Skip to main content

Vendor archive

fedoraproject CVEs

Beta · best-effort

5,417 CVEs tagged to vendor fedoraproject472 Critical, 2,338 High, 2,343 Medium, 264 Low, 0 Unrated.

CVE-2009-1891

Published Jul 10, 2009

The mod_deflate module in Apache httpd 2.2.11 and earlier compresses large files until completion even after the associated network connection is closed, which allows remote attac…

CVSS 7.1 · High

CVE-2009-1890

Published Jul 5, 2009

The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an…

CVSS 7.1 · High

CVE-2009-1837

Published Jun 12, 2009

Race condition in the NPObjWrapper_NewResolve function in modules/plugin/base/src/nsJSNPRuntime.cpp in xul.dll in Mozilla Firefox 3 before 3.0.11 might allow remote attackers to e…

CVSS 7.5 · High

CVE-2009-1903

Published Jun 3, 2009

The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2009-0846

Published Apr 9, 2009

The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to caus…

CVSS 10.0 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2009-0115

Published Mar 30, 2009

The Device Mapper multipathing driver (aka multipath-tools or device-mapper-multipath) 0.4.8, as used in SUSE openSUSE, SUSE Linux Enterprise Server (SLES), Fedora, and possibly o…

CVSS 7.8 · High

CVE-2009-0040

Published Feb 22, 2009

The PNG reference library (aka libpng) before 1.0.43, and 1.2.x before 1.2.35, as used in pngcrush and other applications, allows context-dependent attackers to cause a denial of…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9

CVE-2009-0314

Published Jan 28, 2009

Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, rel…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-5021

Published Nov 13, 2008

nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial…

CVSS 9.3 · Critical

CVE-2008-3969

Published Sep 11, 2008

Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent hand…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2008-3282

Published Aug 29, 2008

Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote atta…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2008-3281

Published Aug 27, 2008

libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Showing 5,351-5,375 of 5,417 CVEsPage 215 of 217