Redhat Fedora Core vulnerabilities
77 known vulnerabilities affecting redhat/fedora_core.
Total CVEs
77
CISA KEV
0
Public exploits
16
Exploited in wild
0
Severity breakdown
CRITICAL20HIGH16MEDIUM28LOW13
Vulnerabilities
Page 2 of 4
CVE-2004-0234P3CRITICALCVSS 10.0vcore_1.02004-08-18
CVE-2004-0234 [CRITICAL] CWE-119 CVE-2004-0234: Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used i
Multiple stack-based buffer overflows in the get_header function in header.c for LHA 1.14, as used in products such as Barracuda Spam Firewall, allow remote attackers or local users to execute arbitrary code via long directory or file names in an LHA archive, which triggers the overflow when testing or extracting the archive.
nvd
CVE-2004-1015P3CRITICALCVSS 10.0vcore_2.0vcore_3.02005-01-10
CVE-2004-1015 [CRITICAL] CVE-2004-1015: Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option ena
Buffer overflow in proxyd for Cyrus IMAP Server 2.2.9 and earlier, with the imapmagicplus option enabled, may allow remote attackers to execute arbitrary code, a different vulnerability than CVE-2004-1011.
nvd
CVE-2005-0156P4LOWCVSS 2.1PoCvcore_3.02005-02-07
CVE-2005-0156 [LOW] CVE-2005-0156: Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sper
Buffer overflow in the PerlIO implementation in Perl 5.8.0, when installed with setuid support (sperl), allows local users to execute arbitrary code by setting the PERLIO_DEBUG variable and executing a Perl script whose full pathname contains a long directory tree.
nvd
CVE-2004-0902P3CRITICALCVSS 10.0vcore_1.02005-01-27
CVE-2004-0902 [CRITICAL] CVE-2004-0902: Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via (1) the "Send page" functionality, (2) certain responses from a malicious POP3 server, or (3) a link containing a non-ASCII
nvd
CVE-2004-0888P4CRITICALCVSS 10.0vcore_2.02005-01-27
CVE-2004-0888 [CRITICAL] CVE-2004-0888: Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS,
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0889.
nvd
CVE-2004-1067P4CRITICALCVSS 10.0vcore_2.0vcore_3.02005-01-10
CVE-2004-1067 [CRITICAL] CVE-2004-1067: Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a
Off-by-one error in the mysasl_canon_user function in Cyrus IMAP Server 2.2.9 and earlier leads to a buffer overflow, which may allow remote attackers to execute arbitrary code via the username.
nvd
CVE-2005-0736P4LOWCVSS 2.1PoCvcore_2.0vcore_3.02005-03-09
CVE-2005-0736 [LOW] CVE-2005-0736: Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users
Integer overflow in sys_epoll_wait in eventpoll.c for Linux kernel 2.6 to 2.6.11 allows local users to overwrite kernel memory via a large number of events.
nvd
CVE-2006-5701P4MEDIUMCVSS 4.9PoCvcore_5.02006-11-03
CVE-2006-5701 [MEDIUM] CVE-2006-5701: Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and
Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem.
nvd
CVE-2005-0754P4HIGHCVSS 7.5vcore_3.02005-04-22
CVE-2005-0754 [HIGH] CVE-2005-0754: Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which
Kommander in KDE 3.2 through KDE 3.4.0 executes data files without confirmation from the user, which allows remote attackers to execute arbitrary code.
nvd
CVE-2004-0889P4CRITICALCVSS 10.0vcore_2.02005-01-27
CVE-2004-0889 [CRITICAL] CVE-2004-0889: Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow re
Multiple integer overflows in xpdf 3.0, and other packages that use xpdf code such as CUPS, allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code, a different set of vulnerabilities than those identified by CVE-2004-0888.
nvd
CVE-2004-0817P4HIGHCVSS 7.5vcore_1.0vcore_2.0+1 more2004-12-31
CVE-2004-0817 [HIGH] CVE-2004-0817: Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execut
Multiple heap-based buffer overflows in the imlib BMP image handler allow remote attackers to execute arbitrary code via a crafted BMP file.
nvd
CVE-2004-1333P4LOWCVSS 2.1PoCvcore_1.0vcore_2.0+1 more2004-12-15
CVE-2004-1333 [LOW] CVE-2004-1333: Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows loca
Integer overflow in the vc_resize function in the Linux kernel 2.4 and 2.6 before 2.6.10 allows local users to cause a denial of service (kernel crash) via a short new screen value, which leads to a buffer overflow.
nvd
CVE-2004-0415P4LOWCVSS 2.1PoCvcore_1.02004-11-23
CVE-2004-0415 [LOW] CVE-2004-0415: Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local us
Linux kernel does not properly convert 64-bit file offset pointers to 32 bits, which allows local users to access portions of kernel memory.
nvd
CVE-2004-0914P4CRITICALCVSS 10.0vcore_2.0vcore_3.02005-01-10
CVE-2004-0914 [CRITICAL] CVE-2004-0914: Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, inc
Multiple vulnerabilities in libXpm for 6.8.1 and earlier, as used in XFree86 and other packages, include (1) multiple integer overflows, (2) out-of-bounds memory accesses, (3) directory traversal, (4) shell metacharacter, (5) endless loops, and (6) memory leaks, which could allow remote attackers to obtain sensitive information, cause a denial of service (a
nvd
CVE-2005-0605P4HIGHCVSS 7.5vcore_2.0vcore_3.02005-03-02
CVE-2005-0605 [HIGH] CVE-2005-0605: scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value tha
scan.c for LibXPM may allow attackers to execute arbitrary code via a negative bitmap_unit value that leads to a buffer overflow.
nvd
CVE-2005-0373P4HIGHCVSS 7.5vcore_1.02004-10-07
CVE-2005-0373 [HIGH] CVE-2005-0373: Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the
Buffer overflow in digestmd5.c CVS release 1.170 (also referred to as digestmda5.c), as used in the DIGEST-MD5 SASL plugin for Cyrus-SASL but not in any official releases, allows remote attackers to execute arbitrary code.
nvd
CVE-2004-1335P4LOWCVSS 2.1PoCvcore_1.0vcore_2.0+1 more2004-12-15
CVE-2004-1335 [LOW] CVE-2004-1335: Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to c
Memory leak in the ip_options_get function in the Linux kernel before 2.6.10 allows local users to cause a denial of service (memory consumption) by repeatedly calling the ip_cmsg_send function.
nvd
CVE-2004-1073P4LOWCVSS 2.1PoCvcore_2.0vcore_3.02005-01-10
CVE-2004-1073 [LOW] CVE-2004-1073: The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and
The open_exec function in the execve functionality (exec.c) in Linux kernel 2.4.x up to 2.4.27, and 2.6.x up to 2.6.8, allows local users to read non-readable ELF binaries by using the interpreter (PT_INTERP) functionality.
nvd
CVE-2004-0986P4HIGHCVSS 7.5vcore_3.02005-03-01
CVE-2004-0986 [HIGH] CVE-2004-0986: Iptables before 1.2.11, under certain conditions, does not properly load the required modules at sys
Iptables before 1.2.11, under certain conditions, does not properly load the required modules at system startup, which causes the firewall rules to fail to load and protect the system from remote attackers.
nvd
CVE-2004-0827P4HIGHCVSS 7.5vcore_1.0vcore_2.0+1 more2004-09-16
CVE-2004-0827 [HIGH] CVE-2004-0827: Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6
Multiple buffer overflows in the ImageMagick graphics library 5.x before 5.4.4, and 6.x before 6.0.6.2, allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via malformed (1) AVI, (2) BMP, or (3) DIB files.
nvd