fedoraproject

5,423 tracked vulnerabilities.

CVE-2010-0629 MEDIUM
MIT Kerberos 5 1.5-1.6.3 - Authenticated Denial of Service via Invalid API Version Number
Apr 07, 2010
CVSS 6.5
EPSS 0.05
CVE-2010-0751
libnids < 1.24 - Denial of Service via Crafted Fragmented Packets
Apr 06, 2010
EPSS 0.04
CVE-2010-0050 HIGH
Apple Safari < 4.0.5 - Use-After-Free via Improperly Nested HTML Tags
Mar 15, 2010
CVSS 8.8
EPSS 0.12
CVE-2010-0434
Apache HTTP Server 2.2.x < 2.2.15 - Exposure of Sensitive Information via Subrequest Header Handling
Mar 05, 2010
EPSS 0.18
CVE-2010-0302 HIGH
CUPS < 1.4.4 - Use-After-Free in File Descriptor Handling
Mar 05, 2010
CVSS 7.5
EPSS 0.03
CVE-2010-0205
libpng 1.0.0-1.0.52, 1.2.0-1.2.42, 1.4.0 - Denial of Service via Decompression Bomb
Mar 03, 2010
EPSS 0.04
CVE-2010-0014
SSSD < 1.0.1 - Improper Authentication via Kerberos TGT Handling
Jan 14, 2010
EPSS 0.01
CVE-2010-0013 HIGH
Adium and Pidgin - Path Traversal via MSN Emoticon Request
Jan 09, 2010
CVSS 7.5
EPSS 0.12
CVE-2009-4135
GNU coreutils <8.1 - Privilege Escalation
Dec 11, 2009
EPSS 0.00
CVE-2009-3553 HIGH
CUPS 1.3.7 and 1.3.10 - Use-After-Free in File-Descriptor Handling
Nov 20, 2009
CVSS 7.5
EPSS 0.04
CVE-2009-2816
Safari < 4.0.4 - Cross-Site Request Forgery via CORS OPTIONS Request
Nov 13, 2009
EPSS 0.02
CVE-2009-3555 CRITICAL
Apache HTTP Server < 2.2.14 - Plaintext Injection via TLS Renegotiation
Nov 09, 2009
CVSS 9.8
EPSS 0.87
CVE-2009-3547 HIGH
Linux Kernel < 2.6.32-rc6 - Race Condition in Pipe Handling via /proc/*/fd/ Pathname
Nov 04, 2009
CVSS 7.0
EPSS 0.05
CVE-2009-3611 HIGH
Le-web Backintime - Incorrect Permission Assignment
Oct 26, 2009
CVSS 7.1
EPSS 0.00
CVE-2009-3767
OpenLDAP < 2.4.18 - Improper Certificate Validation via Null Byte in CN Field
Oct 23, 2009
EPSS 0.03
CVE-2009-3621 MEDIUM
Linux Kernel < 2.6.31.4 - Denial of Service via Abstract-Namespace AF_UNIX Socket
Oct 22, 2009
CVSS 5.5
EPSS 0.01
CVE-2009-3620 HIGH
Linux Kernel < 2.6.31-git11 - Denial of Service via ATI Rage 128 Driver ioctl Calls
Oct 22, 2009
CVSS 7.8
EPSS 0.00
CVE-2009-2910
Linux Kernel < 2.6.31.4 - Unauthorized Register Value Exposure via x86_64 ia32 Mode Switch
Oct 20, 2009
EPSS 0.00
CVE-2009-3612
Linux Kernel < 2.4.37.6 and 2.6.x < 2.6.32-rc5 - Information Disclosure via Uninitialized tcm__pad2 Structure
Oct 19, 2009
EPSS 0.00
CVE-2009-3231
PostgreSQL 8.2-8.2.14 and 8.3-8.3.8 - Unauthenticated Authentication Bypass via Empty LDAP Password
Sep 17, 2009
EPSS 0.08
CVE-2009-2629
nginx <0.5.37, <0.6.39, <0.7.62, <0.8.15 - RCE
Sep 15, 2009
EPSS 0.75
CVE-2009-2813
Samba 3.0.12-3.0.36, 3.2-3.2.14, 3.3-3.3.7, 3.4-3.4.1 - Authenticated Path Traversal
Sep 14, 2009
EPSS 0.03
CVE-2009-3095
Apache HTTP Server 2.0.35-2.0.63 - Remote Command Injection via mod_proxy_ftp Authorization Header
Sep 08, 2009
EPSS 0.13
CVE-2009-3094
Apache HTTP Server 2.0.35-2.0.63 - Denial of Service via Malformed EPSV Reply
Sep 08, 2009
EPSS 0.09
CVE-2009-2698 HIGH
Linux Kernel <2.6.19 - Privilege Escalation
Aug 27, 2009
CVSS 7.8
EPSS 0.07