Fedora records
8 published records for vendor fedora.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 87.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-310 Cryptographic Issues2
- CWE-399 Resource Management Errors2
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-20 Improper Input Validation1
- CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
42Plan | CVE-2008-3252No exploit | Stack-based buffer overflow in the read_article function in getarticle.c in newsx 1.6 allows remote attackers to execute arbitrary code via redhat · fedora · CWE-119 | Critical10.0 | — | 6.7% | Jul 21, 2008 |
35Monitor | CVE-2024-2746No exploit | Incomplete fix for CVE-2024-1929fedora · dnf5daemon-server · CWE-20 | High8.8 | — | 0.2% | May 7, 2024 |
32Monitor | CVE-2008-3283No exploit | Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier fedora · directory server · CWE-399 | High7.8 | — | 2.9% | Aug 29, 2008 |
30Monitor | CVE-2008-2930Proof of concept | Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a denfedora · directory server · CWE-399 | High7.1 | — | 6.6% | Aug 29, 2008 |
28Monitor | CVE-2015-1848No exploit | The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for refedora · pacemaker configuration system · CWE-310 | Medium6.8 | — | 2.4% | May 14, 2015 |
18Monitor | CVE-2015-3983No exploit | The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remotefedora · pacemaker configuration system · CWE-310 | Medium4.3 | — | 2.1% | May 14, 2015 |
18Monitor | CVE-2008-2929No exploit | Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Sefedora · directory server · CWE-79 | Medium4.3 | — | 1.7% | Aug 29, 2008 |
4Monitor | CVE-2012-3500No exploit | scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via devscripts devel team · devscripts · CWE-362 | Low1.2 | — | 0.3% | Sep 30, 2012 |
- CVE-2008-325242Plan
Stack-based buffer overflow in the read_article function in getarticle.c in newsx 1.6 allows remote attackers to execute arbitrary code via
CriticalCVSS 10.0No exploitEPSS 7%redhat · fedoraJul 21, 2008
- CVE-2024-274635Monitor
Incomplete fix for CVE-2024-1929
HighCVSS 8.8No exploitEPSS 0%fedora · dnf5daemon-serverMay 7, 2024
- CVE-2008-328332Monitor
Multiple memory leaks in Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 and earlier
HighCVSS 7.8No exploitEPSS 3%fedora · directory serverAug 29, 2008
- CVE-2008-293030Monitor
Red Hat Directory Server 7.1 before SP7, Red Hat Directory Server 8, and Fedora Directory Server 1.1.1 allow remote attackers to cause a den
HighCVSS 7.1Proof of conceptEPSS 7%fedora · directory serverAug 29, 2008
- CVE-2015-184828Monitor
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for re
MediumCVSS 6.8No exploitEPSS 2%fedora · pacemaker configuration systemMay 14, 2015
- CVE-2015-398318Monitor
The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote
MediumCVSS 4.3No exploitEPSS 2%fedora · pacemaker configuration systemMay 14, 2015
- CVE-2008-292918Monitor
Multiple cross-site scripting (XSS) vulnerabilities in the adminutil library in the Directory Server Administration Express and Directory Se
MediumCVSS 4.3No exploitEPSS 2%fedora · directory serverAug 29, 2008
- CVE-2012-35004Monitor
scripts/annotate-output.sh in devscripts before 2.12.2, as used in rpmdevtools before 8.3, allows local users to modify arbitrary files via
LowCVSS 1.2No exploitEPSS 0%devscripts devel team · devscriptsSep 30, 2012