VendorsFedora Projectfedora17
Vulnerabilities

Fedora Project Fedora 17

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

57CVEs
CVE-2015-7810
libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
Published 2019-11-22 · Modified
4.7EPSS 0.004
CVE-2013-4235
shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
Published 2019-12-03 · Modified
4.7EPSS 0.003
CVE-2013-0237
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
Published 2013-07-08 · Modified
4.3EPSS 0.031
CVE-2010-5109
Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of service (crash) via a crafted TNEF file, which triggers a buffer overflow.
Published 2014-05-05 · Modified
4.3EPSS 0.024
CVE-2013-1812
The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansion (XEE) attack.
Published 2013-12-12 · Modified
4.3EPSS 0.021
CVE-2012-3354
doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.
Published 2012-11-20 · Modified
4.3EPSS 0.014
CVE-2012-1159
Moodle before 2.2.2: Overview report allows users to see hidden courses
Published 2019-11-14 · Modified
4.3EPSS 0.014
CVE-2012-1158
Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
Published 2019-11-14 · Modified
4.3EPSS 0.014
CVE-2012-1161
Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
Published 2019-11-14 · Modified
4.3EPSS 0.014
CVE-2013-1930
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.
Published 2019-10-31 · Modified
4.3EPSS 0.012
CVE-2012-1157
Moodle before 2.2.2 has a default repository capabilities issue where all repositories are viewable by all users by default
Published 2019-11-14 · Modified
4.3EPSS 0.012
CVE-2013-2191
python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
Published 2014-02-08 · Modified
4.3EPSS 0.009
CVE-2013-1416
The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.
Published 2013-04-19 · Modified
4.0EPSS 0.029
CVE-2012-1160
Moodle before 2.2.2 has a permission issue in Forum Subscriptions where unenrolled users can subscribe/unsubscribe via mod/forum/index.php
Published 2019-11-14 · Modified
4.0EPSS 0.012
CVE-2013-0348
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
Published 2013-12-13 · Modified
2.1EPSS 0.005
CVE-2013-1888
pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
Published 2013-08-16 · Modified
2.1EPSS 0.004
CVE-2012-4453
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
Published 2012-10-09 · Modified
2.1EPSS 0.004
← Prev2 / 2