VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2021-25218
A too-strict assertion check could be triggered when responses in BIND 9.16.19 and 9.17.16 require UDP fragmentation if RRL is in use
Published 2021-08-18 · Modified
7.5EPSS 0.036
CVE-2020-12663
Unbound before 1.10.1 has an infinite loop via malformed DNS answers received from upstream servers.
Published 2020-05-19 · Modified
7.5EPSS 0.036
CVE-2016-9397
The jpc_dequantize function in jpc_dec.c in JasPer 1.900.13 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
Published 2017-03-23 · Modified
7.5EPSS 0.036
CVE-2016-9446
The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.
Published 2017-01-23 · Modified
7.5EPSS 0.036
CVE-2022-24464
.NET and Visual Studio Denial of Service Vulnerability
Published 2022-03-09 · Modified
7.5EPSS 0.036
CVE-2020-10704
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
Published 2020-05-06 · Modified
7.5EPSS 0.035
CVE-2020-14303
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
Published 2020-07-06 · Modified
7.5EPSS 0.035
CVE-2022-24836
Inefficient Regular Expression Complexity in Nokogiri
Published 2022-04-11 · Modified
7.5EPSS 0.035
CVE-2021-21996
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
Published 2021-09-08 · Modified
7.5EPSS 0.035
CVE-2022-21716
Buffer Overflow in Twisted
Published 2022-03-03 · Modified
7.5EPSS 0.035
CVE-2015-6855
hw/ide/core.c in QEMU does not properly restrict the commands accepted by an ATAPI device, which allows guest users to cause a denial of service or possibly have unspecified other impact via certain IDE commands, as demonstrated by a WIN_READ_NATIVE_MAX command to an empty drive, which triggers a divide-by-zero error and instance crash.
Published 2015-11-06 · Modified
7.5EPSS 0.035
CVE-2008-0063
The Kerberos 4 support in KDC in MIT Kerberos 5 (krb5kdc) does not properly clear the unused portion of a buffer when generating an error message, which might allow remote attackers to obtain sensitive information, aka "Uninitialized stack values."
Published 2008-03-19 · Modified
7.5EPSS 0.035
CVE-2017-6311
gdk-pixbuf-thumbnailer.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors related to printing an error message.
Published 2017-03-10 · Modified
7.5EPSS 0.035
CVE-2016-9243
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
Published 2017-03-27 · Modified
7.5EPSS 0.035
CVE-2015-1783
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.
Published 2017-08-11 · Modified
7.5EPSS 0.035
CVE-2020-3341
ClamAV PDF Parsing Denial of Service Vulnerability
Published 2020-05-13 · Modified
7.5EPSS 0.034
CVE-2018-14553
gdImageClone in gd.c in libgd 2.1.0-rc2 through 2.2.5 has a NULL pointer dereference allowing attackers to crash an application via a specific function call sequence. Only affects PHP when linked with an external libgd (not bundled).
Published 2020-02-11 · Modified
7.5EPSS 0.034
CVE-2020-15166
Denial of Service in ZeroMQ
Published 2020-09-11 · Modified
7.5EPSS 0.034
CVE-2019-3836
It was discovered in gnutls before version 3.6.7 upstream that there is an uninitialized pointer access in gnutls versions 3.6.3 or later which can be triggered by certain post-handshake messages.
Published 2019-04-01 · Modified
7.5EPSS 0.034
CVE-2024-34069
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
Published 2024-05-06 · Analyzed
7.5EPSS 0.034
CVE-2016-2146
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.
Published 2016-04-15 · Modified
7.5EPSS 0.034
CVE-2021-20718
mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.
Published 2021-05-20 · Modified
7.5EPSS 0.034
CVE-2021-39921
NULL pointer exception in the Modbus dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
Published 2021-11-19 · Modified
7.5EPSS 0.034
CVE-2022-27406
FreeType commit 22a0cccb4d9d002f33c1ba7a4b36812c7d4f46b5 was discovered to contain a segmentation violation via the function FT_Request_Size.
Published 2022-04-22 · Modified
7.5EPSS 0.033
CVE-2020-24584
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
Published 2020-09-01 · Modified
7.5EPSS 0.033
CVE-2021-39920
NULL pointer exception in the IPPUSB dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
Published 2021-11-18 · Modified
7.5EPSS 0.033
CVE-2021-41772
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.
Published 2021-11-08 · Modified
7.5EPSS 0.033
CVE-2021-33503
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
Published 2021-06-29 · Modified
7.5EPSS 0.033
CVE-2022-27664
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
Published 2022-09-06 · Modified
7.5EPSS 0.033
CVE-2022-37451
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
Published 2022-08-06 · Modified
7.5EPSS 0.033
CVE-2017-1000050
JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service.
Published 2017-07-13 · Modified
7.5EPSS 0.033
CVE-2020-7044
In Wireshark 3.2.x before 3.2.1, the WASSP dissector could crash. This was addressed in epan/dissectors/packet-wassp.c by using >= and <= to resolve off-by-one errors.
Published 2020-01-16 · Modified
7.5EPSS 0.032
CVE-2016-9956
The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
Published 2017-02-22 · Modified
7.5EPSS 0.032
CVE-2020-27827
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Published 2021-03-18 · Modified
7.5EPSS 0.032
CVE-2014-9328
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."
Published 2015-02-03 · Modified
7.5EPSS 0.032
CVE-2013-4357
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
Published 2019-12-31 · Modified
7.5EPSS 0.032
CVE-2021-41817
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
Published 2022-01-01 · Modified
7.5EPSS 0.032
CVE-2021-4182
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
Published 2021-12-30 · Modified
7.5EPSS 0.032
CVE-2015-4342
SQL injection vulnerability in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via unspecified vectors involving a cdef id.
Published 2015-06-17 · Modified
7.5EPSS 0.032
CVE-2020-3481
Clam AntiVirus (ClamAV) Software Null Pointer Dereference Vulnerability
Published 2020-07-20 · Modified
7.5EPSS 0.032
← Prev60 / 135Next →