Fedoraproject
fedoraproject
5,427 CVEs • 20 products
Products (20)
Click to collapseToggle
Products (20)
Click to collapse
CVEs (5,427)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
4Debian FedoraprojectOpensuse+1 more4Debian Linux FedoraOpensuse+1 moreApr 23, 2026 Mar 31, 2008 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information. |
7Apple CanonicalDebian+4 more11Debian Linux FedoraKerberos 5+8 moreApr 23, 2026 Mar 19, 2008 N/A· v4 7.5 HIGH· v3 4.3 MEDIUM· v2 The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "...Show more |
4Canonical DebianFedoraproject+1 more4Debian Linux FedoraKerberos 5+1 moreApr 23, 2026 Mar 19, 2008 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that...Show more |
2Fedoraproject Ruby Lang2Fedora WebrickApr 23, 2026 Mar 4, 2008 N/A· v4 N/A· v3 5.0 MEDIUM· v2 Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when running on systems that support backslash (\) path separators or case-insensitive file names, allow...Show more |
4Fedoraproject FreedesktopMandrakesoft+1 more4Dbus Enterprise LinuxFedora+1 moreApr 23, 2026 Feb 29, 2008 N/A· v4 N/A· v3 4.6 MEDIUM· v2 dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intend...Show more |
7Apple CanonicalDebian+4 more11Debian Linux FedoraLinux+8 moreApr 23, 2026 Jan 18, 2008 N/A· v4 N/A· v3 9.3 HIGH· v2 The XInput extension in X.Org Xserver before 1.4.1 allows context-dependent attackers to execute arbitrary code via requests related to byte swapping and heap corruption within multiple functions, a different vulnerabili...Show more |
3Apache CanonicalFedoraproject3Fedora Http ServerUbuntu LinuxApr 23, 2026 Jan 12, 2008 N/A· v4 N/A· v3 4.3 MEDIUM· v2 mod_proxy_ftp in Apache 2.2.x before 2.2.7-dev, 2.0.x before 2.0.62-dev, and 1.3.x before 1.3.40-dev does not define a charset, which allows remote attackers to conduct cross-site scripting (XSS) attacks using UTF-7 enco...Show more |
3Debian FedoraprojectPostgresql3Debian Linux FedoraPostgresqlApr 23, 2026 Jan 9, 2008 N/A· v4 N/A· v3 7.2 HIGH· v2 The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileg...Show more |
4Centos FedoraprojectOracle+1 more9Centos Enterprise LinuxEnterprise Linux Desktop+6 moreApr 23, 2026 Dec 18, 2007 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as causing a denial of service by stopping...Show more |
6Apache CanonicalFedoraproject+3 more7Fedora Http ServerHttp Server+4 moreApr 23, 2026 Dec 13, 2007 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in the (1) mod_imap module in the Apache HTTP Server 1.3.0 through 1.3.39 and 2.0.35 through 2.0.61 and the (2) mod_imagemap module in the Apache HTTP Server 2.2.0 through 2.2.6 a...Show more |
2Fedoraproject Wordpress2Fedora WordpressApr 23, 2026 Nov 19, 2007 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentic...Show more |
CoolKey 1.1.0 allows local users to overwrite arbitrary files via a symlink attack on temporary files in the /tmp/.pk11ipc1/ directory. |
3Debian FedoraprojectQemu4Debian Linux FedoraFedora Core+1 moreApr 23, 2026 Oct 30, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks,...Show more |
Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack. |
install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified. |
5Canonical DebianFedoraproject+2 more5Debian Linux FedoraLoop Aes Utils+2 moreApr 23, 2026 Oct 4, 2007 N/A· v4 N/A· v3 7.2 HIGH· v2 mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs. |
The kadm5_modify_policy_internal function in lib/kadm5/srv/svr_policy.c in the Kerberos administration daemon (kadmind) in MIT Kerberos 5 (krb5) 1.5 through 1.6.2 does not properly check return values when the policy doe...Show more |
3Apache CanonicalFedoraproject4Fedora Fedora CoreHttp Server+1 moreApr 23, 2026 Aug 23, 2007 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted dat...Show more |
Fedora Commons before 2.2.1 does not properly handle certain authentication requests involving Java Naming and Directory Interface (JNDI), related to (1) a nonexistent account name in combination with an empty password,...Show more |
The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that intr...Show more |