VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2015-7827
Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
Published 2016-05-13 · Modified
7.5EPSS 0.024
CVE-2016-2849
Botan before 1.10.13 and 1.11.x before 1.11.29 do not use a constant-time algorithm to perform a modular inverse on the signature nonce k, which might allow remote attackers to obtain ECDSA secret keys via a timing side-channel attack.
Published 2016-05-13 · Modified
7.5EPSS 0.024
CVE-2019-5885
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
Published 2019-03-19 · Modified
7.5EPSS 0.024
CVE-2020-36277
Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
Published 2021-03-11 · Modified
7.5EPSS 0.024
CVE-2019-11494
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.
Published 2019-05-08 · Modified
7.5EPSS 0.024
CVE-2022-2309
NULL Pointer Dereference in lxml/lxml
Published 2022-07-05 · Modified
7.5EPSS 0.024
CVE-2021-45115
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. UserAttributeSimilarityValidator incurred significant overhead in evaluating a submitted password that was artificially large in relation to the comparison values. In a situation where access to user registration was unrestricted, this provided a potential vector for a denial-of-service attack.
Published 2022-01-04 · Modified
7.5EPSS 0.024
CVE-2013-4410
ReviewBoard: has an access-control problem in REST API
Published 2019-12-02 · Modified
7.5EPSS 0.024
CVE-2021-22173
Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
Published 2021-02-17 · Modified
7.5EPSS 0.024
CVE-2021-46669
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
Published 2022-02-01 · Modified
7.5EPSS 0.024
CVE-2019-16236
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
Published 2019-09-11 · Modified
7.5EPSS 0.024
CVE-2019-16786
HTTP Request Smuggling: Invalid Transfer-Encoding in Waitress
Published 2019-12-20 · Modified
7.5EPSS 0.024
CVE-2018-17142
The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call.
Published 2018-09-17 · Modified
7.5EPSS 0.024
CVE-2020-12244
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.
Published 2020-05-19 · Modified
7.5EPSS 0.024
CVE-2022-32091
MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.
Published 2022-07-01 · Modified
7.5EPSS 0.024
CVE-2018-17847
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <svg><template><desc><t><svg></template>, leading to a "panic: runtime error" (index out of range) in (*nodeStack).pop in node.go, called from (*parser).clearActiveFormattingElements, during an html.Parse call.
Published 2018-10-01 · Modified
7.5EPSS 0.024
CVE-2020-27638
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
Published 2020-10-22 · Modified
7.5EPSS 0.024
CVE-2022-31779
Improper HTTP/2 scheme and method validation
Published 2022-08-10 · Modified
7.5EPSS 0.024
CVE-2020-1983
libslirp: use after free vulnerability cause a denial of service.
Published 2020-04-22 · Modified
7.5EPSS 0.024
CVE-2020-36280
Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
Published 2021-03-12 · Modified
7.5EPSS 0.024
CVE-2018-18898
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.
Published 2019-03-17 · Modified
7.5EPSS 0.024
CVE-2020-25862
In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.
Published 2020-10-06 · Modified
7.5EPSS 0.024
CVE-2016-7966
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicator to hide content.
Published 2016-12-23 · Modified
7.5EPSS 0.023
CVE-2021-33560
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
Published 2021-06-08 · Modified
7.5EPSS 0.023
CVE-2020-28366
Arbitrary code execution in go command with cgo in cmd/go and cmd/cgo
Published 2020-11-18 · Modified
7.5EPSS 0.023
CVE-2021-28677
An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A malicious EPS file could use this to perform a DoS of Pillow in the open phase, before an image was accepted for opening.
Published 2021-06-02 · Modified
7.5EPSS 0.023
CVE-2014-1487
The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
Published 2014-02-06 · Modified
7.5EPSS 0.023
CVE-2008-4577
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
Published 2008-10-15 · Modified
7.5EPSS 0.023
CVE-2022-28129
Insufficient Validation of HTTP/1.x Headers
Published 2022-08-10 · Modified
7.5EPSS 0.023
CVE-2021-44420
In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.
Published 2021-12-07 · Modified
7.5EPSS 0.023
CVE-2022-31780
HTTP/2 framing vulnerabilities
Published 2022-08-10 · Modified
7.5EPSS 0.023
CVE-2016-7952
X.org libXtst before 1.2.3 allows remote X servers to cause a denial of service (infinite loop) via a reply in the (1) XRecordStartOfData, (2) XRecordEndOfData, or (3) XRecordClientDied category without a client sequence and with attached data.
Published 2016-12-13 · Modified
7.5EPSS 0.023
CVE-2022-32084
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
Published 2022-07-01 · Modified
7.5EPSS 0.023
CVE-2019-17592
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.
Published 2019-10-14 · Modified
7.5EPSS 0.023
CVE-2022-28131
Stack exhaustion from deeply nested XML documents in encoding/xml
Published 2022-08-09 · Modified
7.5EPSS 0.023
CVE-2023-5157
Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6
Published 2023-09-26 · Modified
7.5EPSS 0.023
CVE-2019-18888
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony/mime in 4.3.x).
Published 2019-11-21 · Modified
7.5EPSS 0.022
CVE-2015-4454
SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
Published 2015-06-17 · Modified
7.5EPSS 0.022
CVE-2018-17848
The html package (aka x/net/html) through 2018-09-25 in Go mishandles <math><template><mn><b></template>, leading to a "panic: runtime error" (index out of range) in (*insertionModeStack).pop in node.go, called from inHeadIM, during an html.Parse call.
Published 2018-10-01 · Modified
7.5EPSS 0.022
CVE-2021-26813
markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.
Published 2021-03-03 · Modified
7.5EPSS 0.022
← Prev64 / 135Next →