Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Jasper Project2Fedora JasperMay 13, 2026 Mar 23, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (NULL pointer dereference). |
3Fedoraproject OpensusePercona3Fedora LeapXtrabackupMay 13, 2026 Mar 23, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 xbcrypt in Percona XtraBackup before 2.3.6 and 2.4.x before 2.4.5 does not properly set the initialization vector (IV) for encryption, which makes it easier for context-dependent attackers to obtain sensitive information...Show more |
2Fedoraproject Squashfs Project2Fedora SquashfsMay 13, 2026 Mar 17, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based...Show more |
2Fedoraproject Netpbm Project2Fedora NetpbmMay 13, 2026 Mar 15, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related...Show more |
7Debian FedoraprojectJqueryui+4 more13Application Express Business IntelligenceDebian Linux+10 moreMay 13, 2026 Mar 15, 2017 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in jQuery UI before 1.12.0 might allow remote attackers to inject arbitrary web script or HTML via the closeText parameter of the dialog function. |
3Debian FedoraprojectGnome3Debian Linux FedoraGdk PixbufMay 13, 2026 Mar 10, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file. |
3Debian FedoraprojectGnome3Debian Linux FedoraGdk PixbufMay 13, 2026 Mar 10, 2017 N/A· v4 7.1 HIGH· v3 5.8 MEDIUM· v2 Integer underflow in the load_resources function in io-icns.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (out-of-bounds read and program crash) via a crafted image entry size in an ICO...Show more |
3Debian FedoraprojectGnome3Debian Linux FedoraGdk PixbufMay 13, 2026 Mar 10, 2017 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out...Show more |
2Fedoraproject Gnome2Fedora Gdk PixbufMay 13, 2026 Mar 10, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to printing an error message. |
3Fedoraproject Libass ProjectOpensuse4Fedora LeapLibass+1 moreMay 13, 2026 Mar 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors. |
2Fedoraproject Libass Project2Fedora LibassMay 13, 2026 Mar 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Buffer overflow in the calc_coeff function in libass/ass_blur.c in libass before 0.13.4 allows remote attackers to cause a denial of service via unspecified vectors. |
3Fedoraproject Libass ProjectOpensuse4Fedora LeapLibass+1 moreMay 13, 2026 Mar 3, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The wrap_lines_smart function in ass_render.c in libass before 0.13.4 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors, related to "0/3 line wrapping equalization." |
2Fedoraproject Gnome2Fedora Gtk VncMay 13, 2026 Feb 28, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple integer overflows in the (1) vnc_connection_server_message and (2) vnc_color_map_set functions in gtk-vnc before 0.7.0 allow remote servers to cause a denial of service (crash) or possibly execute arbitrary code...Show more |
2Fedoraproject Gnome2Fedora Gtk VncMay 13, 2026 Feb 28, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyr...Show more |
3Debian FedoraprojectFlightgear3Debian Linux FedoraFlightgearMay 13, 2026 Feb 22, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script. |
2Fedoraproject Teeworlds2Fedora TeeworldsMay 13, 2026 Feb 22, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involvin...Show more |
regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free. |
2Fedoraproject Zend2Fedora Zend FrameworkMay 13, 2026 Feb 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regu...Show more |
2Fedoraproject Zend2Fedora Zend FrameworkMay 13, 2026 Feb 17, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement befo...Show more |
3Fedoraproject Jasper ProjectOpensuse3Fedora JasperOpensuseMay 13, 2026 Feb 15, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the...Show more |