Fedora

Vendor:

First CVE: Aug 30, 2007 · Active for 18 years

27
Total CVEs
More Total CVEs than 96% of tracked products
4.5
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
6.0
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Fedora over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 30, 2007
18 years ago
Most Recent CVE
Nov 9, 2018
2,815 days ago

CVE Severity & Scoring

Fedora27 CVEs
All CVEs352,708 CVEs
MediumHigh
Attack Vector
Local1 (3.7%)
Network0 (0.0%)
Unknown26 (96.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (3.7%)
High0 (0.0%)
Unknown26 (96.3%)
User Interaction
None0 (0.0%)
Unknown26 (96.3%)
Required1 (3.7%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (3.7%)
Unknown26 (96.3%)

Top CVEs

Signals from CVEs in this product scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 through 8, and on Foresight Linux and rPath appliances, allows rem
May 22, 20087.134NOYES
Array index error in the sdpplin_parse function in input/libreal/sdpplin.c in xine-lib 1.1.10.1 allows remote RTSP servers to execute arbitrary code via a large streamid SDP parame
Mar 24, 20086.834NOYES
Stack-based buffer overflow in the read_article function in getarticle.c in newsx 1.6 allows remote attackers to execute arbitrary code via a news article containing a large number
Jul 21, 200810.028NONO
The excel_read_HLINK function in plugins/excel/ms-excel-read.c in Gnome Office Gnumeric before 1.8.1 allows user-assisted remote attackers to execute arbitrary code via a crafted X
Feb 11, 20089.328NONO
The seunshare_mount function in sandbox/seunshare.c in seunshare in certain Red Hat packages of policycoreutils 2.0.83 and earlier in Red Hat Enterprise Linux (RHEL) 6 and earlier,
Feb 24, 20116.923NONO
diatheke.pl in The SWORD Project Diatheke 1.5.9 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the range parameter.
Feb 25, 20087.523NONO
A certain Fedora patch for the utrace subsystem in the Linux kernel before 2.6.26.5-28 on Fedora 8, and before 2.6.26.5-45 on Fedora 9, allows local users to cause a denial of serv
Oct 3, 20084.922NOYES
The pa_drop_root function in PulseAudio 0.9.8, and a certain 0.9.9 build, does not check return values from (1) setresuid, (2) setreuid, (3) setuid, and (4) seteuid calls when atte
Jan 29, 20087.222NONO
A certain Fedora patch for parse.c in sudo before 1.7.4p5-1.fc14 on Fedora 14 does not properly interpret a system group (aka %group) in the sudoers file during authorization decis
Jan 20, 20116.921NONO
Array index error in the gdth_read_event function in drivers/scsi/gdth.c in the Linux kernel before 2.6.32-rc8 allows local users to cause a denial of service or possibly gain priv
Nov 20, 20097.221NONO

Exploit Exposure

Signals from CVEs in this product scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
11.1% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (27 CVEs).

Media Mentions

Signals from CVEs in this product scope (27 CVEs).

Top CNAs Publishing CVEs For Fedora

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
935.50.5%01
846.03.9%02
746.54.5%01
627.06.2%01
1416.90.4%00
1316.90.4%00
1216.90.4%00
1036.20.4%00