Skip to main content

Vendor archive

fedoraproject CVEs

Beta · best-effort

5,417 CVEs tagged to vendor fedoraproject472 Critical, 2,338 High, 2,343 Medium, 264 Low, 0 Unrated.

CVE-2013-6629

Published Nov 19, 2013

The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not c…

CVSS 5.0 · Medium

CVE-2013-2207

Published Oct 9, 2013

pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and ob…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4283

Published Sep 10, 2013

ns-slapd in 389 Directory Server before 1.3.0.8 allows remote attackers to cause a denial of service (server crash) via a crafted Distinguished Name (DN) in a MOD operation reques…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-1888

Published Aug 17, 2013

pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-4854

Published Jul 29, 2013

The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9…

CVSS 7.8 · High

CVE-2013-2028

Published Jul 20, 2013

The ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of service (crash) and execute arbitrary code v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2002-2443

Published May 29, 2013

schpw.c in the kpasswd service in kadmind in MIT Kerberos 5 (aka krb5) before 1.11.3 does not properly validate UDP packets before sending responses, which allows remote attackers…

CVSS 5.0 · Medium

CVE-2013-1897

Published May 13, 2013

The do_search function in ldap/servers/slapd/search.c in 389 Directory Server 1.2.x before 1.2.11.20 and 1.3.x before 1.3.0.5 does not properly restrict access to entries when the…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-1416

Published Apr 19, 2013

The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm r…

CVSS 4.0 · Medium

CVE-2013-1830

Published Mar 25, 2013

user/view.php in Moodle through 2.1.10, 2.2.x before 2.2.8, 2.3.x before 2.3.5, and 2.4.x before 2.4.2 does not enforce the forceloginforprofiles setting, which allows remote atta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-0287

Published Mar 21, 2013

The Simple Access Provider in System Security Services Daemon (SSSD) 1.9.0 through 1.9.4, when the Active Directory provider is used, does not properly enforce the simple_deny_gro…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1568

Published Mar 1, 2013

The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared…

CVSS 1.9 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-0220

Published Feb 24, 2013

The (1) sss_autofs_cmd_getautomntent and (2) sss_autofs_cmd_getautomntbyname function in responder/autofs/autofssrv_cmd.c and the (3) ssh_cmd_parse_request function in responder/s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,201-5,225 of 5,417 CVEsPage 209 of 217