← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3Debian
FedoraprojectProsody
3Debian Linux
FedoraProsody
May 6, 2026
Jan 12, 2016
N/A· v4
5.9 MEDIUM· v3
4.3 MEDIUM· v2
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
2Fedoraproject
Shellinabox Project
2Fedora
Shellinabox
May 6, 2026
Jan 12, 2016
N/A· v4
7.4 HIGH· v3
4.3 MEDIUM· v2
The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.
6Canonical
DebianFedoraproject+3 more
11Debian Linux
Enterprise Linux EusEnterprise Linux Server+8 more
May 6, 2026
Jan 12, 2016
N/A· v4
8.6 HIGH· v3
7.8 HIGH· v2
The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
2Fedoraproject
Zarafa
2Fedora
Zarafa Collaboration Platform
May 6, 2026
Jan 11, 2016
N/A· v4
8.4 HIGH· v3
7.2 HIGH· v2
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.
3Apache
FedoraprojectRedhat
3Activemq
FedoraOpenshift
May 6, 2026
Jan 8, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMess...Show more
Apache ActiveMQ 5.x before 5.13.0 does not restrict the classes that can be serialized in the broker, which allows remote attackers to execute arbitrary code via a crafted serialized Java Message Service (JMS) ObjectMessage object.Show less
4Fedoraproject
OraclePcre+1 more
4Fedora
PcrePhp+1 more
May 6, 2026
Jan 3, 2016
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and relat...Show more
The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.Show less
2Fedoraproject
Gnu
2Fedora
Grub2
May 6, 2026
Dec 16, 2015
N/A· v4
7.4 HIGH· v3
6.9 MEDIUM· v2
Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters...Show more
Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger an "Off-by-two" or "Out of bounds overwrite" memory error.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
4.0 MEDIUM· v2
The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of...Show more
Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application crash) via an MP4 video file with crafted covr metadata that triggers a buffer overflow.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by trigge...Show more
Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a deque size change.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScri...Show more
Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a malformed PushPromise frame that triggers d...Show more
The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a malformed PushPromise frame that triggers decompressed-buffer length miscalculation and incorrect memory allocation.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers inco...Show more
The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a craf...Show more
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other i...Show more
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 image.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt r...Show more
The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
6.8 MEDIUM· v2
Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute...Show more
Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute arbitrary code via a crafted MP4 video file that triggers a buffer overflow.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering a...Show more
Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering a graphics operation that requires a large texture allocation.Show less
3Fedoraproject
MozillaOpensuse
4Fedora
FirefoxLeap+1 more
May 6, 2026
Dec 16, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors.