Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLibgd+3 moreMay 6, 2026 Apr 26, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which trigge...Show more |
2Fedoraproject Redhat6389 Directory Server Enterprise LinuxEnterprise Linux Desktop+3 moreMay 6, 2026 Apr 19, 2016 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormall...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraGlibc+7 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraGlibc+7 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the _...Show more |
6Canonical DebianFedoraproject+3 more10Debian Linux FedoraGlibc+7 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range...Show more |
5Canonical FedoraprojectGnu+2 more9Fedora GlibcLinux Enterprise Debuginfo+6 moreMay 6, 2026 Apr 19, 2016 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long...Show more |
3Fedoraproject OracleXen3Fedora Vm ServerXenMay 6, 2026 Apr 19, 2016 N/A· v4 8.8 HIGH· v3 7.2 HIGH· v2 Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping. |
2Fedoraproject Libreswan2Fedora LibreswanMay 6, 2026 Apr 18, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform. |
2Fedoraproject Latex2rtf Project2Fedora Latex2rtfMay 6, 2026 Apr 18, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file...Show more |
2Fedoraproject Fourkitchens2Block Class FedoraMay 6, 2026 Apr 15, 2016 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML...Show more |
2Fedoraproject Uninett2Fedora Mod Auth MellonMay 6, 2026 Apr 15, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory con...Show more |
2Fedoraproject Uninett2Fedora Mod Auth MellonMay 6, 2026 Apr 15, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and proc...Show more |
4Debian FedoraprojectLibpng+1 more7Debian Linux Enterprise Linux Desktop SupplementaryEnterprise Linux Hpc Node+4 moreMay 6, 2026 Apr 14, 2016 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote atta...Show more |
4Debian FedoraprojectLibssh2+1 more4Debian Linux FedoraLibssh2+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecif...Show more |
5Canonical DebianFedoraproject+2 more5Debian Linux Enterprise LinuxFedora+2 moreMay 6, 2026 Apr 13, 2016 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attacker...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibssh+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer derefere...Show more |
5Debian FedoraprojectMercurial+2 more7Debian Linux FedoraLeap+4 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records. |
4Debian FedoraprojectOracle+1 more4Debian Linux FedoraVm Server+1 moreMay 6, 2026 Apr 13, 2016 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content i...Show more |
3Fedoraproject OracleXen3Fedora Vm ServerXenMay 6, 2026 Apr 13, 2016 N/A· v4 3.8 LOW· v3 1.7 LOW· v2 The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content info...Show more |
6Debian FedoraprojectMercurial+3 more14Debian Linux Enterprise Linux DesktopEnterprise Linux Hpc Node+11 moreMay 6, 2026 Apr 13, 2016 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository. |