fedoraproject

5,423 tracked vulnerabilities.

CVE-2020-25863 HIGH
Wireshark <3.2.7, <3.0.14, <2.6.21 - Buffer Overflow
Oct 06, 2020
CVSS 7.5
EPSS 0.05
CVE-2020-25862 HIGH
Wireshark <3.2.7, <3.0.14, <2.6.21 - DoS
Oct 06, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-25613 HIGH
Ruby WEBrick < 1.6.0 - HTTP Request Smuggling via Transfer-Encoding Header
Oct 06, 2020
CVSS 7.5
EPSS 0.04
CVE-2020-26572 MEDIUM
OpenSC <0.21.0-rc1 - Buffer Overflow
Oct 06, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-26571 MEDIUM
OpenSC <0.21.0-rc1 - Buffer Overflow
Oct 06, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-26570 MEDIUM
OpenSC <0.21.0-rc1 - Buffer Overflow
Oct 06, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-8223 MEDIUM
Nextcloud Server 19.0.0 - Privilege Escalation
Oct 05, 2020
CVSS 6.5
EPSS 0.01
CVE-2020-7070 MEDIUM
PHP 7.2.0-7.2.33, 7.3.0-7.3.22, 7.4.0-7.4.10 - Cookie Prefix Confusion via URL Decoding
Oct 02, 2020
CVSS 4.3
EPSS 0.05
CVE-2020-7069 MEDIUM
PHP 7.2.0-7.2.33, 7.3.0-7.3.22, 7.4.0-7.4.10 - Inadequate Encryption Strength in AES-CCM Mode
Oct 02, 2020
CVSS 5.4
EPSS 0.02
CVE-2020-26519 MEDIUM
Artifex MuPDF < 1.18.0 - Heap-Based Buffer Overflow via JBIG2 File Parsing
Oct 02, 2020
CVSS 5.5
EPSS 0.01
CVE-2020-11979 HIGH
Apache Ant <1.10.8 - Code Injection
Oct 01, 2020
CVSS 7.5
EPSS 0.08
CVE-2020-26154 CRITICAL
libproxy <= 0.4.15 - Buffer Overflow via PAC File Without Content-Length Header
Sep 30, 2020
CVSS 9.8
EPSS 0.04
CVE-2020-15216 MEDIUM
goxmldsig < 1.1.0 - Cryptographic Signature Verification Bypass via Crafted XML File
Sep 29, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-26121 HIGH
MediaWiki < 1.34.4 - Incorrect Authorization in FileImporter Extension
Sep 27, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-26120 MEDIUM
MediaWiki < 1.34.4 - Cross-Site Scripting via MobileFrontend Section Line Regex Replacement
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-25869 HIGH
MediaWiki < 1.31.10 and 1.32.x-1.34.x < 1.34.4 - Information Leak via Actor ID Handling
Sep 27, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-25828 MEDIUM
MediaWiki < 1.31.10 and 1.32.0-1.34.3 - Cross-Site Scripting in Message Parser
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-25827 HIGH
MediaWiki < 1.31.10 and 1.32.x-1.34.x < 1.34.4 - Improper Restriction of Excessive Authentication Attempts
Sep 27, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-25815 MEDIUM
MediaWiki 1.32.0-1.34.3 - Cross-Site Scripting in LogEventList::getFiltersDesc
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-25814 MEDIUM
MediaWiki < 1.31.10 and 1.32.0-1.34.3 - Stored Cross-Site Scripting via jQuery Message Parsing
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-25813 MEDIUM
MediaWiki <1.31.10-1.34.4 - Info Disclosure
Sep 27, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-25812 MEDIUM
MediaWiki 1.34.0-1.34.3 - Cross-Site Scripting via Special:Contributions NS Filter
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-26116 HIGH
Python 3.x < 3.5.10, 3.6.x < 3.6.12, 3.7.x < 3.7.9, 3.8.x < 3.8.5 - HTTP Header Injection via HTTPConnection.request
Sep 27, 2020
CVSS 7.2
EPSS 0.06
CVE-2020-25604 MEDIUM
Xen < 4.14.0 - Denial of Service via Timer Migration Race Condition
Sep 23, 2020
CVSS 4.7
EPSS 0.00
CVE-2020-25603 HIGH
Xen < 4.14.0 - Denial of Service via Missing Memory Barriers in Event Channel Access
Sep 23, 2020
CVSS 7.8
EPSS 0.00