Vulnerability index

Browse CVEs

1,897 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2014-8119 The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augea… Fedora after 0.2.6 Fix from $1,9502017-12-29 HIGH 7.5 CVE-2015-8008 The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intende… Fedora 1.25.3+ Fix from $1,9502017-12-29 MEDIUM 5.5 CVE-2014-4978 The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1)… Fedora Patch available Fix from $1,6002017-12-29 MEDIUM 6.1 CVE-2017-16876 Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary we… Fedora 0.8.1+ Fix from $1,6002017-12-29 CRITICAL 9.8 CVE-2015-7687 Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vec… Fedora after 5.7.1 Fix from $2,3002017-10-16 MEDIUM 5.9 CVE-2015-3229 fedora-cloud-atomic.ks in spin-kickstarts allows remote attackers to conduct man-in-the-middle attacks by leveraging use of HTTP to download Fedora A… Spin Kickstarts Patch available Fix from $1,6002017-10-16 MEDIUM 6.5 CVE-2014-9092 libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker. Fedora after 1.2.90 Fix from $1,6002017-10-10 HIGH 7.8 CVE-2015-5704 scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands. Fedora after 2.15.6 Fix from $1,9502017-09-25 CRITICAL 9.8 CVE-2017-12170 Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored a… Fedora Mitigation only Fix from $2,3002017-09-21 HIGH 8.8 CVE-2015-5607 Cross-site request forgery in the REST API in IPython 2 and 3. Fedora Patch available Fix from $1,9502017-09-20 HIGH 7.5 CVE-2015-1854 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn ca… Fedora after 1.3.3.9 Fix from $1,9502017-09-19 MEDIUM 5.9 CVE-2015-3420 The ssl-proxy-openssl.c function in Dovecot before 2.2.17, when SSLv3 is disabled, allow remote attackers to cause a denial of service (login process… Fedora after 2.2.16 Fix from $1,6002017-09-19 MEDIUM 6.1 CVE-2017-1002150 python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection Python Fedora after 0.8.0 Fix from $1,6002017-09-14 CRITICAL 9.8 CVE-2017-11462EPSS 5% Double free vulnerability in MIT Kerberos 5 (aka krb5) allows attackers to have unspecified impact via vectors involving automatic deletion of securi… Fedora Patch available Fix from $2,3002017-09-13 HIGH 7.5 CVE-2015-5705 Argument injection vulnerability in devscripts before 2.15.7 allows remote attackers to write to arbitrary files via a crafted symlink and crafted fi… Fedora after 2.15.6 Fix from $1,9502017-09-06 HIGH 7.5 CVE-2017-13749 There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of servi… Fedora No fix yet Fix from $1,9502017-08-29 HIGH 7.5 CVE-2017-13750 There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial o… Fedora No fix yet Fix from $1,9502017-08-29 HIGH 7.5 CVE-2017-13751 There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service a… Fedora No fix yet Fix from $1,9502017-08-29 HIGH 7.5 CVE-2017-13752 There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service … Fedora No fix yet Fix from $1,9502017-08-29 HIGH 7.5 CVE-2017-13746 There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1297 in JasPer 2.0.12 that will lead to a remote denial o… Fedora No fix yet Fix from $1,9502017-08-29 HIGH 7.5 CVE-2017-13747 There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service … Fedora No fix yet Fix from $1,9502017-08-29 HIGH 7.5 CVE-2017-13748 There are lots of memory leaks in JasPer 2.0.12, triggered in the function jas_strdup() in base/jas_string.c, that will lead to a remote denial of se… Fedora No fix yet Fix from $1,9502017-08-29 HIGH 7.5 CVE-2015-1395EPSS 11% Directory traversal vulnerability in GNU patch versions which support Git-style patching before 2.7.3 allows remote attackers to write to arbitrary f… Fedora after 2.7.2 Fix from $1,9502017-08-25 MEDIUM 5.5 CVE-2014-9637 GNU patch 2.7.2 and earlier allows remote attackers to cause a denial of service (memory consumption and segmentation fault) via a crafted diff file. Fedora after 2.7.2 Fix from $1,6002017-08-25 MEDIUM 5.3 CVE-2015-5146 ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and acces… Fedora after 4.2.8 Fix from $1,6002017-08-24 HIGH 8.8 CVE-2017-11610EPSS 87% The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to ex… Fedora after 3.0 Fix from $1,9502017-08-23 HIGH 8.8 CVE-2015-5258 Cross-site request forgery (CSRF) vulnerability in springframework-social before 1.1.3. Fedora 1.1.3+ Fix from $1,9502017-08-22 MEDIUM 6.5 CVE-2017-12843 Cyrus IMAP before 3.0.3 allows remote authenticated users to write to arbitrary files via a crafted (1) SYNCAPPLY, (2) SYNCGET or (3) SYNCRESTORE com… Fedora after 3.0.2 Fix from $1,6002017-08-22 CRITICAL 9.8 CVE-2017-7551 389-ds-base version before 1.3.5.19 and 1.3.6.7 are vulnerable to password brute-force attacks during account lockout due to different return codes r… 389 Directory Server Patch available Fix from $2,3002017-08-16 HIGH 7.5 CVE-2015-1783 The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause… Fedora after 2.4.0 Fix from $1,9502017-08-11