fedoraproject
5,423 tracked vulnerabilities.
CVE-2020-12108
MEDIUM
GNU Mailman < 2.1.31 - Arbitrary Content Injection via /options/mailman
May 06, 2020
CVSS 6.5
EPSS 0.03
CVE-2020-10704
HIGH
Samba < 4.10.15 - Denial of Service via LDAP Request Handling
May 06, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-12666
MEDIUM
macaron < 1.3.7 - Open Redirect via Static Handler
May 05, 2020
CVSS 6.1
EPSS 0.01
CVE-2020-11035
HIGH
GLPI 0.83.3-9.4.6 - Use of a Broken or Risky Cryptographic Algorithm in CSRF Token Generation
May 05, 2020
CVSS 7.5
EPSS 0.01
CVE-2020-11033
MEDIUM
GLPI 9.1-9.4.5 - Authenticated Exposure of Sensitive Information via API User Endpoint
May 05, 2020
CVSS 6.6
EPSS 0.01
CVE-2020-10700
MEDIUM
Samba <4.10.15-4.12.2 - Use After Free
May 04, 2020
CVSS 5.3
EPSS 0.02
CVE-2020-10933
MEDIUM
Ruby <2.5.8, <2.6.6, <2.7.1 - Info Disclosure
May 04, 2020
CVSS 5.3
EPSS 0.03
CVE-2020-12050
HIGH
Opensuse Backports Sle - Race Condition
Apr 30, 2020
CVSS 7.0
EPSS 0.00
CVE-2020-11022
MEDIUM
jQuery 1.12.0-3.4.1 - Cross-Site Scripting via DOM Manipulation Methods
Apr 29, 2020
CVSS 6.9
EPSS 0.99
CVE-2020-11023
MEDIUM
KEV
jQuery <3.5.0 - XSS
Apr 29, 2020
CVSS 6.9
EPSS 0.84
CVE-2020-12459
MEDIUM
Grafana 6.x-6.3.6 - Info Disclosure
Apr 29, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-12458
MEDIUM
Grafana < 6.7.3 - Unprotected Database Directory Information Disclosure
Apr 29, 2020
CVSS 5.5
EPSS 0.00
CVE-2020-11884
HIGH
Linux Kernel 4.19-5.6.7 on s390 - Race Condition in Page Table Handling
Apr 29, 2020
CVSS 7.0
EPSS 0.00
CVE-2020-10663
HIGH
JSON gem < 2.2.0 - Unsafe Object Creation via JSON Parsing
Apr 28, 2020
CVSS 7.5
EPSS 0.07
CVE-2020-11810
LOW
OpenVPN 2.4.0-2.4.8 - Denial of Service via Early P_DATA_V2 Packet Injection
Apr 27, 2020
CVSS 3.7
EPSS 0.02
CVE-2020-12272
MEDIUM
OpenDMARC < 1.3.2 - Authentication Bypass by Spoofing via SPF/DKIM Parsing
Apr 27, 2020
CVSS 5.3
EPSS 0.02
CVE-2020-12137
MEDIUM
GNU Mailman 2.0-2.1.29 - Cross-Site Scripting via Scrubbed MIME Part
Apr 24, 2020
CVSS 6.1
EPSS 0.02
CVE-2020-1760
MEDIUM
Ceph < 14.2.21 - Cross-Site Scripting via Anonymous S3 Request Handling
Apr 23, 2020
CVSS 5.8
EPSS 0.02
CVE-2020-11945
CRITICAL
Squid 3.0-3.5.27 - Integer Overflow in Digest Authentication Nonce Counter
Apr 23, 2020
CVSS 9.8
EPSS 0.27
CVE-2020-1983
HIGH
libslirp < 4.2.0 - Use-After-Free in ip_reass()
Apr 22, 2020
CVSS 7.5
EPSS 0.02
CVE-2020-12066
HIGH
Teeworlds 0.7.0-0.7.4 - Denial of Service via CServer::SendMsg
Apr 22, 2020
CVSS 7.5
EPSS 0.03
CVE-2020-11008
MEDIUM
Git < 2.17.5 - Credential Leak via Malicious URL Pattern
Apr 21, 2020
CVSS 4.0
EPSS 0.04
CVE-2020-1967
HIGH
OpenSSL 1.1.1d-1.1.1f - Denial of Service via Invalid Signature Algorithm in TLS 1.3 Handshake
Apr 21, 2020
CVSS 7.5
EPSS 0.53
CVE-2020-0081
HIGH
Android -8.0-10 - Memory Corruption
Apr 17, 2020
CVSS 7.8
EPSS 0.00
CVE-2020-11793
HIGH
WebKitGTK and WPE WebKit < 2.28.1 - Use-After-Free via Crafted Web Content
Apr 17, 2020
CVSS 8.8
EPSS 0.03
Products
fedora 5,353
extra_packages_for_enterprise_linux 76
389_directory_server 39
sssd 19
fedora_core 8
389_administration_server 1
anaconda 1
arm_installer 1
commons 1
coolkey 1
crypto-utils 1
fedmsg 1
fedora_linux_kernel 1
python-fedora 1
sectool 1
selinux-policy 1
spin-kickstarts 1
supybot-fedora 1
unbound 1
Quick Filters