Fedoraproject
fedoraproject
5,423 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,423)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Apple FedoraprojectOpenldap3Fedora Mac Os XOpenldapApr 23, 2026 Oct 23, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certifi...Show more |
6Canonical FedoraprojectLinux+3 more8Esx FedoraLinux Kernel+5 moreApr 23, 2026 Oct 22, 2009 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 net/unix/af_unix.c in the Linux kernel 2.6.31.4 and earlier allows local users to cause a denial of service (system hang) by creating an abstract-namespace AF_UNIX listening socket, performing a shutdown operation on thi...Show more |
6Canonical FedoraprojectLinux+3 more8Fedora Linux Enterprise DebuginfoLinux Enterprise Desktop+5 moreApr 23, 2026 Oct 22, 2009 N/A· v4 7.8 HIGH· v3 4.9 MEDIUM· v2 The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointe...Show more |
6Canonical FedoraprojectLinux+3 more13Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+10 moreApr 23, 2026 Oct 20, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier...Show more |
5Canonical FedoraprojectLinux+2 more7Fedora Linux Enterprise DesktopLinux Enterprise Server+4 moreApr 23, 2026 Oct 19, 2009 N/A· v4 N/A· v3 2.1 LOW· v2 The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allo...Show more |
5Canonical FedoraprojectOpensuse+2 more6Fedora Linux EnterpriseLinux Enterprise Server+3 moreApr 23, 2026 Sep 17, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password. |
3Debian F5Fedoraproject3Debian Linux FedoraNginxApr 23, 2026 Sep 15, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, and 0.8.x before 0.8.15 allows remote attackers to execute arbitrary code via crafted HTTP requests. |
3Apple FedoraprojectSamba4Fedora Mac Os XMac Os X Server+1 moreApr 23, 2026 Sep 14, 2009 N/A· v4 N/A· v3 6.0 MEDIUM· v2 Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems,...Show more |
6Apache AppleDebian+3 more7Debian Linux FedoraHttp Server+4 moreApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the...Show more |
3Apache DebianFedoraproject3Debian Linux FedoraHttp ServerApr 23, 2026 Sep 8, 2009 N/A· v4 N/A· v3 2.6 LOW· v2 The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and...Show more |
6Canonical FedoraprojectLinux+3 more12Enterprise Linux Desktop Enterprise Linux EusEnterprise Linux Server+9 moreApr 23, 2026 Aug 27, 2009 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereferen...Show more |
4Apple CanonicalFedoraproject+1 more4Fedora Mac Os XNeon+1 moreApr 23, 2026 Aug 21, 2009 N/A· v4 N/A· v3 5.8 MEDIUM· v2 neon before 0.28.6, when OpenSSL or GnuTLS is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to...Show more |
8Canonical FedoraprojectLinux+5 more12Enterprise Linux Desktop Enterprise Linux ServerEnterprise Linux Workstation+9 moreApr 23, 2026 Aug 18, 2009 N/A· v4 N/A· v3 5.9 MEDIUM· v2 The execve function in the Linux kernel, possibly 2.6.30-rc6 and earlier, does not properly clear the current->clear_child_tid pointer, which allows local users to cause a denial of service (memory corruption) or possibl...Show more |
11Apple CanonicalDebian+8 more19Chrome Debian LinuxEnterprise Linux+16 moreApr 23, 2026 Aug 11, 2009 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notatio...Show more |
7Apache CanonicalDebian+4 more9Debian Linux FedoraJdk+6 moreApr 23, 2026 Aug 6, 2009 N/A· v4 N/A· v3 5.0 MEDIUM· v2 XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a deni...Show more |
6Apple CanonicalDebian+3 more6Debian Linux FedoraMac Os X+3 moreApr 23, 2026 Jul 31, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via ve...Show more |
4Fedoraproject MozillaOpensuse+1 more6Fedora FirefoxLinux Enterprise Debuginfo+3 moreApr 23, 2026 Jul 22, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) atta...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 10, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attackers to cause a denial of service (CPU co...Show more |
5Apache CanonicalDebian+2 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Eus+6 moreApr 23, 2026 Jul 5, 2009 N/A· v4 N/A· v3 7.1 HIGH· v2 The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the...Show more |
4Debian FedoraprojectMozilla+1 more9Debian Linux Enterprise LinuxEnterprise Linux Desktop+6 moreApr 23, 2026 Jun 12, 2009 N/A· v4 7.5 HIGH· v3 9.3 HIGH· v2 Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to execute arbitrary code via a page transiti...Show more |