Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
8Apple CanonicalDebian+5 more9Curl Debian LinuxFedora+6 moreMay 6, 2026 Apr 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly hav...Show more |
2Fedoraproject Wesnoth2Battle For Wesnoth FedoraMay 6, 2026 Apr 14, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The WML/Lua API in Battle for Wesnoth 1.7.x through 1.11.x and 1.12.x before 1.12.2 allows remote attackers to read arbitrary files via a crafted (1) campaign or (2) map file. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraLibtasn1+1 moreMay 6, 2026 Apr 10, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 Stack-based buffer overflow in asn1_der_decoding in libtasn1 before 4.4 allows remote attackers to have unspecified impact via unknown vectors. |
3Arj Software DebianFedoraproject3Arj Archiver Debian LinuxFedoraMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive. |
2Arj Software Fedoraproject2Arj Archiver FedoraMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open-source ARJ archiver 3.10.22 does not properly remove leading slashes from paths, which allows remote attackers to conduct absolute path traversal attacks and write to arbitrary files via multiple leading slashes in...Show more |
2Arj Software Fedoraproject2Arj Archiver FedoraMay 6, 2026 Apr 8, 2015 N/A· v4 N/A· v3 5.8 MEDIUM· v2 Open-source ARJ archiver 3.10.22 allows remote attackers to conduct directory traversal attacks via a symlink attack in an ARJ archive. |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraUbuntu Linux+1 moreMay 6, 2026 Apr 1, 2015 N/A· v4 N/A· v3 4.9 MEDIUM· v2 QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabl...Show more |
The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via...Show more |
Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations. |
The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a gr...Show more |
2Fedoraproject Selinux2Fedora SetroubleshootMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 10.0 HIGH· v2 The get_rpm_nvr_by_file_path_temporary function in util.py in setroubleshoot before 3.2.22 allows remote attackers to execute arbitrary commands via shell metacharacters in a file name. |
MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request. |
5Debian FedoraprojectNih+2 more5Debian Linux FedoraLibzip+2 moreMay 6, 2026 Mar 30, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remot...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 Mar 27, 2015 N/A· v4 N/A· v3 2.1 LOW· v2 The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory...Show more |
6Canonical DebianDjangoproject+3 more6Debian Linux DjangoFedora+3 moreMay 6, 2026 Mar 25, 2015 N/A· v4 N/A· v3 4.3 MEDIUM· v2 The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scr...Show more |
5Canonical DjangoprojectFedoraproject+2 more5Django FedoraOpensuse+2 moreMay 6, 2026 Mar 25, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by...Show more |
3Digia FedoraprojectOpensuse3Fedora OpensuseQtMay 6, 2026 Mar 25, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BM...Show more |
5Debian FedoraprojectOpensuse+2 more5Debian Linux FedoraOpensuse+2 moreMay 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 7.5 HIGH· v2 The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. |
3Apache DebianFedoraproject3Debian Linux FedoraXerces C++May 6, 2026 Mar 24, 2015 N/A· v4 N/A· v3 5.0 MEDIUM· v2 internal/XMLReader.cpp in Apache Xerces-C before 3.1.2 allows remote attackers to cause a denial of service (segmentation fault and crash) via crafted XML data. |
Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console b...Show more |