Vulnerabilities > Fedoraproject > Low

DATE CVE VULNERABILITY TITLE RISK
2018-03-01 CVE-2017-9271 Information Exposure Through Log Files vulnerability in multiple products
The commandline package update tool zypper writes HTTP proxy credentials into its logfile, allowing local attackers to gain access to proxies used.
local
low complexity
opensuse fedoraproject CWE-532
3.3
2018-01-08 CVE-2014-1859 Link Following vulnerability in multiple products
(1) core/tests/test_memmap.py, (2) core/tests/test_multiarray.py, (3) f2py/f2py2e.py, and (4) lib/tests/test_io.py in NumPy before 1.8.1 allow local users to write to arbitrary files via a symlink attack on a temporary file.
local
low complexity
numpy fedoraproject redhat CWE-59
2.1
2017-12-29 CVE-2014-4978 Link Following vulnerability in multiple products
The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph.
local
low complexity
rawstudio fedoraproject CWE-59
3.6
2017-10-06 CVE-2015-0296 Permissions, Privileges, and Access Controls vulnerability in TUG Texlive 3.1.20140525R34255.Fc21/6.20131226R32488.Fc20
The pre-install script in texlive 3.1.20140525_r34255.fc21 as packaged in Fedora 21 and rpm, and texlive 6.20131226_r32488.fc20 and rpm allows local users to delete arbitrary files via a crafted file in the user's home directory.
local
high complexity
tug fedoraproject CWE-264
1.2
2017-09-26 CVE-2015-5070 Information Exposure vulnerability in multiple products
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML.
3.5
2017-08-24 CVE-2015-5146 Improper Input Validation vulnerability in multiple products
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
3.5
2017-06-08 CVE-2016-3095 Information Exposure vulnerability in multiple products
server/bin/pulp-gen-ca-certificate in Pulp before 2.8.2 allows local users to read the generated private key.
local
low complexity
fedoraproject pulpproject CWE-200
2.1
2017-02-03 CVE-2016-9085 Integer Overflow or Wraparound vulnerability in multiple products
Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
local
low complexity
webmproject fedoraproject CWE-190
3.3
2016-04-15 CVE-2016-3144 Cross-site Scripting vulnerability in multiple products
Cross-site scripting (XSS) vulnerability in the Block Class module 7.x-2.x before 7.x-2.2 for Drupal allows remote authenticated users with the "Administer block classes" permission to inject arbitrary web script or HTML via a class name.
3.5
2016-04-13 CVE-2016-3158 Improper Access Control vulnerability in multiple products
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits.
local
low complexity
xen fedoraproject oracle CWE-284
1.7