Fedora Core
Vendor:
First CVE: Oct 25, 2005 · Active for 20 years
8
Total CVEs
More Total CVEs than 87% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 63% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 24% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Fedora Core over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 25, 2005
20 years ago
Most Recent CVE
Jun 30, 2008
6,602 days ago
CVE Severity & Scoring
Fedora Core8 CVEs
63%
38%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown8 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown8 (100.0%)
User Interaction
None0 (0.0%)
Unknown8 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown8 (100.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-3103MEDIUM The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the permissions of arbitrary files via a symlink attack on the | Jul 15, 2007 | 6.2 | 25 | NO | YES |
CVE-2006-5170HIGH pam_ldap in nss_ldap on Red Hat Enterprise Linux 4, Fedora Core 3 and earlier, and possibly other distributions does not return an error condition when an LDAP directory server res | Oct 10, 2006 | 7.5 | 23 | NO | NO |
CVE-2005-2970MEDIUM Memory leak in the worker MPM (worker.c) for Apache 2, in certain circumstances, allows remote attackers to cause a denial of service (memory consumption) via aborted connections, | Oct 25, 2005 | 5.0 | 23 | NO | NO |
CVE-2007-3847MEDIUM The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forw | Aug 23, 2007 | 5.0 | 22 | NO | NO |
CVE-2007-1320HIGH Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow loc | May 2, 2007 | 7.2 | 21 | NO | NO |
CVE-2007-1321HIGH Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain re | Oct 30, 2007 | 7.2 | 20 | NO | NO |
CVE-2008-2944MEDIUM Double free vulnerability in the utrace support in the Linux kernel, probably 2.6.18, in Red Hat Enterprise Linux (RHEL) 5 and Fedora Core 6 (FC6) allows local users to cause a den | Jun 30, 2008 | 4.9 | 16 | NO | NO |
CVE-2007-6283MEDIUM Red Hat Enterprise Linux 5 and Fedora install the Bind /etc/rndc.key file with world-readable permissions, which allows local users to perform unauthorized named commands, such as | Dec 18, 2007 | 4.9 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
12.5% of CVEs· 86th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Fedora Core
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0 | 1 | 6.2 | 0.9% | 0 | 1 |
| 6 | 4 | 6.1 | 3.6% | 0 | 0 |
| 4 | 1 | 5.0 | 14.2% | 0 | 0 |