Fedora Core

Vendor:

First CVE: Jul 27, 2004 · Active for 21 years

81
Total CVEs
More Total CVEs than 99% of tracked products
20.3
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Fedora Core over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 27, 2004
21 years ago
Most Recent CVE
Nov 26, 2007
6,816 days ago

CVE Severity & Scoring

Fedora Core81 CVEs
All CVEs352,708 CVEs
LowMediumHigh
Attack Vector
Local1 (1.2%)
Network0 (0.0%)
Unknown80 (98.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High1 (1.2%)
Unknown80 (98.8%)
User Interaction
None1 (1.2%)
Unknown80 (98.8%)
Required0 (0.0%)
Privileges Required
Low1 (1.2%)
High0 (0.0%)
None0 (0.0%)
Unknown80 (98.8%)

Top CVEs

Signals from CVEs in this product scope (81 CVEs).

81 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag names when restricting input to allowed tags, which allows d
Jul 27, 20046.854NOYES
Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is no
Mar 1, 200510.049NOYES
Buffer overflow in the logging capability for the DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13 allows remote attackers to cause a denial of service (server crash) and p
Aug 6, 200410.048NONO
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allow remote attackers to execute arbitrary code via certain WAV
Aug 6, 200410.048NOYES
The DHCP daemon (DHCPD) for ISC DHCP 3.0.1rc12 and 3.0.1rc13, when compiled in environments that do not provide the vsnprintf function, uses C include files that define vsnprintf t
Aug 6, 200410.038NONO
Buffer overflow in the QFILEPATHINFO request handler in Samba 3.0.x through 3.0.7 may allow remote attackers to execute arbitrary code via a TRANSACT2_QFILEPATHINFO request with a
Jan 27, 200510.037NONO
Integer overflow in the Samba daemon (smbd) in Samba 2.x and 3.0.x through 3.0.9 allows remote authenticated users to cause a denial of service (application crash) and possibly exe
Jan 10, 200510.036NONO
Multiple heap-based buffer overflows in Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allow remote attackers to cause a denial of ser
Jan 27, 200510.035NONO
Multiple integer overflows in xpdf 2.0 and 3.0, and other packages that use xpdf code such as CUPS, gpdf, and kdegraphics, allow remote attackers to cause a denial of service (cras
Jan 27, 200510.034NONO
Stack-based buffer overflow in the writeGroup function in nsVCardObj.cpp for Mozilla Firefox before the Preview Release, Mozilla before 1.7.3, and Thunderbird before 0.8 allows rem
Jan 27, 200510.034NONO

Exploit Exposure

Signals from CVEs in this product scope (81 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
17 CVEs
21.0% of CVEs· 90th percentile

Social Chatter

Signals from CVEs in this product scope (81 CVEs).

Media Mentions

Signals from CVEs in this product scope (81 CVEs).

Top CNAs Publishing CVEs For Fedora Core

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
f712.10.4%00
core6110.05.7%00
core_5.046.82.0%02
core_4.046.35.8%01
core_3.0436.23.8%010
core_2.0496.77.0%011
core_1.0256.46.3%07
1.045.71.6%00