Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Canonical FedoraprojectLinux+1 more20Enterprise Linux Enterprise Linux Compute Node EusEnterprise Linux Desktop+17 moreNov 21, 2024 Jan 9, 2018 N/A· v4 4.7 MEDIUM· v3 4.9 MEDIUM· v2 A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it...Show more |
3Fedoraproject NumpyRedhat3Enterprise Linux FedoraNumpyNov 21, 2024 Jan 8, 2018 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 (1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary f...Show more |
2Fedoraproject Mediawiki2Fedora MediawikiMay 13, 2026 Dec 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an exist...Show more |
3Fedoraproject Netcf ProjectRedhat3Enterprise Linux FedoraNetcfMay 13, 2026 Dec 29, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions. |
2Fedoraproject Rawstudio2Fedora RawstudioMay 13, 2026 Dec 29, 2017 N/A· v4 5.5 MEDIUM· v3 3.6 LOW· v2 The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph. |
2Fedoraproject Mistune Project2Fedora MistuneMay 13, 2026 Dec 29, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument. |
2Fedoraproject Redhat2Ceph FedoraMay 13, 2026 Dec 20, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an inval...Show more |
5Debian FedoraprojectOpensuse+2 more6Debian Linux FedoraLeap+3 moreMay 13, 2026 Dec 5, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Tor before 0.2.8.12 might allow remote attackers to cause a denial of service (client crash) via a crafted hidden service descriptor. |
3Fedoraproject GolangRedhat6Enterprise Linux Server Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 13, 2026 Oct 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The net/http library in net/http/transfer.go in Go before 1.4.3 does not properly parse HTTP headers, which allows remote attackers to conduct HTTP request smuggling attacks via a request with two Content-length headers. |
3Fedoraproject GolangRedhat6Enterprise Linux Server Enterprise Linux Server AusEnterprise Linux Server Eus+3 moreMay 13, 2026 Oct 18, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as dem...Show more |
2Fedoraproject Openbsd2Fedora OpensmtpdMay 13, 2026 Oct 16, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta. |
1Fedoraproject 1Spin Kickstarts May 13, 2026 Oct 16, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora Atomic updates. |
3Canonical FedoraprojectLibjpeg Turbo3Fedora Libjpeg TurboUbuntu LinuxMay 13, 2026 Oct 10, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker. |
6Canonical DebianFedoraproject+3 more8Debian Linux DnsmasqEnterprise Linux Desktop+5 moreMay 13, 2026 Oct 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In dnsmasq before 2.78, if the DNS packet size does not match the expected size, the size parameter in a memset call gets a negative value. As it is an unsigned value, memset ends up writing up to 0xffffffff zero's (0xff...Show more |
2Fedoraproject Wesnoth2Battle For Wesnoth FedoraMay 13, 2026 Sep 26, 2017 N/A· v4 3.1 LOW· v3 3.5 LOW· v2 The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is u...Show more |
2Fedoraproject Wesnoth2Battle For Wesnoth FedoraMay 13, 2026 Sep 26, 2017 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensiti...Show more |
2Devscripts Devel Team Fedoraproject2Devscripts FedoraMay 13, 2026 Sep 25, 2017 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands. |
2Fedoraproject Pureftpd2Fedora Pure FtpdMay 13, 2026 Sep 21, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. Thi...Show more |
2Fedoraproject Ipython2Fedora IpythonMay 13, 2026 Sep 20, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Cross-site request forgery in the REST API in IPython 2 and 3. |
2Dovecot Fedoraproject2Dovecot FedoraMay 13, 2026 Sep 19, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process crash) via vectors related to handshake failures. |