fedoraproject
5,423 tracked vulnerabilities.
CVE-2020-25863
HIGH
Wireshark <3.2.7, <3.0.14, <2.6.21 - Buffer Overflow
Oct 06, 2020
CVSS 7.5
EPSS 0.05
CVE-2020-25862
HIGH
Wireshark <3.2.7, <3.0.14, <2.6.21 - DoS
Oct 06, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-25613
HIGH
Ruby WEBrick < 1.6.0 - HTTP Request Smuggling via Transfer-Encoding Header
Oct 06, 2020
CVSS 7.5
EPSS 0.04
CVE-2020-26572
MEDIUM
OpenSC <0.21.0-rc1 - Buffer Overflow
Oct 06, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-26571
MEDIUM
OpenSC <0.21.0-rc1 - Buffer Overflow
Oct 06, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-26570
MEDIUM
OpenSC <0.21.0-rc1 - Buffer Overflow
Oct 06, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-8223
MEDIUM
Nextcloud Server 19.0.0 - Privilege Escalation
Oct 05, 2020
CVSS 6.5
EPSS 0.01
CVE-2020-7070
MEDIUM
PHP 7.2.0-7.2.33, 7.3.0-7.3.22, 7.4.0-7.4.10 - Cookie Prefix Confusion via URL Decoding
Oct 02, 2020
CVSS 4.3
EPSS 0.05
CVE-2020-7069
MEDIUM
PHP 7.2.0-7.2.33, 7.3.0-7.3.22, 7.4.0-7.4.10 - Inadequate Encryption Strength in AES-CCM Mode
Oct 02, 2020
CVSS 5.4
EPSS 0.02
CVE-2020-26519
MEDIUM
Artifex MuPDF < 1.18.0 - Heap-Based Buffer Overflow via JBIG2 File Parsing
Oct 02, 2020
CVSS 5.5
EPSS 0.01
CVE-2020-11979
HIGH
Apache Ant <1.10.8 - Code Injection
Oct 01, 2020
CVSS 7.5
EPSS 0.08
CVE-2020-26154
CRITICAL
libproxy <= 0.4.15 - Buffer Overflow via PAC File Without Content-Length Header
Sep 30, 2020
CVSS 9.8
EPSS 0.04
CVE-2020-15216
MEDIUM
goxmldsig < 1.1.0 - Cryptographic Signature Verification Bypass via Crafted XML File
Sep 29, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-26121
HIGH
MediaWiki < 1.34.4 - Incorrect Authorization in FileImporter Extension
Sep 27, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-26120
MEDIUM
MediaWiki < 1.34.4 - Cross-Site Scripting via MobileFrontend Section Line Regex Replacement
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-25869
HIGH
MediaWiki < 1.31.10 and 1.32.x-1.34.x < 1.34.4 - Information Leak via Actor ID Handling
Sep 27, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-25828
MEDIUM
MediaWiki < 1.31.10 and 1.32.0-1.34.3 - Cross-Site Scripting in Message Parser
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-25827
HIGH
MediaWiki < 1.31.10 and 1.32.x-1.34.x < 1.34.4 - Improper Restriction of Excessive Authentication Attempts
Sep 27, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-25815
MEDIUM
MediaWiki 1.32.0-1.34.3 - Cross-Site Scripting in LogEventList::getFiltersDesc
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-25814
MEDIUM
MediaWiki < 1.31.10 and 1.32.0-1.34.3 - Stored Cross-Site Scripting via jQuery Message Parsing
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-25813
MEDIUM
MediaWiki <1.31.10-1.34.4 - Info Disclosure
Sep 27, 2020
CVSS 5.3
EPSS 0.01
CVE-2020-25812
MEDIUM
MediaWiki 1.34.0-1.34.3 - Cross-Site Scripting via Special:Contributions NS Filter
Sep 27, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-26116
HIGH
Python 3.x < 3.5.10, 3.6.x < 3.6.12, 3.7.x < 3.7.9, 3.8.x < 3.8.5 - HTTP Header Injection via HTTPConnection.request
Sep 27, 2020
CVSS 7.2
EPSS 0.06
CVE-2020-25604
MEDIUM
Xen < 4.14.0 - Denial of Service via Timer Migration Race Condition
Sep 23, 2020
CVSS 4.7
EPSS 0.00
CVE-2020-25603
HIGH
Xen < 4.14.0 - Denial of Service via Missing Memory Barriers in Event Channel Access
Sep 23, 2020
CVSS 7.8
EPSS 0.00
Products
fedora 5,353
extra_packages_for_enterprise_linux 76
389_directory_server 39
sssd 19
fedora_core 8
389_administration_server 1
anaconda 1
arm_installer 1
commons 1
coolkey 1
crypto-utils 1
fedmsg 1
fedora_linux_kernel 1
python-fedora 1
sectool 1
selinux-policy 1
spin-kickstarts 1
supybot-fedora 1
unbound 1
Quick Filters