fedoraproject
5,423 tracked vulnerabilities.
CVE-2020-13962
HIGH
Mumble 1.3.0 - Denial of Service via OpenSSL Error Queue Mishandling
Jun 09, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-10754
MEDIUM
NetworkManager < 1.22.14 - Improper Authentication via nmcli Profile Creation
Jun 08, 2020
CVSS 4.3
EPSS 0.01
CVE-2020-13696
MEDIUM
xawtv < 3.107 - Unauthenticated Arbitrary File Access via v4l-conf Device Path Manipulation
Jun 08, 2020
CVSS 4.4
EPSS 0.00
CVE-2020-13625
HIGH
PHPMailer < 6.1.6 - Improper Output Escaping in File Attachment Name
Jun 08, 2020
CVSS 7.5
EPSS 0.04
CVE-2020-12695
HIGH
Open Connectivity Foundation UPnP <2020-04-17 - SSRF
Jun 08, 2020
CVSS 7.5
EPSS 0.15
CVE-2020-12803
MEDIUM
LibreOffice < 6.4.4 - Unauthenticated Arbitrary File Write via Form Submission to file: URI
Jun 08, 2020
CVSS 6.5
EPSS 0.02
CVE-2020-12802
MEDIUM
LibreOffice <6.4.4 - Info Disclosure
Jun 08, 2020
CVSS 5.3
EPSS 0.02
CVE-2020-13871
HIGH
SQLite 3.32.2 - Use-After-Free in Window Function Parse Tree Rewrite
Jun 06, 2020
CVSS 7.5
EPSS 0.04
CVE-2020-13867
MEDIUM
targetcli-fb < 2.1.52 - Incorrect Default Permissions for /etc/target
Jun 05, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-8555
MEDIUM
Kubernetes <1.15.12, <1.16.9, <1.17.5, <1.18.0 - SSRF
Jun 05, 2020
CVSS 6.3
EPSS 0.04
CVE-2020-12723
HIGH
Perl < 5.30.3 - Buffer Overflow via Recursive S_study_chunk Calls
Jun 05, 2020
CVSS 7.5
EPSS 0.06
CVE-2020-10878
HIGH
Perl < 5.30.3 - Integer Overflow via Regular Expression Compilation
Jun 05, 2020
CVSS 8.6
EPSS 0.05
CVE-2020-10543
HIGH
Perl < 5.30.3 - Heap-Based Buffer Overflow via Nested Regular Expression Quantifiers
Jun 05, 2020
CVSS 8.2
EPSS 0.11
CVE-2020-13692
HIGH
PostgreSQL JDBC Driver < 42.2.13 - XML External Entity Injection
Jun 04, 2020
CVSS 7.7
EPSS 0.04
CVE-2020-13777
HIGH
GnuTLS 3.6.4-3.6.13 - Use of a Broken or Risky Cryptographic Algorithm in Session Ticket Encryption
Jun 04, 2020
CVSS 7.4
EPSS 0.18
CVE-2020-11080
LOW
nghttp2 < 1.41.0 - Denial of Service via Large HTTP/2 SETTINGS Frame Payload
Jun 03, 2020
CVSS 3.7
EPSS 0.05
CVE-2020-13379
HIGH
NUCLEI
Grafana 3.0.1-7.0.1 - Unauthenticated Server-Side Request Forgery via Avatar Feature
Jun 03, 2020
CVSS 8.2
EPSS 1.00
CVE-2020-13596
MEDIUM
Django 2.2-2.2.13 - Cross-Site Scripting via ForeignKeyRawIdWidget Query Parameters
Jun 03, 2020
CVSS 6.1
EPSS 0.03
CVE-2020-13254
MEDIUM
Django <2.2.13, <3.0.7 - Info Disclosure
Jun 03, 2020
CVSS 5.9
EPSS 0.06
CVE-2020-10749
MEDIUM
containernetworking/plugins <0.8.6 - Privilege Escalation
Jun 03, 2020
CVSS 6.0
EPSS 0.02
CVE-2020-13776
MEDIUM
systemd < 245 - Improper Privilege Management via Numerical Username Handling
Jun 03, 2020
CVSS 6.7
EPSS 0.00
CVE-2020-13775
MEDIUM
ZNC 1.8.0-1.8.1-rc1 - Authenticated Denial of Service via NULL Pointer Dereference
Jun 02, 2020
CVSS 6.5
EPSS 0.02
CVE-2020-13401
MEDIUM
Docker Engine < 19.03.11 - IPv6 Router Advertisement Spoofing via CAP_NET_RAW
Jun 02, 2020
CVSS 6.0
EPSS 0.03
CVE-2020-13757
HIGH
Python-RSA < 4.1 - Use of a Broken or Risky Cryptographic Algorithm
Jun 01, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-12867
MEDIUM
sane_backends < 1.0.30 - Denial of Service via NULL Pointer Dereference in sanei_epson_net_read
Jun 01, 2020
CVSS 5.5
EPSS 0.00
Products
fedora 5,353
extra_packages_for_enterprise_linux 76
389_directory_server 39
sssd 19
fedora_core 8
389_administration_server 1
anaconda 1
arm_installer 1
commons 1
coolkey 1
crypto-utils 1
fedmsg 1
fedora_linux_kernel 1
python-fedora 1
sectool 1
selinux-policy 1
spin-kickstarts 1
supybot-fedora 1
unbound 1
Quick Filters