fedoraproject
5,423 tracked vulnerabilities.
CVE-2017-9106
HIGH
adns < 1.5.2 - Buffer Overflow via Integer Conversion in adns_rr_info
Jun 18, 2020
CVSS 7.5
EPSS 0.02
CVE-2017-9105
HIGH
adns <1.5.2 - Remote Code Execution
Jun 18, 2020
CVSS 8.8
EPSS 0.04
CVE-2017-18640
HIGH
SnakeYAML < 1.26 - XML Entity Expansion via Alias Feature
Dec 12, 2019
CVSS 7.5
EPSS 0.27
CVE-2017-12173
MEDIUM
Red Hat Enterprise Linux - Information Disclosure via SSSD Local Cache Injection
Jul 27, 2018
CVSS 4.3
EPSS 0.01
CVE-2017-18342
CRITICAL
PyYAML < 5.1 - Remote Code Execution via yaml.load()
Jun 27, 2018
CVSS 9.8
EPSS 0.06
CVE-2017-2668
MEDIUM
389 Directory Server < 1.3.5.17 - Unauthenticated Denial of Service via LDAP Bind Request
Jun 22, 2018
CVSS 6.5
EPSS 0.03
CVE-2017-2591
LOW
389 Directory Server < 1.3.6 - Out-of-bounds Read in Attribute Uniqueness Plugin
Apr 30, 2018
CVSS 3.7
EPSS 0.03
CVE-2017-6888
MEDIUM
FLAC < 1.3.2 - Memory Leak in read_metadata_vorbiscomment_()
Apr 25, 2018
CVSS 5.5
EPSS 0.01
CVE-2017-15134
HIGH
389 Directory Server 1.3.6.1-1.3.6.12, 1.3.7.1-1.3.7.8, 1.4.0-1.4.0.4 - DoS via LDAP Search Filter
Mar 01, 2018
CVSS 7.5
EPSS 0.04
CVE-2017-9271
LOW
zypper - Sensitive Information Exposure via HTTP Proxy Credential Logging
Mar 01, 2018
CVSS 3.3
EPSS 0.00
CVE-2017-15365
HIGH
MariaDB <10.1.30, Percona XtraDB Cluster <5.6.37-26.21-3, <5.7.19-2...
Jan 25, 2018
CVSS 8.8
EPSS 0.03
CVE-2017-15135
HIGH
389 Directory Server 1.3.6.1-1.4.0.3 - Unauthenticated Authentication Bypass via Internal Hash Comparison
Jan 24, 2018
CVSS 8.1
EPSS 0.04
CVE-2017-15129
MEDIUM
Linux Kernel < 4.14.11 - Use-After-Free in Network Namespace Handling
Jan 09, 2018
CVSS 4.7
EPSS 0.00
CVE-2017-16876
MEDIUM
mistune < 0.8.1 - Cross-Site Scripting via _keyify Function
Dec 29, 2017
CVSS 6.1
EPSS 0.02
CVE-2017-16818
MEDIUM
Ceph 12.1.0-12.2.1 - Authenticated Denial of Service via Invalid Profile Post to Admin API
Dec 20, 2017
CVSS 6.5
EPSS 0.02
CVE-2017-13704
HIGH
Canonical Ubuntu Linux < 2.77 - Improper Input Validation
Oct 03, 2017
CVSS 7.5
EPSS 0.65
CVE-2017-12170
CRITICAL
pure-ftpd 1.0.46-1 - Info Disclosure
Sep 21, 2017
CVSS 9.8
EPSS 0.02
CVE-2017-1002150
MEDIUM
python-fedora <0.8.0 - Open Redirect
Sep 14, 2017
CVSS 6.1
EPSS 0.01
CVE-2017-11462
CRITICAL
MIT Kerberos 5 - Double Free via Security Context Deletion on Error
Sep 13, 2017
CVSS 9.8
EPSS 0.05
CVE-2017-6362
HIGH
libgd < 2.2.5 - Double Free in gdImagePngPtr
Sep 07, 2017
CVSS 7.5
EPSS 0.05
CVE-2017-13752
HIGH
JasPer 2.0.12 - Denial of Service via Reachable Assertion in jpc_dequantize
Aug 29, 2017
CVSS 7.5
EPSS 0.04
CVE-2017-13751
HIGH
JasPer 2.0.12 - Denial of Service via Reachable Assertion in calcstepsizes()
Aug 29, 2017
CVSS 7.5
EPSS 0.04
CVE-2017-13750
HIGH
JasPer 2.0.12 - Reachable Assertion Denial of Service in jpc_dec_process_siz
Aug 29, 2017
CVSS 7.5
EPSS 0.04
CVE-2017-13749
HIGH
JasPer 2.0.12 - Reachable Assertion Denial of Service in jpc_pi_nextrpcl
Aug 29, 2017
CVSS 7.5
EPSS 0.04
CVE-2017-13748
HIGH
JasPer 2.0.12 - Denial of Service via Memory Leak in jas_strdup
Aug 29, 2017
CVSS 7.5
EPSS 0.05
Products
fedora 5,353
extra_packages_for_enterprise_linux 76
389_directory_server 39
sssd 19
fedora_core 8
389_administration_server 1
anaconda 1
arm_installer 1
commons 1
coolkey 1
crypto-utils 1
fedmsg 1
fedora_linux_kernel 1
python-fedora 1
sectool 1
selinux-policy 1
spin-kickstarts 1
supybot-fedora 1
unbound 1
Quick Filters