← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
6Fedoraproject
MariadbOpensuse+3 more
11Enterprise Linux Desktop
Enterprise Linux EusEnterprise Linux Server+8 more
May 6, 2026
Dec 16, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero...Show more
Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.Show less
4Fedoraproject
OpenstackOpensuse+1 more
4Fedora
HorizonOpensuse+1 more
May 6, 2026
Dec 12, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service...Show more
OpenStack Dashboard (Horizon) before 2014.1.3 and 2014.2.x before 2014.2.1 does not properly handle session records when using a db or memcached session engine, which allows remote attackers to cause a denial of service via a large number of requests to the login page.Show less
2Fedoraproject
Yourls
2Fedora
Yourls
May 6, 2026
Dec 10, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the Shorten functionality.
4Debian
FedoraprojectMageia Project+1 more
4Debian Linux
FedoraMageia+1 more
May 6, 2026
Dec 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
UnRTF allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code as demonstrated by a file containing the string "{\cb-999999999".
3Canonical
FedoraprojectGnu
3Binutils
FedoraUbuntu Linux
May 6, 2026
Dec 9, 2014
N/A· v4
N/A· v3
3.6 LOW· v2
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary...Show more
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.Show less
3Canonical
FedoraprojectGnu
3Binutils
FedoraUbuntu Linux
May 6, 2026
Dec 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted f...Show more
Stack-based buffer overflow in the srec_scan function in bfd/srec.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted file.Show less
3Canonical
FedoraprojectGnu
3Binutils
FedoraUbuntu Linux
May 6, 2026
Dec 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted i...Show more
Stack-based buffer overflow in the ihex_scan function in bfd/ihex.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a crafted ihex file.Show less
3Canonical
FedoraprojectGnu
3Binutils
FedoraUbuntu Linux
May 6, 2026
Dec 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a t...Show more
Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.Show less
3Canonical
FedoraprojectGnu
3Binutils
FedoraUbuntu Linux
May 6, 2026
Dec 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted...Show more
The _bfd_XXi_swap_aouthdr_in function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (out-of-bounds write) and possibly have other unspecified impact via a crafted NumberOfRvaAndSizes field in the AOUT header in a PE executable.Show less
3Canonical
FedoraprojectGnu
3Binutils
FedoraUbuntu Linux
May 6, 2026
Dec 9, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an EL...Show more
The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.Show less
3Canonical
FedoraprojectGnu
3Binutils
FedoraUbuntu Linux
May 6, 2026
Dec 9, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
3Debian
FedoraprojectLsyncd Project
3Debian Linux
FedoraLsyncd
May 6, 2026
Dec 5, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
default-rsyncssh.lua in Lsyncd 2.1.5 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a filename.
3Fedoraproject
OpensuseOpenvas
3Fedora
OpensuseOpenvas Manager
May 6, 2026
Dec 3, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command.
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraLibreoffice+1 more
May 6, 2026
Nov 26, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
LibreOffice before 4.3.5 allows remote attackers to cause a denial of service (invalid write operation and crash) and possibly execute arbitrary code via a crafted RTF file.
6Apache
DebianDrupal+3 more
6Debian Linux
DrillDrupal+3 more
May 6, 2026
Nov 24, 2014
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in jquery.ui.dialog.js in the Dialog widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title option.
3Fedoraproject
OpenstackRedhat
3Fedora
NeutronOpenstack
May 6, 2026
Nov 24, 2014
N/A· v4
N/A· v3
4.0 MEDIUM· v2
OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
3Bundler
FedoraprojectOpensuse
3Bundler
FedoraOpensuse
May 6, 2026
Oct 31, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
11Apple
DebianFedoraproject+8 more
20Aix
DatabaseDebian Linux+17 more
May 28, 2026
Oct 15, 2014
N/A· v4
3.4 LOW· v3
4.3 MEDIUM· v2
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, a...Show more
The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.Show less
2Fedoraproject
Mozilla
2Bugzilla
Fedora
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote...Show more
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.Show less
2Fedoraproject
Mozilla
2Bugzilla
Fedora
May 6, 2026
Oct 13, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not s...Show more
The confirm_create_account function in the account-creation feature in token.cgi in Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not specify a scalar context for the realname parameter, which allows remote attackers to create accounts with unverified e-mail addresses by sending three realname values with realname=login_name as the second, as demonstrated by selecting an e-mail address with a domain name for which group privileges are automatically granted.Show less