Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fedora HIGH 7.5
CVE-2014-8119

The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augea…

Fix: after 0.2.6
Fix from $1,950 2017-12-29
Fedora HIGH 7.5
CVE-2015-8008

The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intende…

Fix: 1.25.3+
Fix from $1,950 2017-12-29
Fedora MEDIUM 5.5
CVE-2014-4978

The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1)…

Patch available
Fix from $1,600 2017-12-29
Fedora MEDIUM 6.1
CVE-2017-16876

Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary we…

Fix: 0.8.1+
Fix from $1,600 2017-12-29
Fedora CRITICAL 9.8
CVE-2015-7687

Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vec…

Fix: after 5.7.1
Fix from $2,300 2017-10-16
Spin Kickstarts MEDIUM 5.9
CVE-2015-3229

fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora A…

Patch available
Fix from $1,600 2017-10-16
Fedora MEDIUM 6.5
CVE-2014-9092

libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.

Fix: after 1.2.90
Fix from $1,600 2017-10-10
Fedora HIGH 7.8
CVE-2015-5704

scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.

Fix: after 2.15.6
Fix from $1,950 2017-09-25
Fedora CRITICAL 9.8
CVE-2017-12170

Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored a…

Mitigation only
Fix from $2,300 2017-09-21
Fedora HIGH 8.8
CVE-2015-5607

Cross-site request forgery in the REST API in IPython 2 and 3.

Patch available
Fix from $1,950 2017-09-20
Fedora HIGH 7.5
CVE-2015-1854

389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn ca…

Fix: after 1.3.3.9
Fix from $1,950 2017-09-19
Fedora MEDIUM 5.9
CVE-2015-3420

The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process…

Fix: after 2.2.16
Fix from $1,600 2017-09-19
Python Fedora MEDIUM 6.1
CVE-2017-1002150

python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection

Fix: after 0.8.0
Fix from $1,600 2017-09-14
Fedora CRITICAL 9.8
CVE-2017-11462EPSS 5%

Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of securi…

Patch available
Fix from $2,300 2017-09-13
Fedora HIGH 7.5
CVE-2015-5705

Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted fi…

Fix: after 2.15.6
Fix from $1,950 2017-09-06
Fedora HIGH 7.5
CVE-2017-13749

There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of servi…

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13750

There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial o…

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13751

There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service a…

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13752

There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service …

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13746

There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial o…

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13747

There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service …

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2017-13748

There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of se…

No fix yet
Fix from $1,950 2017-08-29
Fedora HIGH 7.5
CVE-2015-1395EPSS 11%

Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary f…

Fix: after 2.7.2
Fix from $1,950 2017-08-25
Fedora MEDIUM 5.5
CVE-2014-9637

GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file.

Fix: after 2.7.2
Fix from $1,600 2017-08-25
Fedora MEDIUM 5.3
CVE-2015-5146

ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and acces…

Fix: after 4.2.8
Fix from $1,600 2017-08-24
Fedora HIGH 8.8
CVE-2017-11610EPSS 87%

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to ex…

Fix: after 3.0
Fix from $1,950 2017-08-23
Fedora HIGH 8.8
CVE-2015-5258

Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3.

Fix: 1.1.3+
Fix from $1,950 2017-08-22
Fedora MEDIUM 6.5
CVE-2017-12843

Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE com…

Fix: after 3.0.2
Fix from $1,600 2017-08-22
389 Directory Server CRITICAL 9.8
CVE-2017-7551

389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes r…

Patch available
Fix from $2,300 2017-08-16
Fedora HIGH 7.5
CVE-2015-1783

The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause…

Fix: after 2.4.0
Fix from $1,950 2017-08-11