exploited by malicious attackers to cause a crash or, potentially, execute arbitrary code via a crafted .cab file. |