fedoraproject

5,423 tracked vulnerabilities.

CVE-2019-16789 HIGH
Waitress <1.4.0 - HTTP Request Smuggling
Dec 26, 2019
CVSS 7.1
EPSS 0.03
CVE-2019-19956 HIGH
libxml2 < 2.9.10 - Memory Leak in xmlParseBalancedChunkMemoryRecover
Dec 24, 2019
CVSS 7.5
EPSS 0.06
CVE-2019-11050 MEDIUM
PHP 7.2.0-7.2.25, 7.3.0-7.3.12, 7.4.0 - Out-of-bounds Read in EXIF Extension
Dec 23, 2019
CVSS 4.8
EPSS 0.08
CVE-2019-11049 MEDIUM
PHP 7.3.0-7.3.12 - Use-After-Free via mail() Function Lowercase Header
Dec 23, 2019
CVSS 6.5
EPSS 0.04
CVE-2019-11047 MEDIUM
PHP 7.2.0-7.2.25, 7.3.0-7.3.12, 7.4.0 - Out-of-bounds Read in EXIF Extension
Dec 23, 2019
CVSS 4.8
EPSS 0.07
CVE-2019-11046 LOW
PHP 7.2.0-7.2.25, 7.3.0-7.3.12, 7.4.0 - Out-of-bounds Read in bcmath Extension
Dec 23, 2019
CVSS 3.7
EPSS 0.04
CVE-2019-11045 LOW
PHP 7.2.0-7.2.25, 7.3.0-7.3.12, 7.4.0 - Improper Null Termination in DirectoryIterator
Dec 23, 2019
CVSS 3.7
EPSS 0.09
CVE-2019-11044 LOW
PHP <7.2.26-7.3.13-7.4.0 (Windows) - Path Traversal
Dec 23, 2019
CVSS 3.7
EPSS 0.05
CVE-2019-16786 HIGH
Waitress < 1.4.0 - HTTP Request Smuggling via Transfer-Encoding Header Mishandling
Dec 20, 2019
CVSS 7.1
EPSS 0.03
CVE-2019-16785 HIGH
Waitress < 1.4.0 - HTTP Request Smuggling via Inconsistent CRLF Parsing
Dec 20, 2019
CVSS 7.1
EPSS 0.03
CVE-2019-19918 HIGH
Lout 3.40 - Heap-Based Buffer Overflow in srcnext Function
Dec 20, 2019
CVSS 7.8
EPSS 0.02
CVE-2019-19917 HIGH
Lout 3.40 - Buffer Overflow in StringQuotedWord Function
Dec 20, 2019
CVSS 7.8
EPSS 0.02
CVE-2019-19906 HIGH
cyrus-sasl < 2.1.28 - Unauthenticated Denial of Service via Malformed LDAP Packet
Dec 19, 2019
CVSS 7.5
EPSS 0.08
CVE-2019-16782 MEDIUM
Rack <1.6.12, 2.0.8 - Info Disclosure
Dec 18, 2019
CVSS 6.3
EPSS 0.04
CVE-2019-3996 MEDIUM
elog < 3.1.4-57bea22 - Unauthenticated HTTP Request Smuggling via Crafted POST Requests
Dec 17, 2019
CVSS 6.5
EPSS 0.06
CVE-2019-3995 HIGH
elog < 3.1.4-57bea22 - Unauthenticated Denial of Service via NULL Pointer Dereference
Dec 17, 2019
CVSS 7.5
EPSS 0.29
CVE-2019-3994 HIGH
elog < 3.1.4-57bea22 - Unauthenticated Denial of Service via HTTP POST Request Handling
Dec 17, 2019
CVSS 7.5
EPSS 0.03
CVE-2019-3993 HIGH
elog < 3.1.4-57bea22 - Unauthenticated Cleartext Transmission of Sensitive Information via HTTP POST Request
Dec 17, 2019
CVSS 7.5
EPSS 0.46
CVE-2019-3992 HIGH
ELOG < 3.1.4-57bea22 - Unauthenticated Information Disclosure via Configuration File Access
Dec 17, 2019
CVSS 7.5
EPSS 0.01
CVE-2019-19783 MEDIUM
Cyrus IMAP < 2.5.15, 3.0.x < 3.0.13, 3.1.x <= 3.1.8 - Privilege Escalation via Sieve Script Fileinto Directive
Dec 16, 2019
CVSS 6.5
EPSS 0.02
CVE-2019-19797 MEDIUM
fig2dev 3.2.7b - Out-of-bounds Write in read_colordef
Dec 15, 2019
CVSS 5.5
EPSS 0.01
CVE-2019-19722 MEDIUM
Dovecot < 2.3.9.2 - Denial of Service via NULL Pointer Dereference in Push Notification Driver
Dec 13, 2019
CVSS 5.3
EPSS 0.02
CVE-2019-19787 HIGH
ATasm 1.06 - Stack-based Buffer Overflow in get_signed_expression()
Dec 13, 2019
CVSS 7.8
EPSS 0.01
CVE-2019-19786 HIGH
ATasm 1.06 - Stack-based Buffer Overflow in parse_expr() Function
Dec 13, 2019
CVSS 7.8
EPSS 0.01
CVE-2019-19785 HIGH
ATasm 1.06 - Stack-based Buffer Overflow in to_comma() Function
Dec 13, 2019
CVSS 7.8
EPSS 0.01