← Back

Fedoraproject

fedoraproject

5,427 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,427)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
FedoraprojectOpensuse+1 more
4Debian Linux
FedoraOpensuse+1 more
Apr 23, 2026
Mar 31, 2008
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
7Apple
CanonicalDebian+4 more
11Debian Linux
FedoraKerberos 5+8 more
Apr 23, 2026
Mar 19, 2008
N/A· v4
7.5 HIGH· v3
4.3 MEDIUM· v2
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "...Show more
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."Show less
4Canonical
DebianFedoraproject+1 more
4Debian Linux
FedoraKerberos 5+1 more
Apr 23, 2026
Mar 19, 2008
N/A· v4
9.8 CRITICAL· v3
9.3 HIGH· v2
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that...Show more
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.Show less
2Fedoraproject
Ruby Lang
2Fedora
Webrick
Apr 23, 2026
Mar 4, 2008
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allow...Show more
Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allows remote attackers to access arbitrary files via (1) "..%5c" (encoded backslash) sequences or (2) filenames that match patterns in the :NondisclosureName option.Show less
4Fedoraproject
FreedesktopMandrakesoft+1 more
4Dbus
Enterprise LinuxFedora+1 more
Apr 23, 2026
Feb 29, 2008
N/A· v4
N/A· v3
4.6 MEDIUM· v2
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intend...Show more
dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.Show less
7Apple
CanonicalDebian+4 more
11Debian Linux
FedoraLinux+8 more
Apr 23, 2026
Jan 18, 2008
N/A· v4
N/A· v3
9.3 HIGH· v2
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerabili...Show more
The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerability than CVE-2007-4990.Show less
3Apache
CanonicalFedoraproject
3Fedora
Http ServerUbuntu Linux
Apr 23, 2026
Jan 12, 2008
N/A· v4
N/A· v3
4.3 MEDIUM· v2
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 enco...Show more
mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 encoding.Show less
3Debian
FedoraprojectPostgresql
3Debian Linux
FedoraPostgresql
Apr 23, 2026
Jan 9, 2008
N/A· v4
N/A· v3
7.2 HIGH· v2
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileg...Show more
The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.Show less
4Centos
FedoraprojectOracle+1 more
9Centos
Enterprise LinuxEnterprise Linux Desktop+6 more
Apr 23, 2026
Dec 18, 2007
N/A· v4
N/A· v3
4.9 MEDIUM· v2
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping...Show more
Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping named.Show less
6Apache
CanonicalFedoraproject+3 more
7Fedora
Http ServerHttp Server+4 more
Apr 23, 2026
Dec 13, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 a...Show more
Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
2Fedoraproject
Wordpress
2Fedora
Wordpress
Apr 23, 2026
Nov 19, 2007
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentic...Show more
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.Show less
1Fedoraproject
1Coolkey
Apr 23, 2026
Nov 8, 2007
N/A· v4
N/A· v3
3.3 LOW· v2
CoolKey 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files in the /tmp/.pk11ipc1/ directory.
3Debian
FedoraprojectQemu
4Debian Linux
FedoraFedora Core+1 more
Apr 23, 2026
Oct 30, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks,...Show more
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.Show less
2Drupal
Fedoraproject
2Drupal
Fedora
Apr 23, 2026
Oct 19, 2007
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.
2Drupal
Fedoraproject
2Drupal
Fedora
Apr 23, 2026
Oct 19, 2007
N/A· v4
N/A· v3
6.8 MEDIUM· v2
install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.
5Canonical
DebianFedoraproject+2 more
5Debian Linux
FedoraLoop Aes Utils+2 more
Apr 23, 2026
Oct 4, 2007
N/A· v4
N/A· v3
7.2 HIGH· v2
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
2Fedoraproject
Mit
2Fedora
Kerberos 5
Apr 23, 2026
Sep 5, 2007
N/A· v4
N/A· v3
8.5 HIGH· v2
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy doe...Show more
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy does not exist, which might allow remote authenticated users with the "modify policy" privilege to execute arbitrary code via unspecified vectors that trigger a write to an uninitialized pointer.Show less
3Apache
CanonicalFedoraproject
4Fedora
Fedora CoreHttp Server+1 more
Apr 23, 2026
Aug 23, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted dat...Show more
The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.Show less
1Fedoraproject
1Commons
Apr 23, 2026
Aug 15, 2007
N/A· v4
N/A· v3
8.5 HIGH· v2
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password,...Show more
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password, which allows remote attackers to trigger a certain "unexpected / strange response" from an LDAP server, and (2) a reauthentication attempt that throws an exception, which allows remote attackers to trigger use of a cached authentication decision. NOTE: authentication can be bypassed by using vector 1 followed by vector 2, and possibly can be bypassed by using a single vector.Show less
2Apple
Fedoraproject
2Cups
Fedora
Apr 23, 2026
Jul 27, 2007
N/A· v4
N/A· v3
5.0 MEDIUM· v2
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that intr...Show more
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.Show less