Vulnerabilities > Fedoraproject > Fedora > High

DATE CVE VULNERABILITY TITLE RISK
2019-04-17 CVE-2019-9497 Improper Authentication vulnerability in multiple products
The implementations of EAP-PWD in hostapd EAP Server and wpa_supplicant EAP Peer do not validate the scalar and element values in EAP-pwd-Commit.
network
high complexity
w1-fi fedoraproject CWE-287
8.1
2019-04-17 CVE-2019-9496 Improper Authentication vulnerability in multiple products
An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode.
network
low complexity
w1-fi fedoraproject CWE-287
7.5
2019-04-09 CVE-2019-3842 Incorrect Authorization vulnerability in multiple products
In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable.
7.0
2019-04-09 CVE-2019-10903 Out-of-bounds Read vulnerability in multiple products
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash.
7.5
2019-04-09 CVE-2019-10902 Unchecked Return Value vulnerability in multiple products
In Wireshark 3.0.0, the TSDNS dissector could crash.
network
low complexity
wireshark fedoraproject CWE-252
7.5
2019-04-09 CVE-2019-10901 NULL Pointer Dereference vulnerability in multiple products
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the LDSS dissector could crash.
7.5
2019-04-09 CVE-2019-10900 Infinite Loop vulnerability in multiple products
In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop.
network
low complexity
wireshark fedoraproject CWE-835
7.5
2019-04-09 CVE-2019-10899 Out-of-bounds Read vulnerability in multiple products
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the SRVLOC dissector could crash.
7.5
2019-04-09 CVE-2019-10898 Infinite Loop vulnerability in multiple products
In Wireshark 3.0.0, the GSUP dissector could go into an infinite loop.
network
low complexity
wireshark fedoraproject CWE-835
7.5
2019-04-09 CVE-2019-10897 Infinite Loop vulnerability in multiple products
In Wireshark 3.0.0, the IEEE 802.11 dissector could go into an infinite loop.
network
low complexity
wireshark fedoraproject CWE-835
7.5