cbcvebase.

Redhat Fedora Core vulnerabilities

77 known vulnerabilities affecting redhat/fedora_core.

Total CVEs
77
CISA KEV
0
Public exploits
16
Exploited in wild
0
Severity breakdown
CRITICAL20HIGH16MEDIUM28LOW13

Vulnerabilities

Page 4 of 4
CVE-2004-0930P4MEDIUMCVSS 5.0vcore_2.0vcore_3.02005-01-27
CVE-2004-0930 [MEDIUM] CVE-2004-0930: The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authentic The ms_fnmatch function in Samba 3.0.4 and 3.0.7 and possibly other versions allows remote authenticated users to cause a denial of service (CPU consumption) via a SAMBA request that contains multiple * (wildcard) characters.
nvd
CVE-2005-3630P4MEDIUMCVSS 5.0v1.02005-12-31
CVE-2005-3630 [MEDIUM] CVE-2005-3630: Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as t Fedora Directory Server before 10 allows remote attackers to obtain sensitive information, such as the password from adm.conf via an IFRAME element, probably involving an Apache httpd.conf configuration that orders "allow" directives before "deny" directives.
nvd
CVE-2005-0085P4MEDIUMCVSS 6.8vcore_3.02005-04-27
CVE-2005-0085 [MEDIUM] CVE-2005-0085: Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers Cross-site scripting (XSS) vulnerability in ht://dig (htdig) before 3.1.6-r7 allows remote attackers to execute arbitrary web script or HTML via the config parameter, which is not properly sanitized before it is displayed in an error message.
nvd
CVE-2005-3624P4MEDIUMCVSS 5.0vcore_1.0vcore_2.0+2 more2005-12-31
CVE-2005-3624 [MEDIUM] CWE-189 CVE-2005-3624: The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, t The CCITTFaxStream::CCITTFaxStream function in Stream.cc for xpdf, gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others allows attackers to corrupt the heap via negative or large integers in a CCITTFaxDecode stream, which lead to integer overflows and integer underflows.
nvd
CVE-2005-3626P4MEDIUMCVSS 5.0vcore_1.0vcore_2.0+2 more2005-12-31
CVE-2005-3626 [MEDIUM] CWE-399 CVE-2005-3626: Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and oth Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (crash) via a crafted FlateDecode stream that triggers a null dereference.
nvd
CVE-2004-0960P4MEDIUMCVSS 5.0vcore_2.02005-02-09
CVE-2004-0960 [MEDIUM] CVE-2004-0960: FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malform FreeRADIUS before 1.0.1 allows remote attackers to cause a denial of service (core dump) via malformed USR vendor-specific attributes (VSA) that cause a memcpy operation with a -1 argument.
nvd
CVE-2006-0452P4MEDIUMCVSS 5.0v1.02006-02-14
CVE-2006-0452 [MEDIUM] CVE-2006-0452: dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a dn2ancestor in the LDAP component in Fedora Directory Server 1.0 allows remote attackers to cause a denial of service (CPU and memory consumption) via a ModDN operation with a DN that contains a large number of "," (comma) characters, which results in a large amount of recursion, as demonstrated using the ProtoVer LDAP test suite.
nvd
CVE-2006-0451P4MEDIUMCVSS 5.0v1.02006-02-14
CVE-2006-0451 [MEDIUM] CVE-2006-0451: Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to Multiple memory leaks in the LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (memory consumption) via invalid BER packets that trigger an error, which might prevent memory from being freed if it was allocated during the ber_scanf call, as demonstrated using the ProtoVer LDAP test suite.
nvd
CVE-2004-1613P4MEDIUMCVSS 5.0vcore_1.0vcore_2.02004-10-18
CVE-2004-1613 [MEDIUM] CVE-2004-1613: Mozilla allows remote attackers to cause a denial of service (application crash from null dereferenc Mozilla allows remote attackers to cause a denial of service (application crash from null dereference or infinite loop) via a web page that contains a (1) TEXTAREA, (2) INPUT, (3) FRAMESET or (4) IMG tag followed by a null character and some trailing characters, as demonstrated by mangleme.
nvd
CVE-2005-0109P4MEDIUMCVSS 5.6vcore_3.02005-03-05
CVE-2005-0109 [MEDIUM] CVE-2005-0109: Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pen Hyper-Threading technology, as used in FreeBSD and other operating systems that are run on Intel Pentium and other processors, allows local users to use a malicious thread to create covert channels, monitor the execution of other threads, and obtain sensitive information such as cryptographic keys, via a timing attack on memory cache misses.
nvd
CVE-2007-2030P4MEDIUMCVSS 4.9vcore_5.02007-04-16
CVE-2007-2030 [MEDIUM] CVE-2007-2030: lharc.c in lha does not securely create temporary files, which might allow local users to read or wr lharc.c in lha does not securely create temporary files, which might allow local users to read or write files by creating a file before LHA is invoked.
nvd
CVE-2004-1268P4LOWCVSS 2.1vcore_2.0vcore_3.02005-01-10
CVE-2004-1268 [LOW] CVE-2004-1268: lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local lppasswd in CUPS 1.1.22 ignores write errors when modifying the CUPS passwd file, which allows local users to corrupt the file by filling the associated file system and triggering the write errors.
nvd
CVE-2004-1171P4LOWCVSS 2.1vcore_2.0vcore_3.02005-01-10
CVE-2004-1171 [LOW] CVE-2004-1171: KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user KDE 3.2.x and 3.3.0 through 3.3.2, when saving credentials that are (1) manually entered by the user or (2) created by the SMB protocol handler, stores those credentials for plaintext in the user's .desktop file, which may be created with world-readable permissions, which could allow local users to obtain usernames and passwords for remote resources such as SMB
nvd
CVE-2007-6131P4LOWCVSS 2.1vf72007-11-26
CVE-2007-6131 [LOW] CWE-16 CVE-2007-6131: buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink buttonpressed.sh in scanbuttond 0.2.3 allows local users to overwrite arbitrary files via a symlink attack on the (1) scan.pnm and (2) scan.jpg temporary files.
nvd
CVE-2004-0587P4LOWCVSS 2.1vcore_1.02004-08-06
CVE-2004-0587 [LOW] CVE-2004-0587: Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause Insecure permissions for the /proc/scsi/qla2300/HbaApiNode file in Linux allows local users to cause a denial of service.
nvd
CVE-2004-0974P4LOWCVSS 2.1vcore_2.0vcore_3.02005-02-09
CVE-2004-0974 [LOW] CVE-2004-0974: The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, The netatalk package in Trustix Secure Linux 1.5 through 2.1, and possibly other operating systems, allows local users to overwrite files via a symlink attack on temporary files.
nvd
CVE-2004-1270P4LOWCVSS 2.1vcore_2.0vcore_3.02005-01-10
CVE-2004-1270 [LOW] CVE-2004-1270: lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and lppasswd in CUPS 1.1.22, when run in environments that do not ensure that file descriptors 0, 1, and 2 are open when lppasswd is called, does not verify that the passwd.new file is different from STDERR, which allows local users to control output to passwd.new via certain user input that triggers an error message.
nvd
Redhat Fedora Core vulnerabilities | cvebase