← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Canonical
DebianFedoraproject+3 more
6Debian Linux
FedoraLibgd+3 more
May 6, 2026
Apr 26, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which trigge...Show more
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code via crafted compressed gd2 data, which triggers a heap-based buffer overflow.Show less
2Fedoraproject
Redhat
6389 Directory Server
Enterprise LinuxEnterprise Linux Desktop+3 more
May 6, 2026
Apr 19, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormall...Show more
slapd/connection.c in 389 Directory Server (formerly Fedora Directory Server) 1.3.4.x before 1.3.4.7 allows remote attackers to cause a denial of service (infinite loop and connection blocking) by leveraging an abnormally closed connection.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary...Show more
Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the _...Show more
Integer overflow in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via the size argument to the __hcreate_r function, which triggers out-of-bounds heap-memory access.Show less
6Canonical
DebianFedoraproject+3 more
10Debian Linux
FedoraGlibc+7 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range...Show more
The strftime function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly obtain sensitive information via an out-of-range time value.Show less
5Canonical
FedoraprojectGnu+2 more
9Fedora
GlibcLinux Enterprise Debuginfo+6 more
May 6, 2026
Apr 19, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long...Show more
Multiple stack-based buffer overflows in the GNU C Library (aka glibc or libc6) before 2.23 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long argument to the (1) nan, (2) nanf, or (3) nanl function.Show less
3Fedoraproject
OracleXen
3Fedora
Vm ServerXen
May 6, 2026
Apr 19, 2016
N/A· v4
8.8 HIGH· v3
7.2 HIGH· v2
Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.
2Fedoraproject
Libreswan
2Fedora
Libreswan
May 6, 2026
Apr 18, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
2Fedoraproject
Latex2rtf Project
2Fedora
Latex2rtf
May 6, 2026
Apr 18, 2016
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file...Show more
Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.Show less
2Fedoraproject
Fourkitchens
2Block Class
Fedora
May 6, 2026
Apr 15, 2016
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML...Show more
Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.Show less
2Fedoraproject
Uninett
2Fedora
Mod Auth Mellon
May 6, 2026
Apr 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory con...Show more
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.Show less
2Fedoraproject
Uninett
2Fedora
Mod Auth Mellon
May 6, 2026
Apr 15, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and proc...Show more
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not check if the ap_get_client_block function returns an error, which allows remote attackers to cause a denial of service (segmentation fault and process crash) via a crafted POST data.Show less
4Debian
FedoraprojectLibpng+1 more
7Debian Linux
Enterprise Linux Desktop SupplementaryEnterprise Linux Hpc Node+4 more
May 6, 2026
Apr 14, 2016
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote atta...Show more
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.Show less
4Debian
FedoraprojectLibssh2+1 more
4Debian Linux
FedoraLibssh2+1 more
May 6, 2026
Apr 13, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecif...Show more
The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."Show less
5Canonical
DebianFedoraproject+2 more
5Debian Linux
Enterprise LinuxFedora+2 more
May 6, 2026
Apr 13, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attacker...Show more
libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLibssh+1 more
May 6, 2026
Apr 13, 2016
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer derefere...Show more
The (1) SSH_MSG_NEWKEYS and (2) SSH_MSG_KEXDH_REPLY packet handlers in package_cb.c in libssh before 0.6.5 do not properly validate state, which allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted SSH packet.Show less
5Debian
FedoraprojectMercurial+2 more
7Debian Linux
FedoraLeap+4 more
May 6, 2026
Apr 13, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
4Debian
FedoraprojectOracle+1 more
4Debian Linux
FedoraVm Server+1 more
May 6, 2026
Apr 13, 2016
N/A· v4
3.8 LOW· v3
1.7 LOW· v2
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content i...Show more
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.Show less
3Fedoraproject
OracleXen
3Fedora
Vm ServerXen
May 6, 2026
Apr 13, 2016
N/A· v4
3.8 LOW· v3
1.7 LOW· v2
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content info...Show more
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-2013-2076.Show less
6Debian
FedoraprojectMercurial+3 more
14Debian Linux
Enterprise Linux DesktopEnterprise Linux Hpc Node+11 more
May 6, 2026
Apr 13, 2016
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.