← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Canonical
FedoraprojectLinux+1 more
20Enterprise Linux
Enterprise Linux Compute Node EusEnterprise Linux Desktop+17 more
Nov 21, 2024
Jan 9, 2018
N/A· v4
4.7 MEDIUM· v3
4.9 MEDIUM· v2
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it...Show more
A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead to double free and memory corruption. This vulnerability could allow an unprivileged local user to induce kernel memory corruption on the system, leading to a crash. Due to the nature of the flaw, privilege escalation cannot be fully ruled out, although it is thought to be unlikely.Show less
3Fedoraproject
NumpyRedhat
3Enterprise Linux
FedoraNumpy
Nov 21, 2024
Jan 8, 2018
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary f...Show more
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.Show less
2Fedoraproject
Mediawiki
2Fedora
Mediawiki
May 13, 2026
Dec 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an exist...Show more
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.Show less
3Fedoraproject
Netcf ProjectRedhat
3Enterprise Linux
FedoraNetcf
May 13, 2026
Dec 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
2Fedoraproject
Rawstudio
2Fedora
Rawstudio
May 13, 2026
Dec 29, 2017
N/A· v4
5.5 MEDIUM· v3
3.6 LOW· v2
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph.
2Fedoraproject
Mistune Project
2Fedora
Mistune
May 13, 2026
Dec 29, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.
2Fedoraproject
Redhat
2Ceph
Fedora
May 13, 2026
Dec 20, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an inval...Show more
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h.Show less
5Debian
FedoraprojectOpensuse+2 more
6Debian Linux
FedoraLeap+3 more
May 13, 2026
Dec 5, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor.
3Fedoraproject
GolangRedhat
6Enterprise Linux Server
Enterprise Linux Server AusEnterprise Linux Server Eus+3 more
May 13, 2026
Oct 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers.
3Fedoraproject
GolangRedhat
6Enterprise Linux Server
Enterprise Linux Server AusEnterprise Linux Server Eus+3 more
May 13, 2026
Oct 18, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as dem...Show more
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" instead of "Content-Length."Show less
2Fedoraproject
Openbsd
2Fedora
Opensmtpd
May 13, 2026
Oct 16, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.
1Fedoraproject
1Spin Kickstarts
May 13, 2026
Oct 16, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates.
3Canonical
FedoraprojectLibjpeg Turbo
3Fedora
Libjpeg TurboUbuntu Linux
May 13, 2026
Oct 10, 2017
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
6Canonical
DebianFedoraproject+3 more
8Debian Linux
DnsmasqEnterprise Linux Desktop+5 more
May 13, 2026
Oct 3, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xff...Show more
In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xffffffffffffffff in 64 bit platforms), making dnsmasq crash.Show less
2Fedoraproject
Wesnoth
2Battle For Wesnoth
Fedora
May 13, 2026
Sep 26, 2017
N/A· v4
3.1 LOW· v3
3.5 LOW· v2
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is u...Show more
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5069.Show less
2Fedoraproject
Wesnoth
2Battle For Wesnoth
Fedora
May 13, 2026
Sep 26, 2017
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensiti...Show more
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML.Show less
2Devscripts Devel Team
Fedoraproject
2Devscripts
Fedora
May 13, 2026
Sep 25, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
2Fedoraproject
Pureftpd
2Fedora
Pure Ftpd
May 13, 2026
Sep 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. Thi...Show more
Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue doesn't affect upstream version of pure-ftpd.Show less
2Fedoraproject
Ipython
2Fedora
Ipython
May 13, 2026
Sep 20, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery in the REST API in IPython 2 and 3.
2Dovecot
Fedoraproject
2Dovecot
Fedora
May 13, 2026
Sep 19, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures.