← Back

Fedoraproject

fedoraproject

5,423 CVEs • 20 products

Products (20)

Click to collapse
Toggle
Fedora
fedora
Sssd
sssd
Fedora Core
fedora_core
Commons
commons
Coolkey
coolkey
Anaconda
anaconda
Crypto Utils
crypto-utils
Arm Installer
arm_installer
Fedmsg
fedmsg
Python Fedora
python-fedora
Sectool
sectool
Selinux Policy
selinux-policy
Supybot Fedora
supybot-fedora
Unbound
unbound
Atomic
atomic

CVEs (5,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
3C Ares Project
FedoraprojectRedhat
4C Ares
Enterprise LinuxFedora+1 more
Jun 17, 2026
Mar 6, 2023
N/A· v4
8.6 HIGH· v3
N/A· v2
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or...Show more
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.Show less
2Fedoraproject
Samba
2Fedora
Samba
Jun 17, 2026
Mar 6, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.
2Fedoraproject
Libtiff
2Fedora
Libtiff
Jun 17, 2026
Mar 3, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with com...Show more
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.Show less
3Fedoraproject
PostgresqlRedhat
6Enterprise Linux
FedoraIntegration Camel K+3 more
Jun 17, 2026
Mar 3, 2023
N/A· v4
3.7 LOW· v3
N/A· v2
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report...Show more
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.Show less
2Fedoraproject
Webkitgtk
2Fedora
Webkitgtk
Jun 17, 2026
Mar 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
2Fedoraproject
Vim
2Fedora
Vim
Jun 17, 2026
Mar 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.
2Fedoraproject
Sudo Project
2Fedora
Sudo
Jun 17, 2026
Feb 28, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
2Fedoraproject
Golang
3Fedora
ImageTiff
Jun 17, 2026
Feb 28, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
2Fedoraproject
Redhat
2Directory Server
Fedora
Jun 17, 2026
Feb 27, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker wit...Show more
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat from this vulnerability is to data confidentiality.Show less
5Debian
FedoraprojectHaxx+2 more
9Clustered Data Ontap
CurlDebian Linux+6 more
Jun 17, 2026
Feb 23, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potent...Show more
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped, but the cap was implemented on a per-header basis allowing a maliciousserver to insert a virtually unlimited number of compression steps simply byusing many headers. The use of such a decompression chain could result in a "malloc bomb", making curl end up spending enormous amounts of allocated heap memory, or trying to and returning out of memory errors.Show less
2Fedoraproject
Gnome
2Epiphany
Fedora
Jun 17, 2026
Feb 20, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
3Fedoraproject
NetappPython
6Active Iq Unified Manager
FedoraManagement Services For Element Software+3 more
Jun 17, 2026
Feb 17, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
5Debian
FedoraprojectGnu+2 more
7Active Iq Unified Manager
Converged Systems Advisor AgentDebian Linux+4 more
Jun 17, 2026
Feb 15, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbache...Show more
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.Show less
2Fedoraproject
Paloaltonetworks
2Cortex Xsoar
Fedora
Jun 17, 2026
Feb 8, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
2Fedoraproject
Gnu
2Fedora
Less
Jun 17, 2026
Feb 7, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
2Fedoraproject
Harfbuzz Project
2Fedora
Harfbuzz
Jun 17, 2026
Feb 4, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.
3Fedoraproject
NetappOpenbsd
6500f Firmware
A250 FirmwareC250 Firmware+3 more
Jun 17, 2026
Feb 3, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the defaul...Show more
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."Show less
3Fedoraproject
Pesign ProjectRedhat
3Enterprise Linux
FedoraPesign
Jun 17, 2026
Feb 2, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privi...Show more
A flaw was found in pesign. The pesign package provides a systemd service used to start the pesign daemon. This service unit runs a script to set ACLs for /etc/pki/pesign and /run/pesign directories to grant access privileges to users in the 'pesign' group. However, the script doesn't check for symbolic links. This could allow an attacker to gain access to privileged files and directories via a path traversal attack.Show less
2Fedoraproject
Redhat
13Enterprise Linux
Enterprise Linux DesktopEnterprise Linux For Ibm Z Systems+10 more
Jun 17, 2026
Feb 1, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
sssd: libsss_certmap fails to sanitise certificate data used in LDAP filters
2Fedoraproject
Gnu
2Fedora
Tar
Jun 17, 2026
Jan 30, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_he...Show more
GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.Show less