fedoraproject
5,423 tracked vulnerabilities.
CVE-2020-15811
MEDIUM
Squid <4.13-5.0.4 - HTTP Request Splitting
Sep 02, 2020
CVSS 6.5
EPSS 0.04
CVE-2020-15810
MEDIUM
Squid < 4.13 and 5.x < 5.0.4 - HTTP Request Smuggling via Relaxed Header Parsing
Sep 02, 2020
CVSS 6.5
EPSS 0.03
CVE-2020-16150
MEDIUM
Mbed TLS < 2.7.17 - Timing Side-Channel Attack via CBC Mode Padding
Sep 02, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-24584
HIGH
Django <2.2.16, <3.0.10, <3.1.1 - Info Disclosure
Sep 01, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-24583
HIGH
Django <2.2.16, 3.0<10, 3.1<1 - Info Disclosure
Sep 01, 2020
CVSS 7.5
EPSS 0.04
CVE-2020-14364
MEDIUM
QEMU < 5.2.0 - Out-of-bounds Read/Write in USB Emulator
Aug 31, 2020
CVSS 5.0
EPSS 0.05
CVE-2020-14352
HIGH
librepo < 1.12.1 - Path Traversal via Remote Repository Metadata
Aug 30, 2020
CVSS 8.0
EPSS 0.03
CVE-2020-24972
HIGH
Kleopatra <3.1.12 - Code Execution via openpgp4fpr URL Handling
Aug 29, 2020
CVSS 8.8
EPSS 0.05
CVE-2020-24661
MEDIUM
GNOME Geary <3.36.3 - Info Disclosure
Aug 26, 2020
CVSS 5.9
EPSS 0.01
CVE-2020-24614
HIGH
Fossil <2.10.2, <2.11.2, <2.12.1 - Authenticated RCE
Aug 25, 2020
CVSS 8.8
EPSS 0.03
CVE-2020-24612
MEDIUM
selinux-policy <2020-08-24 - Privilege Escalation
Aug 24, 2020
CVSS 6.7
EPSS 0.00
CVE-2020-24606
HIGH
Squid 3.0-4.12 and 5.x < 5.0.4 - Denial of Service via Crafted Cache Digest Response
Aug 24, 2020
CVSS 8.6
EPSS 0.05
CVE-2020-14367
MEDIUM
chrony < 3.5.1 - Denial of Service via PID File Symlink Attack
Aug 24, 2020
CVSS 6.0
EPSS 0.00
CVE-2020-8624
MEDIUM
BIND <9.16.5 - Privilege Escalation
Aug 21, 2020
CVSS 4.3
EPSS 0.04
CVE-2020-8623
HIGH
BIND 9.10.0-9.11.21, 9.12.0-9.16.5, 9.17.0-9.17.3 - Reachable Assertion via Crafted Query Packet
Aug 21, 2020
CVSS 7.5
EPSS 0.06
CVE-2020-8622
MEDIUM
BIND 9.0.0-9.11.21, 9.12.0-9.16.5, 9.17.0-9.17.3 - Reachable Assertion via Truncated TSIG Response
Aug 21, 2020
CVSS 6.5
EPSS 0.06
CVE-2020-1597
HIGH
ASP.NET Core - Unauthenticated Denial of Service via Specially Crafted Requests
Aug 17, 2020
CVSS 7.5
EPSS 0.07
CVE-2020-1472
MEDIUM
KEV
Netlogon Weak Cryptographic Authentication
Aug 17, 2020
CVSS 5.5
EPSS 1.00
CVE-2020-24370
MEDIUM
Lua 5.4.0 - Integer Underflow via getlocal/setlocal Debug Interface
Aug 17, 2020
CVSS 5.3
EPSS 0.04
CVE-2020-24342
HIGH
Lua <= 5.4.0 - Stack-Based Buffer Overflow via luaO_pushvfstring
Aug 13, 2020
CVSS 7.8
EPSS 0.01
CVE-2020-24332
MEDIUM
TrouSerS <0.3.14 - Privilege Escalation
Aug 13, 2020
CVSS 5.5
EPSS 0.01
CVE-2020-24331
HIGH
TrouSerS < 0.3.14 - Improper Privilege Management in tcsd.conf
Aug 13, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-24330
HIGH
TrouSerS <0.3.14 - Privilege Escalation
Aug 13, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-17498
MEDIUM
Wireshark 3.2.0-3.2.5 - Use After Free
Aug 13, 2020
CVSS 6.5
EPSS 0.03
CVE-2020-17507
MEDIUM
Qt < 5.12.9 and 5.13.x-5.15.x < 5.15.1 - Out-of-bounds Read in XBM Image Handler
Aug 12, 2020
CVSS 5.3
EPSS 0.04
Products
fedora 5,353
extra_packages_for_enterprise_linux 76
389_directory_server 39
sssd 19
fedora_core 8
389_administration_server 1
anaconda 1
arm_installer 1
commons 1
coolkey 1
crypto-utils 1
fedmsg 1
fedora_linux_kernel 1
python-fedora 1
sectool 1
selinux-policy 1
spin-kickstarts 1
supybot-fedora 1
unbound 1
Quick Filters