← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Entrouvert
Fedoraproject
2Fedora
Lasso
May 13, 2026
Aug 11, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash...Show more
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.Show less
2Fedoraproject
Mit
3Fedora
KerberosKerberos 5
May 13, 2026
Aug 9, 2017
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
In MIT Kerberos 5 (aka krb5) 1.7 and later, an authenticated attacker can cause a KDC assertion failure by sending invalid S4U2Self or S4U2Proxy requests.
2Fedoraproject
Ganglia
2Fedora
Ganglia Web
May 13, 2026
Aug 9, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
7Debian
FedoraprojectNtp+4 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+10 more
May 13, 2026
Aug 9, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and...Show more
ntp-keygen in ntp 4.2.8px before 4.2.8p2-RC2 and 4.3.x before 4.3.12 does not generate MD5 keys with sufficient entropy on big endian machines when the lowest order byte of the temp variable is between 0x20 and 0x7f and not #, which might allow remote attackers to obtain the value of generated MD5 keys via a brute force attack with the 93 possible keys.Show less
4Fedoraproject
Jasper ProjectOpensuse+1 more
5Fedora
JasperLeap+2 more
May 13, 2026
Aug 2, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Double free vulnerability in the jasper_image_stop_load function in JasPer 1.900.17 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
4Fedoraproject
Jasper ProjectOpensuse+1 more
5Fedora
JasperLeap+2 more
May 13, 2026
Jul 25, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000...Show more
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.Show less
7Canonical
DebianFedoraproject+4 more
20Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+17 more
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time wh...Show more
The panic_gate check in NTP before 4.2.8p5 is only re-enabled after the first change to the system clock that was greater than 128 milliseconds by default, which allows remote attackers to set NTP to an arbitrary time when started with the -g option, or to alter the time by up to 900 seconds otherwise by responding to an unspecified number of requests from trusted sources, and leveraging a resulting denial of service (abort and restart).Show less
10Canonical
DebianFedoraproject+7 more
18Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+15 more
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a craft...Show more
The ULOGTOD function in ntp.d in SNTP before 4.2.7p366 does not properly perform type conversions from a precision value to a double, which allows remote attackers to cause a denial of service (infinite loop) via a crafted NTP packet.Show less
5Canonical
DebianFedoraproject+2 more
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+5 more
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ntp_openssl.m4 in ntpd in NTP before 4.2.7p112 allows remote attackers to cause a denial of service (segmentation fault) via a crafted statistics or filegen configuration command that is not enabled during compilation.
6Canonical
DebianFedoraproject+3 more
13Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+10 more
May 13, 2026
Jul 21, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
4Canonical
FedoraprojectJasper Project+1 more
6Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Workstation+3 more
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
1Fedoraproject
1Fedmsg
May 13, 2026
Jul 17, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
FedMsg 0.18.1 and older is vulnerable to a message validation flaw resulting in message validation not being enabled if configured to be on.
4Fedoraproject
GolangNovell+1 more
4Fedora
GoLeap+1 more
May 13, 2026
Jul 6, 2017
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive att...Show more
A bug in the standard library ScalarMult implementation of curve P-256 for amd64 architectures in Go before 1.7.6 and 1.8.x before 1.8.2 causes incorrect results to be generated for specific input points. An adaptive attack can be mounted to progressively extract the scalar input to ScalarMult by submitting crafted points and observing failures to the derive correct output. This leads to a full key recovery attack against static ECDH, as used in popular JWT libraries.Show less
2Elog Project
Fedoraproject
2Elog
Fedora
May 13, 2026
Jun 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
1Fedoraproject
1Arm Installer
May 13, 2026
Jun 26, 2017
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories.
2Fedoraproject
Libreswan
2Fedora
Libreswan
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
libreswan before 3.18 allows remote attackers to cause a denial of service (NULL pointer dereference and pluto daemon restart).
2Fedoraproject
Pulpproject
2Fedora
Pulp
May 13, 2026
Jun 13, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
2Fedoraproject
Pulpproject
2Fedora
Pulp
May 13, 2026
Jun 13, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
2Fedoraproject
Pulpproject
2Fedora
Pulp
May 13, 2026
Jun 8, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
5Fedoraproject
Game Music Emu ProjectNovell+2 more
7Fedora
Game Music EmuLeap+4 more
May 13, 2026
Jun 6, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
game-music-emu before 0.6.1 mishandles unspecified integer values.