Vulnerabilities > Redhat > Fedora Core > Medium

DATE CVE VULNERABILITY TITLE RISK
2007-07-27 CVE-2007-2874 Remote Security vulnerability in Fedora Core
Buffer overflow in the wpa_printf function in the debugging code in wpa_supplicant in the Fedora NetworkManager package before 0.6.5-3.fc7 allows user-assisted remote attackers to execute arbitrary code via malformed frames on a WPA2 network.
network
redhat
5.8
2007-04-16 CVE-2007-2030 Unspecified vulnerability in Redhat Enterprise Linux and Fedora Core
lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.
local
low complexity
redhat
4.9
2007-03-20 CVE-2007-0998 Permissions, Privileges, and Access Controls vulnerability in XEN Qemu
The VNC server implementation in QEMU, as used by Xen and possibly other environments, allows local users of a guest operating system to read arbitrary files on the host operating system via unspecified vectors related to QEMU monitor mode, as demonstrated by mapping files to a CDROM device.
network
redhat xen CWE-264
4.3
2007-03-07 CVE-2006-7151 Unspecified vulnerability in GNU Libtool-Ltdl 1.5.222.3
Untrusted search path vulnerability in the libtool-ltdl library (libltdl.so) 1.5.22-2.3 in Fedora Core 5 might allow local users to execute arbitrary code via a malicious library in the (1) hwcap, (2) 0, and (3) nosegneg subdirectories.
local
redhat gnu
6.6
2006-11-03 CVE-2006-5701 Denial of Service vulnerability in Linux Kernel SquashFS Double Free
Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem.
local
low complexity
linux redhat
4.9
2006-02-14 CVE-2006-0452 Remote Denial Of Service vulnerability in Redhat Fedora Core 1.0
dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a large amount of recursion, as demonstrated using the ProtoVer LDAP test suite.
network
low complexity
redhat
5.0
2006-02-14 CVE-2006-0451 Remote Denial Of Service vulnerability in Redhat Fedora Core 1.0
Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.
network
low complexity
redhat
5.0
2005-12-31 CVE-2005-3630 Information Disclosure vulnerability in Redhat Fedora Core 1.0
Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.
network
low complexity
redhat
5.0
2005-12-31 CVE-2005-3626 Resource Management Errors vulnerability in multiple products
Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
5.0
2005-12-31 CVE-2005-3624 Numeric Errors vulnerability in multiple products
The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
5.0