Known vulnerabilities in Fedora 25

Software: Fedora
Version: 25
Software CPE: cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*
Total vulnerabilities: 1035
Public exploits: 73
Known exploited (KEV): 10
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Fedora version 25 Fedora 25 is affected by 1035 vulnerabilities: 3 critical, 265 high, 271 medium, 496 low Critical High Medium Low

Vulnerabilities (1035)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU14021 - NULL Pointer Dereference
CVE-2017-17440
CWE-476 Low
No
No
- 26.07.2018 SB2018072616
SB2020112333
SB20171211345
and 2 more
#VU13603 - Exposure of sensitive information to an unauthorized actor
CVE-2017-17042
CWE-200 Low
No
No
- 07.07.2018 SB2018070909
SB2017120130
SB2017120131
and 1 more
#VU9766 - Error Handling
CVE-2017-16644
CWE-388 Low
No
No
- 26.12.2017 SB2017122601
SB2018032313
SB2018032314
and 10 more
#VU9763 - Divide By Zero
CVE-2017-16649
CWE-369 Low
No
No
- 26.12.2017 SB2017122104
SB2017120821
SB2017120408
and 3 more
#VU9762 - Divide By Zero
CVE-2017-16650
CWE-369 Low
No
No
- 26.12.2017 SB2017122104
SB2017120821
SB2017120408
and 3 more
#VU9761 - Out-of-bounds read
CVE-2017-16645
CWE-125 Low
No
No
- 26.12.2017 SB2017122104
SB2017122211
SB2017122105
and 6 more
#VU9760 - Improper input validation
CVE-2017-16646
CWE-20 Low
No
No
- 26.12.2017 SB2017122104
SB2017122211
SB2017122105
and 6 more
#VU9759 - NULL Pointer Dereference
CVE-2017-16647
CWE-476 Low
No
No
- 26.12.2017 SB2017122104
SB2017112827
SB2017112828
and 1 more
#VU9605 - Out-of-bounds read
CVE-2017-16643
CWE-125 Low
No
No
- 08.12.2017 SB2017120709
SB2017120710
SB2017120711
and 6 more
#VU9541 - Command injection
CVE-2017-1000159
CWE-77 High
No
No
- 05.12.2017 SB2017071413
SB2017120503
SB2018041706
and 3 more
#VU9441 - Missing release of memory after effective lifetime
CVE-2017-15094
CWE-401 Medium
No
No
- 29.11.2017 SB2017112906
SB2017112907
SB2017121529
and 5 more
#VU9440 - Improper Access Control
CVE-2017-15093
CWE-284 Low
No
No
- 29.11.2017 SB2017112906
SB2017112907
SB2017121528
and 5 more
#VU9439 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-15092
CWE-79 Low
No
No
- 29.11.2017 SB2017112906
SB2017112907
SB2017121534
and 5 more
#VU9437 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle')
CVE-2017-15090
CWE-300 Low
No
No
- 29.11.2017 SB2017112906
SB2017112907
SB2017121531
and 5 more
#VU9432 - Integer overflow
CVE-2017-1000158
CWE-190 High
No
No
- 28.11.2017 SB2017112809
SB2017112810
SB2017112811
and 20 more
#VU37876 - Memory corruption
CVE-2017-16938
CWE-119 High
No
No
- 24.11.2017 SB2017112409
SB2018010703
SB2017120412
and 3 more
#VU37892 - Use After Free
CVE-2017-1000211
CWE-416 Medium
No
No
- 17.11.2017 SB2017111713
SB20171211340
SB20171211341
#VU37894 - Integer overflow
CVE-2017-1000229
CWE-190 High
No
No
- 17.11.2017 SB2017111716
SB2018010703
SB2017120412
and 3 more
#VU92790 - Use After Free
CVE-2017-16648
CWE-416 Low
No
No
- 08.11.2017 SB2017110818
SB2017112827
SB2017112828
and 2 more
#VU8970 - Stack-based buffer overflow
CVE-2017-15396
CWE-121 Medium
No
No
- 27.10.2017 SB2017102709
SB2017102710
SB2017110701
and 7 more


Showing elements 1 - 20 out of 1035