Known vulnerabilities in Fedora 25 - page 2

Software: Fedora
Version: 25
Software CPE: cpe:2.3:o:fedoraproject:fedora:*:*:*:*:*:*:*:*
Total vulnerabilities: 1035
Public exploits: 73
Known exploited (KEV): 10
Highest CVSSv4 Score: 9.4

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Fedora version 25 Fedora 25 is affected by 1035 vulnerabilities: 3 critical, 265 high, 271 medium, 496 low Critical High Medium Low

Vulnerabilities (1035)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU20864 - Missing release of memory after effective lifetime
CVE-2017-8807
CWE-401 Medium
No
No
- 04.09.2019 SB2017111615
SB2017112601
SB2017112140
and 3 more
#VU12612 - NULL Pointer Dereference
CVE-2017-9216
CWE-476 Low
No
No
- 14.05.2018 SB2017052316
SB2017112210
SB2022050919
and 3 more
#VU12599 - Resource exhaustion
CVE-2017-15298
CWE-400 Low
No
No
- 11.05.2018 SB2018020716
SB2020050201
SB2017111654
and 2 more
#VU10565 - Double Free
CVE-2017-16820
CWE-415 Low
No
No
- 14.02.2018 SB2018010420
SB2018021414
SB2018032103
and 9 more
#VU9765 - Exposure of sensitive information to an unauthorized actor
CVE-2017-16994
CWE-200 Low
No
No
- 26.12.2017 SB2017122104
SB2017122211
SB2017122105
and 7 more
#VU9764 - Use After Free
CVE-2017-15115
CWE-416 Low
No
No
- 26.12.2017 SB2017122104
SB2017122211
SB2017122105
and 16 more
#VU9571 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2017-16641
CWE-78 High
No
No
- 07.12.2017 SB2017111504
SB2017112305
SB2017111909
and 3 more
#VU9570 - Improper input validation
CVE-2017-16660
CWE-20 High
No
No
- 07.12.2017 SB2017111504
SB2017112305
SB2017111909
and 3 more
#VU9569 - Exposure of sensitive information to an unauthorized actor
CVE-2017-16661
CWE-200 Low
No
No
- 02.12.2017 SB2017111504
SB2017112305
SB2017111909
and 3 more
#VU37877 - Memory corruption
CVE-2017-16927
CWE-119 High
No
No
- 23.11.2017 SB2017112318
SB2017112410
SB2017112411
and 5 more
#VU9333 - Permissions, Privileges, and Access Controls
CVE-2017-15906
CWE-264 Low
No
No
- 15.11.2017 SB2017111501
SB2017111502
SB2018010803
and 14 more
#VU9338 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2017-16785
CWE-79 Low
No
No
- 14.11.2017 SB2017111504
SB2017112305
SB2017111909
and 3 more
#VU9109 - Cryptographic Issues
CVE-2017-3736
CWE-310 Low
No
No
- 02.11.2017 SB2017110221
SB2017110302
SB2017110401
and 34 more
#VU37991 - Improper input validation
CVE-2017-14992
CWE-20 Medium
No
No
- 01.11.2017 SB2017110108
SB2018011222
SB2017112325
and 2 more
#VU9038 - Memory corruption
CVE-2017-13803
CWE-119 High
No
No
- 01.11.2017 SB2017110101
SB2017110102
SB2017111603
and 5 more
#VU9036 - Memory corruption
CVE-2017-13798
CWE-119 High
Public exploit available
No
- 01.11.2017 SB2017110101
SB2017110102
SB2017111603
and 5 more
#VU9029 - Memory corruption
CVE-2017-13788
CWE-119 High
No
No
- 01.11.2017 SB2017110101
SB2017110102
SB2017111603
and 5 more
#VU33780 - Improper input validation
CVE-2017-16228
CWE-20 High
No
No
- 29.10.2017 SB2018080624
SB2017112720
SB2017112725
and 1 more
#VU8487 - Out-of-bounds read
CVE-2017-3735
CWE-125 Low
No
No
- 28.08.2017 SB2017082906
SB2017110401
SB2017110402
and 30 more
#VU38818 - Out-of-bounds read
CVE-2017-9847
CWE-125 Medium
No
No
- 24.06.2017 SB2017062402
SB2017112416
SB2017112417
and 1 more


Showing elements 21 - 40 out of 1035