Skip to main content

Vendor archive

fedoraproject CVEs

Beta · best-effort

5,417 CVEs tagged to vendor fedoraproject472 Critical, 2,338 High, 2,343 Medium, 264 Low, 0 Unrated.

CVE-2014-0010

Published Jan 20, 2014

Multiple cross-site request forgery (CSRF) vulnerabilities in user/profile/index.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-0746

Published Jan 13, 2014

Directory traversal vulnerability in DeviceKit-disks in DeviceKit, as used in Fedora 11 and 12 and possibly other operating systems, allows local users to gain privileges via .. (…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5268

Published Dec 24, 2013

connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple f…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-4550

Published Dec 24, 2013

Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed,…

CVSS 5.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1812

Published Dec 12, 2013

The ruby-openid gem before 2.2.2 for Ruby allows remote OpenID providers to cause a denial of service (CPU consumption) via (1) a large XRDS document or (2) an XML Entity Expansio…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-6673

Published Dec 11, 2013

Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certifica…

CVSS 5.9 · Medium

CVE-2013-6672

Published Dec 11, 2013

Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.

CVSS 4.3 · Medium

CVE-2013-5619

Published Dec 11, 2013

Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a den…

CVSS 7.5 · High

CVE-2013-5615

Published Dec 11, 2013

The JavaScript implementation in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 does not properly enforce certain ty…

CVSS 9.8 · Critical

CVE-2013-5611

Published Dec 11, 2013

Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by co…

CVSS 5.8 · Medium

CVE-2013-5610

Published Dec 11, 2013

Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 allow remote attackers to cause a denial of service (memory cor…

CVSS 10.0 · Critical
Showing 5,176-5,200 of 5,417 CVEsPage 208 of 217