Vulnerabilities > Fedoraproject > Fedora > 23

DATE CVE VULNERABILITY TITLE RISK
2017-04-21 CVE-2016-0721 Session Fixation vulnerability in multiple products
Session fixation vulnerability in pcsd in pcs before 0.9.157.
network
low complexity
clusterlabs redhat fedoraproject CWE-384
8.1
2017-04-21 CVE-2016-0720 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
network
low complexity
clusterlabs redhat fedoraproject CWE-352
8.8
2017-04-14 CVE-2016-6299 Permissions, Privileges, and Access Controls vulnerability in multiple products
The scm plug-in in mock might allow attackers to bypass the intended chroot protection mechanism and gain root privileges via a crafted spec file.
local
low complexity
fedoraproject mock-project CWE-264
7.8
2017-04-13 CVE-2015-8567 Memory Leak vulnerability in multiple products
Memory leak in net/vmxnet3.c in QEMU allows remote attackers to cause a denial of service (memory consumption).
7.7
2017-04-13 CVE-2015-1839 Data Processing Errors vulnerability in multiple products
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
local
low complexity
saltstack fedoraproject CWE-19
5.3
2017-04-13 CVE-2015-1838 Data Processing Errors vulnerability in multiple products
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
local
low complexity
saltstack fedoraproject CWE-19
5.3
2017-03-28 CVE-2016-8884 NULL Pointer Dereference vulnerability in multiple products
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image.
local
low complexity
jasper-project fedoraproject CWE-476
5.5
2017-03-27 CVE-2016-9243 HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
network
low complexity
cryptography-io fedoraproject canonical
7.5
2017-03-23 CVE-2016-8887 NULL Pointer Dereference vulnerability in multiple products
The jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (NULL pointer dereference).
local
low complexity
jasper-project fedoraproject CWE-476
5.5
2017-03-03 CVE-2016-7972 Resource Management Errors vulnerability in multiple products
The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
network
low complexity
opensuse fedoraproject libass-project CWE-399
7.5