fedoraproject
5,423 tracked vulnerabilities.
CVE-2018-11797
MEDIUM
Apache PDFBox 1.8.0-1.8.15 and 2.0.0RC1-2.0.11 - Denial of Service via Page Tree Parsing
Oct 05, 2018
CVSS 5.5
EPSS 0.04
CVE-2018-17848
HIGH
golang/net < 2018-09-25 - Denial of Service via Malformed HTML Parsing
Oct 01, 2018
CVSS 7.5
EPSS 0.03
CVE-2018-17847
HIGH
Go html package <2018-09-25 - Info Disclosure
Oct 01, 2018
CVSS 7.5
EPSS 0.03
CVE-2018-17846
HIGH
golang/net < 2018-09-25 - Infinite Loop via Malformed HTML Table Parsing
Oct 01, 2018
CVSS 7.5
EPSS 0.03
CVE-2018-17825
CRITICAL
AdPlug 2.3.1 - Double Free in CEmuopl Class Destructor
Oct 01, 2018
CVSS 9.8
EPSS 0.02
CVE-2018-14648
HIGH
389 Directory Server < 1.4.0.17 - Unauthenticated Denial of Service via Crafted Search Query
Sep 28, 2018
CVSS 7.5
EPSS 0.06
CVE-2018-14647
HIGH
Python 2.7.0-2.7.15, 3.4.0-3.4.9, 3.5.0-3.5.6, 3.6.0-3.6.6, 3.7.0 - Denial of Service via Expat Hash Collisions
Sep 25, 2018
CVSS 7.5
EPSS 0.11
CVE-2018-17143
HIGH
golang/net < 2018-09-17 - Denial of Service via Malformed HTML Template Parsing
Sep 17, 2018
CVSS 7.5
EPSS 0.03
CVE-2018-17142
HIGH
golang/net < 2018-09-17 - Use-After-Free in HTML Parser
Sep 17, 2018
CVSS 7.5
EPSS 0.03
CVE-2018-17075
HIGH
Go html package <2018-07-13 - Panic
Sep 16, 2018
CVSS 7.5
EPSS 0.03
CVE-2018-14638
HIGH
389 Directory Server < 1.3.8.4 - Denial of Service via Persistent Search Connection Termination
Sep 14, 2018
CVSS 7.5
EPSS 0.03
CVE-2018-14624
HIGH
389-ds-base <1.3.7.10-1.4.0.16 - DoS
Sep 06, 2018
CVSS 7.5
EPSS 0.02
CVE-2018-14599
CRITICAL
libX11 < 1.6.5 - Off-by-one Error in XListExtensions
Aug 24, 2018
CVSS 9.8
EPSS 0.05
CVE-2018-14598
HIGH
libX11 < 1.6.5 - Denial of Service via XListExtensions Overflow
Aug 24, 2018
CVSS 7.5
EPSS 0.04
CVE-2018-10846
MEDIUM
GnuTLS < 3.6.12 - Plain Text Recovery via Cache-Based Side Channel
Aug 22, 2018
CVSS 5.6
EPSS 0.00
CVE-2018-10845
MEDIUM
GnuTLS < 3.6.12 - Timing Side-Channel Attack via HMAC-SHA-384
Aug 22, 2018
CVSS 5.9
EPSS 0.04
CVE-2018-10844
MEDIUM
GnuTLS < 3.6.12 - Timing Side-Channel Attack via HMAC-SHA-256
Aug 22, 2018
CVSS 5.9
EPSS 0.04
CVE-2018-14348
HIGH
libcgroup <= 0.41 - Exposure of Sensitive Information via Log File Permissions
Aug 14, 2018
CVSS 8.1
EPSS 0.02
CVE-2018-10871
LOW
389 Directory Server < 1.3.8.5 - Cleartext Storage of Sensitive Information in Replica and RetroChangeLog Plugins
Jul 18, 2018
CVSS 3.8
EPSS 0.01
CVE-2018-13405
HIGH
Linux Kernel < 3.16 - Privilege Escalation via SGID Directory Inode Initialization
Jul 06, 2018
CVSS 7.8
EPSS 0.01
CVE-2018-10852
LOW
Debian Linux < 1.16.3 - Information Disclosure
Jun 26, 2018
CVSS 3.8
EPSS 0.02
CVE-2018-10811
HIGH
strongSwan < 5.6.3 - Denial of Service via Missing Variable Initialization
Jun 19, 2018
CVSS 7.5
EPSS 0.07
CVE-2018-1061
MEDIUM
Python < 2.7.15 - Denial of Service via Catastrophic Backtracking in difflib.IS_LINE_JUNK
Jun 19, 2018
CVSS 6.5
EPSS 0.05
CVE-2018-1090
MEDIUM
Pulp < 2.16.2 - Unauthorized Exposure of Sensitive Information via Task Override Config
Jun 18, 2018
CVSS 5.5
EPSS 0.01
CVE-2018-1060
HIGH
Python < 2.7.15 - Denial of Service via Catastrophic Backtracking in pop3lib apop()
Jun 18, 2018
CVSS 7.5
EPSS 0.05
Products
fedora 5,353
extra_packages_for_enterprise_linux 76
389_directory_server 39
sssd 19
fedora_core 8
389_administration_server 1
anaconda 1
arm_installer 1
commons 1
coolkey 1
crypto-utils 1
fedmsg 1
fedora_linux_kernel 1
python-fedora 1
sectool 1
selinux-policy 1
spin-kickstarts 1
supybot-fedora 1
unbound 1
Quick Filters