← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
8Apple
CanonicalDebian+5 more
9Curl
Debian LinuxFedora+6 more
May 6, 2026
Apr 24, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly hav...Show more
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.Show less
2Fedoraproject
Wesnoth
2Battle For Wesnoth
Fedora
May 6, 2026
Apr 14, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1) campaign or (2) map file.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLibtasn1+1 more
May 6, 2026
Apr 10, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors.
3Arj Software
DebianFedoraproject
3Arj Archiver
Debian LinuxFedora
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
2Arj Software
Fedoraproject
2Arj Archiver
Fedora
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in...Show more
Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in a path in an ARJ archive.Show less
2Arj Software
Fedoraproject
2Arj Archiver
Fedora
May 6, 2026
Apr 8, 2015
N/A· v4
N/A· v3
5.8 MEDIUM· v2
Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraUbuntu Linux+1 more
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabl...Show more
QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request (UR) response.Show less
2Fedoraproject
Xen
2Fedora
Xen
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
4.9 MEDIUM· v2
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via...Show more
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).Show less
2Fedoraproject
Xen
2Fedora
Xen
May 6, 2026
Apr 1, 2015
N/A· v4
N/A· v3
7.1 HIGH· v2
Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.
2Fedoraproject
Freeipa
2Fedora
Freeipa
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a gr...Show more
The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.Show less
2Fedoraproject
Selinux
2Fedora
Setroubleshoot
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
10.0 HIGH· v2
The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name.
2Fedoraproject
Mongodb
2Fedora
Mongodb
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
5Debian
FedoraprojectNih+2 more
5Debian Linux
FedoraLibzip+2 more
May 6, 2026
Mar 30, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remot...Show more
Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many entries, leading to a heap-based buffer overflow.Show less
5Debian
FedoraprojectOpensuse+2 more
5Debian Linux
FedoraOpensuse+2 more
May 6, 2026
Mar 27, 2015
N/A· v4
N/A· v3
2.1 LOW· v2
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory...Show more
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.Show less
6Canonical
DebianDjangoproject+3 more
6Debian Linux
DjangoFedora+3 more
May 6, 2026
Mar 25, 2015
N/A· v4
N/A· v3
4.3 MEDIUM· v2
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scr...Show more
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.Show less
5Canonical
DjangoprojectFedoraproject+2 more
5Django
FedoraOpensuse+2 more
May 6, 2026
Mar 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by...Show more
The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.Show less
3Digia
FedoraprojectOpensuse
3Fedora
OpensuseQt
May 6, 2026
Mar 25, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BM...Show more
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.Show less
5Debian
FedoraprojectOpensuse+2 more
5Debian Linux
FedoraOpensuse+2 more
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
7.5 HIGH· v2
The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
3Apache
DebianFedoraproject
3Debian Linux
FedoraXerces C++
May 6, 2026
Mar 24, 2015
N/A· v4
N/A· v3
5.0 MEDIUM· v2
internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data.
2Fedoraproject
Xen
2Fedora
Xen
May 6, 2026
Mar 18, 2015
N/A· v4
N/A· v3
1.9 LOW· v2
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console b...Show more
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.0.1, when not compiled with SDL support.Show less