fedoraproject

5,423 tracked vulnerabilities.

CVE-2020-15811 MEDIUM
Squid <4.13-5.0.4 - HTTP Request Splitting
Sep 02, 2020
CVSS 6.5
EPSS 0.04
CVE-2020-15810 MEDIUM
Squid < 4.13 and 5.x < 5.0.4 - HTTP Request Smuggling via Relaxed Header Parsing
Sep 02, 2020
CVSS 6.5
EPSS 0.03
CVE-2020-16150 MEDIUM
Mbed TLS < 2.7.17 - Timing Side-Channel Attack via CBC Mode Padding
Sep 02, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-24584 HIGH
Django <2.2.16, <3.0.10, <3.1.1 - Info Disclosure
Sep 01, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-24583 HIGH
Django <2.2.16, 3.0<10, 3.1<1 - Info Disclosure
Sep 01, 2020
CVSS 7.5
EPSS 0.04
CVE-2020-14364 MEDIUM
QEMU < 5.2.0 - Out-of-bounds Read/Write in USB Emulator
Aug 31, 2020
CVSS 5.0
EPSS 0.05
CVE-2020-14352 HIGH
librepo < 1.12.1 - Path Traversal via Remote Repository Metadata
Aug 30, 2020
CVSS 8.0
EPSS 0.03
CVE-2020-24972 HIGH
Kleopatra <3.1.12 - Code Execution via openpgp4fpr URL Handling
Aug 29, 2020
CVSS 8.8
EPSS 0.05
CVE-2020-24661 MEDIUM
GNOME Geary <3.36.3 - Info Disclosure
Aug 26, 2020
CVSS 5.9
EPSS 0.01
CVE-2020-24614 HIGH
Fossil <2.10.2, <2.11.2, <2.12.1 - Authenticated RCE
Aug 25, 2020
CVSS 8.8
EPSS 0.03
CVE-2020-24612 MEDIUM
selinux-policy <2020-08-24 - Privilege Escalation
Aug 24, 2020
CVSS 6.7
EPSS 0.00
CVE-2020-24606 HIGH
Squid 3.0-4.12 and 5.x < 5.0.4 - Denial of Service via Crafted Cache Digest Response
Aug 24, 2020
CVSS 8.6
EPSS 0.05
CVE-2020-14367 MEDIUM
chrony < 3.5.1 - Denial of Service via PID File Symlink Attack
Aug 24, 2020
CVSS 6.0
EPSS 0.00
CVE-2020-8624 MEDIUM
BIND <9.16.5 - Privilege Escalation
Aug 21, 2020
CVSS 4.3
EPSS 0.04
CVE-2020-8623 HIGH
BIND 9.10.0-9.11.21, 9.12.0-9.16.5, 9.17.0-9.17.3 - Reachable Assertion via Crafted Query Packet
Aug 21, 2020
CVSS 7.5
EPSS 0.06
CVE-2020-8622 MEDIUM
BIND 9.0.0-9.11.21, 9.12.0-9.16.5, 9.17.0-9.17.3 - Reachable Assertion via Truncated TSIG Response
Aug 21, 2020
CVSS 6.5
EPSS 0.06
CVE-2020-1597 HIGH
ASP.NET Core - Unauthenticated Denial of Service via Specially Crafted Requests
Aug 17, 2020
CVSS 7.5
EPSS 0.07
CVE-2020-1472 MEDIUM KEV
Netlogon Weak Cryptographic Authentication
Aug 17, 2020
CVSS 5.5
EPSS 1.00
CVE-2020-24370 MEDIUM
Lua 5.4.0 - Integer Underflow via getlocal/setlocal Debug Interface
Aug 17, 2020
CVSS 5.3
EPSS 0.04
CVE-2020-24342 HIGH
Lua <= 5.4.0 - Stack-Based Buffer Overflow via luaO_pushvfstring
Aug 13, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-24332 MEDIUM
TrouSerS <0.3.14 - Privilege Escalation
Aug 13, 2020
CVSS 5.5
EPSS 0.01
CVE-2020-24331 HIGH
TrouSerS < 0.3.14 - Improper Privilege Management in tcsd.conf
Aug 13, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-24330 HIGH
TrouSerS <0.3.14 - Privilege Escalation
Aug 13, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-17498 MEDIUM
Wireshark 3.2.0-3.2.5 - Use After Free
Aug 13, 2020
CVSS 6.5
EPSS 0.03
CVE-2020-17507 MEDIUM
Qt < 5.12.9 and 5.13.x-5.15.x < 5.15.1 - Out-of-bounds Read in XBM Image Handler
Aug 12, 2020
CVSS 5.3
EPSS 0.04