Vulnerabilities > Fedoraproject > Fedora

DATE CVE VULNERABILITY TITLE RISK
2019-12-31 CVE-2013-4357 Classic Buffer Overflow vulnerability in multiple products
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function.
7.5
2019-12-31 CVE-2013-4161 Improper Privilege Management vulnerability in multiple products
gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.
7.8
2019-12-31 CVE-2019-20176 Resource Exhaustion vulnerability in multiple products
In Pure-FTPd 1.0.49, a stack exhaustion issue was discovered in the listdir function in ls.c.
network
low complexity
pureftpd fedoraproject CWE-400
7.5
2019-12-30 CVE-2012-5645 Resource Exhaustion vulnerability in multiple products
A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets.
network
low complexity
freeciv fedoraproject CWE-400
7.5
2019-12-30 CVE-2012-5474 Missing Encryption of Sensitive Data vulnerability in multiple products
The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
5.5
2019-12-30 CVE-2019-20093 NULL Pointer Dereference vulnerability in multiple products
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.
local
low complexity
podofo-project fedoraproject CWE-476
5.5
2019-12-27 CVE-2019-20051 Incorrect Calculation vulnerability in multiple products
A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95.
local
low complexity
upx-project fedoraproject CWE-682
5.5
2019-12-27 CVE-2019-20021 Out-of-bounds Read vulnerability in multiple products
A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
local
low complexity
upx-project fedoraproject CWE-125
5.5
2019-12-26 CVE-2019-16789 HTTP Request Smuggling vulnerability in multiple products
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling.
8.2
2019-12-24 CVE-2019-19956 Memory Leak vulnerability in multiple products
xmlParseBalancedChunkMemoryRecover in parser.c in libxml2 before 2.9.10 has a memory leak related to newDoc->oldNs.
7.5