Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The nginx package before 1.6.2-5+deb8u3 on Debian jessie, the nginx packages before 1.4.6-1ubuntu3.6 on Ubuntu 14.04 LTS, before 1.10.0-0ubuntu0.16.04.3 on Ubuntu 16.04 LTS, and before 1.10.1-0ubuntu1.1 on Ubuntu 16.10,...Show more |
7Canonical DebianFedoraproject+4 more18Cloud Backup Debian LinuxEnterprise Linux+15 moreApr 21, 2026 Nov 10, 2016 N/A· v4 7.0 HIGH· v3 7.2 HIGH· v2 Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by leveraging incorrect handling of a copy-on-write (COW) feature to write to a read-only memory mapping,...Show more |
2Fedoraproject Haxx2Fedora LibcurlMay 6, 2026 Oct 7, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple integer overflows in the (1) curl_escape, (2) curl_easy_escape, (3) curl_unescape, and (4) curl_easy_unescape functions in libcurl before 7.50.3 allow attackers to have unspecified impact via a string of length...Show more |
3Fedoraproject GnuOpensuse3Fedora GlibcOpensuseMay 6, 2026 Oct 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to ca...Show more |
2Eclipse Fedoraproject2Fedora JettyMay 6, 2026 Oct 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak. |
2Adodb Project Fedoraproject2Adodb FedoraMay 6, 2026 Oct 3, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting. |
2Fedoraproject Mongodb2Fedora MongodbMay 6, 2026 Oct 3, 2016 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files. |
3Fedoraproject OpensuseSqlite3Fedora LeapSqliteMay 6, 2026 Sep 26, 2016 N/A· v4 5.9 MEDIUM· v3 4.6 MEDIUM· v2 os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unsp...Show more |
2Fedoraproject Redhat3Fedora Jboss Enterprise Application PlatformJboss Enterprise Web ServerMay 6, 2026 Sep 26, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate el...Show more |
4Debian FedoraprojectRedhat+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreMay 6, 2026 Sep 21, 2016 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the opj_pi_create_decode function in pi.c in OpenJPEG allows remote attackers to execute arbitrary code via a crafted JP2 file, which triggers an out-of-bounds read or write. |
3Fedoraproject GoogleOpensuse3Chrome FedoraLeapMay 6, 2026 Sep 11, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers t...Show more |
3Fedoraproject FreeipaOracle3Fedora FreeipaLinuxMay 6, 2026 Sep 7, 2016 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The cert_revoke command in FreeIPA does not check for the "revoke certificate" permission, which allows remote authenticated users to revoke arbitrary certificates by leveraging the "retrieve certificate" permission. |
4Canonical FedoraprojectGnome+1 more5Eye Of Gnome FedoraLeap+2 moreMay 6, 2026 Sep 7, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via ve...Show more |
3Collectd DebianFedoraproject3Collectd Debian LinuxFedoraMay 6, 2026 Aug 19, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code vi...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraFontconfig+1 moreMay 6, 2026 Aug 13, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file. |
5Canonical DebianFedoraproject+2 more6Debian Linux FedoraLeap+3 moreMay 6, 2026 Aug 10, 2016 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors. |
2Fedoraproject Microsoft5Fedora Windows 10Windows 8.1+2 moreMay 6, 2026 Aug 9, 2016 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to bypass the Secure Boot protection mechanism by leveraging (1) administrative or (2) physical access...Show more |
2Fedoraproject Openbsd2Fedora OpensshMay 6, 2026 Aug 7, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password authentication, which allows remote attackers to cause a denial of service (crypt CPU consumption) vi...Show more |
5Debian FedoraprojectFreebsd+2 more6Debian Linux Enterprise LinuxFedora+3 moreMay 6, 2026 Aug 7, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraPerl+2 moreMay 6, 2026 Aug 2, 2016 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working...Show more |