← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Fedoraproject
3389 Directory Server
Debian LinuxFedora
May 13, 2026
Sep 19, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
1Fedoraproject
1Python Fedora
May 13, 2026
Sep 14, 2017
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection
2Fedoraproject
Mit
2Fedora
Kerberos 5
May 13, 2026
Sep 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of security contexts on error.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLibgd+1 more
May 13, 2026
Sep 7, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
2Devscripts Devel Team
Fedoraproject
2Devscripts
Fedora
May 13, 2026
Sep 6, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted filename.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial of service attack.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
3Debian
FedoraprojectJasper Project
3Debian Linux
FedoraJasper
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of service attack.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Aug 29, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial of service attack.
1Fedoraproject
1389 Administration Server
May 13, 2026
Aug 28, 2017
N/A· v4
4.2 MEDIUM· v3
4.6 MEDIUM· v2
Multiple insecure Temporary File vulnerabilities in 389 Administration Server before 1.1.38.
3Canonical
FedoraprojectGnu
3Fedora
PatchUbuntu Linux
May 13, 2026
Aug 25, 2017
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a di...Show more
Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary files with the permissions of the target user via a .. (dot dot) in a diff file name.Show less
4Canonical
FedoraprojectGnu+1 more
4Fedora
MageiaPatch+1 more
May 13, 2026
Aug 25, 2017
N/A· v4
5.5 MEDIUM· v3
7.1 HIGH· v2
GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.
3Debian
FedoraprojectNtp
3Debian Linux
FedoraNtp
May 13, 2026
Aug 24, 2017
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a de...Show more
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.Show less
4Debian
FedoraprojectRedhat+1 more
4Cloudforms
Debian LinuxFedora+1 more
May 13, 2026
Aug 23, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nest...Show more
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.Show less
2Fedoraproject
Vmware
2Fedora
Spring Social
May 13, 2026
Aug 22, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.
2Cyrusimap
Fedoraproject
2Cyrus Imap
Fedora
May 13, 2026
Aug 22, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE command.
1Fedoraproject
1389 Directory Server
May 13, 2026
Aug 16, 2017
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes returned on password attempts.