Skip to main content

Vendor archive

fedoraproject CVEs

Beta · best-effort

5,419 CVEs tagged to vendor fedoraproject472 Critical, 2,345 High, 2,338 Medium, 264 Low, 0 Unrated.

CVE-2011-3045

Published Mar 22, 2012

Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote att…

CVSS 8.8 · High

CVE-2011-4862

Published Dec 25, 2011

Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.2 and earlier, Heimdal 1.5.1 and earlier, GNU…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2011-4517

Published Dec 15, 2011

The jpc_crg_getparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 uses an incorrect data type during a certain size calculation, which allows remote attackers to trigger a…

CVSS 6.8 · Medium

CVE-2011-4516

Published Dec 15, 2011

Heap-based buffer overflow in the jpc_cox_getcompparms function in libjasper/jpc/jpc_cs.c in JasPer 1.900.1 allows remote attackers to execute arbitrary code or cause a denial of…

CVSS 6.8 · Medium

CVE-2011-1770

Published Jun 24, 2011

Integer underflow in the dccp_parse_options function (net/dccp/options.c) in the Linux kernel before 2.6.33.14 allows remote attackers to cause a denial of service via a Datagram…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-1943

Published Jun 14, 2011

The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate pas…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1758

Published May 26, 2011

The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentica…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-1027

Published Mar 20, 2011

Off-by-one error in the convert_query_hexchar function in html.c in cgit.cgi in cgit before 0.8.3.5 allows remote attackers to cause a denial of service (infinite loop) via a stri…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1067

Published Feb 23, 2011

slapd (aka ns-slapd) in 389 Directory Server before 1.2.8.a2 does not properly manage the c_timelimit field of the connection table element, which allows remote attackers to cause…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 5,251-5,275 of 5,419 CVEsPage 211 of 217