Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Fedorahosted

First CVE: Jul 30, 2009Active for: 17 yearsTotal CVEs: 5

Fedorahosted hosts a modest portfolio of infrastructure and system-management components, including the cronie job scheduler, SSSD identity-service daemon, and Newt user-interface library, each of which can occupy sensitive roles in authentication and task automation. Observed vulnerabilities across this portfolio cluster around sensitive-information disclosure, improper authentication handling, insecure file-access patterns including link-following issues, and memory-buffer boundary violations—weakness classes typical of lower-level system software where access control and input parsing are critical. Current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
5
Total CVEs
More Total CVEs than 83% of tracked vendors
0.4
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 4% of tracked vendors
4.4
Avg CVSS Score
Higher Avg CVSS Score than 6% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Fedorahosted over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 30, 2009
16 years ago
Most Recent CVE
Apr 9, 2013
4,854 days ago

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (5 CVEs).

5 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2009-2410HIGH
The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows
Jul 30, 20097.520NONO
CVE-2009-2905MEDIUM
Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code vi
Sep 29, 20094.619NONO
CVE-2012-6097MEDIUM
File descriptor leak in cronie 1.4.8, when running in certain environments, might allow local users to read restricted files, as demonstrated by reading /etc/crontab.
Apr 9, 20134.318NONO
CVE-2010-0424LOW
The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequent
Feb 25, 20103.317NONO
CVE-2010-4341LOW
The pam_parse_in_data_v2 function in src/responder/pam/pamsrv_cmd.c in the PAM responder in SSSD 1.5.0, 1.4.x, and 1.3 allows local users to cause a denial of service (infinite loo
Jan 25, 20112.113NONO
View all 5 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products5 CVEs
40%
40%
20%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown5 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown5 (100.0%)
User Interaction
None0 (0.0%)
Unknown5 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown5 (100.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (5 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Fedorahosted.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Fedorahosted — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Fedorahosted's Products

View all 1 CNAs →

Top CWEs