Skip to main content

Vendor/product archive

redhat / fedora CVEs

Beta · best-effort

27 CVEs tagged to redhat / fedora2 Critical, 6 High, 19 Medium, 0 Low, 0 Unrated.

CVE-2011-0008

Published Jan 20, 2011

A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization deci…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-4695

Published Jan 14, 2011

A certain Fedora patch for gif2png.c in gif2png 2.5.1 and 2.5.2, as distributed in gif2png-2.5.1-1200.fc12 on Fedora 12 and gif2png_2.5.2-1 on Debian GNU/Linux, truncates a GIF pa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-3080

Published Nov 20, 2009

Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain pri…

CVSS 7.2 · High

CVE-2008-6755

Published Apr 27, 2009

ZoneMinder 1.23.3 on Fedora 10 sets the ownership of /etc/zm.conf to the apache user account, and sets the permissions to 0600, which makes it easier for remote attackers to modif…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-6560

Published Mar 31, 2009

Buffer overflow in CMAN - The Cluster Manager before 2.03.09-1 on Fedora 9 and Red Hat Enterprise Linux (RHEL) 5 allows attackers to cause a denial of service (CPU consumption and…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2009-0180

Published Jan 20, 2009

Certain Fedora build scripts for nfs-utils before 1.1.2-9.fc9 on Fedora 9, and before 1.1.4-6.fc10 on Fedora 10, omit TCP Wrapper support, which might allow remote attackers to by…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3832

Published Oct 3, 2008

A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-45 on Fedora 9, allows local users to cause a denial of ser…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3524

Published Sep 29, 2008

rc.sysinit in initscripts before 8.76.3-1 on Fedora 9 and other Linux platforms allows local users to delete arbitrary files via a symlink attack on a file or directory under (1)…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3252

Published Jul 21, 2008

Stack-based buffer overflow in the read_article function in getarticle.c in newsx 1.6 allows remote attackers to execute arbitrary code via a news article containing a large numbe…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2008-2808

Published Jul 7, 2008

Mozilla Firefox before 2.0.0.15 and SeaMonkey before 1.1.10 do not properly escape HTML in file:// URLs in directory listings, which allows remote attackers to conduct cross-site…

CVSS 4.3 · Medium

CVE-2008-1796

Published Apr 15, 2008

Comix 3.6.4 creates temporary directories with predictable names, which allows local users to cause an unspecified denial of service.

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0073

Published Mar 24, 2008

Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP param…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1290

Published Mar 24, 2008

ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1291

Published Mar 24, 2008

ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-1292

Published Mar 24, 2008

ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1)…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-0668

Published Feb 11, 2008

The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2