Skip to content
Noroxi

fedoraproject records

5,450 published records for vendor fedoraproject.

Researcher profile

Entered KEV
86 · 1.6%
Weaponized
115 · 2.1%
Pre-auth RCE
332
With a fix record
92.7%
Median publish → KEV
148 days

All records

5,450 records
  • Apache Log4j2 JNDI features do not protect against attacker controlled LDAP and other JNDI related endpoints

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    apache · log4jDec 10, 2021

  • sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle que

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpMay 11, 2012

  • Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · http serverOct 5, 2021

  • Argument Injection in PHP-CGI

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpJun 9, 2024

  • Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    apache · http serverOct 7, 2021

  • Underflow in PHP-FPM can lead to RCE

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    php · phpOct 28, 2019

  • An issue was discovered in SaltStack Salt through 3002.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    saltstack · saltNov 6, 2020

  • When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    apache · geodeFeb 24, 2020

  • smtp_mailaddr in smtp_session.c in OpenSMTPD 6.6, as used in OpenBSD 6.6 and other products, allows remote attackers to execute arbitrary co

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    openbsd · opensmtpdJan 29, 2020

  • OpenSLP as used in ESXi and the Horizon DaaS appliances has a heap overwrite issue.

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    openslp · openslpDec 6, 2019

  • A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user.

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    resf · rocky linuxSep 16, 2021

  • Apache Log4j2 Thread Context Message Pattern and Context Lookup Pattern vulnerable to a denial of service attack

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    apache · log4jDec 14, 2021

  • Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bo

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    google · chromeSep 12, 2023

  • XStream is vulnerable to a Remote Command Execution attack

    HighCVSS 8.5KEVWeaponizedEPSS 98%

    xstream · xstreamAug 23, 2021

  • Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing t

    HighCVSS 7.8KEVWeaponizedEPSS 100%

    exiftool project · exiftoolApr 23, 2021

  • Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root

    HighCVSS 7.8KEVWeaponizedEPSS 100%

    sudo project · sudoJan 26, 2021

  • The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows rem

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    openssl · opensslApr 7, 2014

  • The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    siemens · simatic s7-1500 cpu 1518f-4 pn\/dp mfp firmwareOct 10, 2023

  • There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accep

    HighCVSS 7.5KEVWeaponizedEPSS 99%

    rubyonrails · railsMar 27, 2019

  • Type confusion in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to execute arbitrary code inside a sandbox via a craft

    HighCVSS 8.8KEVWeaponizedEPSS 84%

    google · chromeApr 26, 2021

  • Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

    CriticalCVSS 9.8KEVWeaponizedEPSS 70%

    roundcube · webmailNov 19, 2021

  • Snapshot authentication bypass in grafana

    HighCVSS 7.3KEVWeaponizedEPSS 100%

    grafana · grafanaOct 5, 2021

  • A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe

    HighCVSS 7.8KEVWeaponizedEPSS 93%

    linux · linux kernelMar 10, 2022

  • Type confusion in V8 in Google Chrome prior to 80.0.3987.122 allowed a remote attacker to potentially exploit heap corruption via a crafted

    HighCVSS 8.8KEVWeaponizedEPSS 79%

    google · chromeFeb 27, 2020

  • Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper attack (such as fil

    HighCVSS 7.8KEVWeaponizedEPSS 85%

    php · archive tarNov 19, 2020