← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
5Fedoraproject
Game Music Emu ProjectNovell+2 more
7Fedora
Game Music EmuLeap+4 more
May 13, 2026
Jun 6, 2017
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraGit Shell+2 more
May 13, 2026
Jun 1, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote...Show more
git-shell in git before 2.4.12, 2.5.x before 2.5.6, 2.6.x before 2.6.7, 2.7.x before 2.7.5, 2.8.x before 2.8.5, 2.9.x before 2.9.4, 2.10.x before 2.10.3, 2.11.x before 2.11.2, and 2.12.x before 2.12.3 might allow remote authenticated users to gain privileges via a repository name that starts with a - (dash) character.Show less
5Debian
FedoraprojectGoogle+2 more
7Chrome
Debian LinuxEnterprise Linux Server Supplementary+4 more
May 13, 2026
May 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple unspecified vulnerabilities in Google Chrome before 53.0.2785.143 allow remote attackers to cause a denial of service or possibly have other impact via unknown vectors.
5Debian
FedoraprojectGoogle+2 more
7Chrome
Debian LinuxEnterprise Linux Server Supplementary+4 more
May 13, 2026
May 23, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Use-after-free vulnerability in V8 in Google Chrome before 53.0.2785.143 allows remote attackers to cause a denial of service (crash) or possibly have unspecified other impact via unknown vectors.
3Debian
FedoraprojectTug
3Debian Linux
FedoraTex Live
May 13, 2026
May 2, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
2Fedoraproject
Vmware
2Fedora
Spring Advanced Message Queuing Protocol
May 13, 2026
Apr 21, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
org.springframework.core.serializer.DefaultDeserializer in Spring AMQP before 1.5.5 allows remote attackers to execute arbitrary code.
3Clusterlabs
FedoraprojectRedhat
3Enterprise Linux
FedoraPcs
May 13, 2026
Apr 21, 2017
N/A· v4
8.1 HIGH· v3
4.3 MEDIUM· v2
Session fixation vulnerability in pcsd in pcs before 0.9.157.
3Clusterlabs
FedoraprojectRedhat
3Enterprise Linux
FedoraPcs
May 13, 2026
Apr 21, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
2Fedoraproject
Mock Project
2Fedora
Scm Plugin
May 13, 2026
Apr 14, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraLeap+7 more
May 13, 2026
Apr 13, 2017
N/A· v4
7.7 HIGH· v3
6.8 MEDIUM· v2
Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
2Fedoraproject
Saltstack
2Fedora
Salt
May 13, 2026
Apr 13, 2017
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
2Fedoraproject
Saltstack
2Fedora
Salt
May 13, 2026
Apr 13, 2017
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
3Fedoraproject
KernelOpensuse
3Fedora
OpensuseUtil Linux
May 13, 2026
Mar 31, 2017
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Mar 28, 2017
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vu...Show more
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8690.Show less
3Canonical
Cryptography.ioFedoraproject
3Cryptography
FedoraUbuntu Linux
May 13, 2026
Mar 27, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
2Fedoraproject
Kde
2Ark
Fedora
May 13, 2026
Mar 27, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.
2Artifex
Fedoraproject
2Fedora
Mujs
May 13, 2026
Mar 24, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.
3Fedoraproject
Jasper ProjectOpensuse
3Fedora
JasperLeap
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
4Fedoraproject
Jasper ProjectOpensuse+1 more
6Fedora
JasperLeap+3 more
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The jpc_floorlog2 function in jpc_math.c in JasPer before 1.900.17 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
2Fedoraproject
Jasper Project
2Fedora
Jasper
May 13, 2026
Mar 23, 2017
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The jpc_dequantize function in jpc_dec.c in JasPer 1.900.13 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.