Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory. |
5Canonical FedoraprojectOpensuse+2 more5Enterprise Linux FedoraOpensuse+2 moreApr 29, 2026 Aug 6, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Integer overflow in the read_nttrans_ea_list function in nttrans.c in smbd in Samba 3.x before 3.5.22, 3.6.x before 3.6.17, and 4.x before 4.0.8 allows remote attackers to cause a denial of service (memory consumption) v...Show more |
2Fedoraproject Redhat2389 Directory Server Directory ServerApr 29, 2026 Jul 31, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The Red Hat Directory Server before 8.2.11-13 and 389 Directory Server do not properly restrict access to entity attributes, which allows remote authenticated users to obtain sensitive information via a search query for...Show more |
10Fedoraproject FreebsdHp+7 more12Bind Business ServerDnsco Bind+9 moreApr 29, 2026 Jul 29, 2013 N/A· v4 N/A· v3 7.8 HIGH· v2 The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause...Show more |
The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a chunked Transfer-Encoding request wi...Show more |
3Fedoraproject MoxiecodeWordpress3Fedora PluploadWordpressApr 29, 2026 Jul 8, 2013 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id...Show more |
6Canonical DebianFedoraproject+3 more6Debian Linux FedoraLibxcb+3 moreApr 29, 2026 Jun 15, 2013 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function. |
6Canonical DebianFedoraproject+3 more10Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+7 moreApr 29, 2026 May 29, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers to cause a denial of service (CPU and ba...Show more |
The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the nsslapd-allow-anonymous-access configura...Show more |
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraModsecurity+1 moreApr 29, 2026 Apr 25, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 ModSecurity before 2.7.3 allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML external entity declaration in conjun...Show more |
4Fedoraproject MitOpensuse+1 more8Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+5 moreApr 29, 2026 Apr 19, 2013 N/A· v4 N/A· v3 4.0 MEDIUM· v2 The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticate...Show more |
3Canonical FedoraprojectTransmissionbt3Fedora TransmissionUbuntu LinuxApr 29, 2026 Apr 3, 2013 N/A· v4 N/A· v3 7.5 HIGH· v2 Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via craf...Show more |
user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote attackers to obtain sensitive course-profile...Show more |
The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_groups option, which allows remote authentic...Show more |
1Fedoraproject 1389 Directory Server Apr 29, 2026 Mar 13, 2013 N/A· v4 N/A· v3 5.0 MEDIUM· v2 389 Directory Server before 1.3.0.4 allows remote attackers to cause a denial of service (crash) via a zero length LDAP control sequence. |
2Fedoraproject Redhat2Enterprise Linux FedoraApr 29, 2026 Mar 1, 2013 N/A· v4 N/A· v3 1.9 LOW· v2 The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, wh...Show more |
The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/ssh/sshsrv_cmd.c in System Security Servic...Show more |
2Fedoraproject Redhat2Enterprise Linux SssdApr 29, 2026 Feb 24, 2013 N/A· v4 N/A· v3 3.7 LOW· v2 System Security Services Daemon (SSSD) before 1.9.4, when (1) creating, (2) copying, or (3) removing a user home directory tree, allows local users to create, modify, or delete arbitrary files via a symlink attack on ano...Show more |
3Debian FedoraprojectZend3Debian Linux FedoraZend FrameworkApr 29, 2026 Feb 13, 2013 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Zend_XmlRpc in Zend Framework 1.x before 1.11.12 and 1.12.x before 1.12.0 does not properly handle SimpleXMLElement classes, which allows remote attackers to read arbitrary files or create TCP connections via an external...Show more |
7Canonical DebianFedoraproject+4 more12Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+9 moreApr 29, 2026 Feb 13, 2013 N/A· v4 N/A· v3 9.3 HIGH· v2 Buffer overflow in the e1000_receive function in the e1000 device driver (hw/e1000.c) in QEMU 1.3.0-rc2 and other versions, when the SBP and LPE flags are disabled, allows remote attackers to cause a denial of service (g...Show more |