cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 100 of 264
CVE-2015-7202P3CRITICALCVSS 10.0v22v232015-12-16
CVE-2015-7202 [CRITICAL] CWE-119 CVE-2015-7202: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remo Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 43.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2019-7574P3HIGHCVSS 8.8v312019-02-07
CVE-2019-7574 [HIGH] CWE-125 CVE-2019-7574: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in IMA_ADPCM_decode in audio/SDL_wave.c.
nvd
CVE-2019-7572P3HIGHCVSS 8.8v312019-02-07
CVE-2019-7572 [HIGH] CWE-125 CVE-2019-7572: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_AD SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a buffer over-read in IMA_ADPCM_nibble in audio/SDL_wave.c.
nvd
CVE-2022-3592P3MEDIUMCVSS 6.5v36v372023-01-12
CVE-2022-3592 [MEDIUM] CWE-61 CVE-2022-3592: A symlink following vulnerability was found in Samba, where a user can create a symbolic link that w A symlink following vulnerability was found in Samba, where a user can create a symbolic link that will make 'smbd' escape the configured share path. This flaw allows a remote user with access to the exported part of the file system under a share via SMB1 unix extensions or NFS to create symlinks to files outside the 'smbd' configured share path and ga
nvd
CVE-2015-2782P3HIGHCVSS 7.5v20v21+1 more2015-04-08
CVE-2015-2782 [HIGH] CWE-119 CVE-2015-2782: Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of ser Buffer overflow in Open-source ARJ archiver 3.10.22 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted ARJ archive.
nvd
CVE-2018-20406P3HIGHCVSS 7.5v28v29+1 more2018-12-23
CVE-2018-20406 [HIGH] CWE-190 CVE-2018-20406: Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that Modules/_pickle.c in Python before 3.7.1 has an integer overflow via a large LONG_BINPUT value that is mishandled during a "resize to twice the size" attempt. This issue might cause memory exhaustion, but is only relevant if the pickle format is used for serializing tens or hundreds of gigabytes of data. This issue is fixed in: v3.4.10, v3.4.10rc1; v3.
nvd
CVE-2019-10896P3HIGHCVSS 7.5v29v302019-04-09
CVE-2019-10896 [HIGH] CWE-787 CVE-2019-10896: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was add In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.
nvd
CVE-2014-9674P3HIGHCVSS 7.5v20v212015-02-08
CVE-2014-9674 [HIGH] CVE-2014-9674: The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding t The Mac_Read_POST_Resource function in base/ftobjs.c in FreeType before 2.5.4 proceeds with adding to length values without validating the original values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Mac font.
nvd
CVE-2007-0455P3HIGHCVSS 7.5v13v142007-01-30
CVE-2007-0455 [HIGH] CWE-120 CVE-2007-0455: Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlie Buffer overflow in the gdImageStringFTEx function in gdft.c in GD Graphics Library 2.0.33 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a crafted string with a JIS encoded font.
nvd
CVE-2015-3148P3MEDIUMCVSS 5.0v21v222015-04-24
CVE-2015-3148 [MEDIUM] CWE-284 CVE-2015-3148: cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, w cURL and libcurl 7.10.6 through 7.41.0 do not properly re-use authenticated Negotiate connections, which allows remote attackers to connect as other users via a request.
nvd
CVE-2019-10894P3HIGHCVSS 7.5v29v302019-04-09
CVE-2019-10894 [HIGH] CWE-617 CVE-2019-10894: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called.
nvd
CVE-2021-40839P3HIGHCVSS 7.5v34v352021-09-10
CVE-2021-40839 [HIGH] CWE-835 CVE-2021-40839: The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as v The rencode package through 1.0.6 for Python allows an infinite loop in typecode decoding (such as via ;\x2f\x7f), enabling a remote attack that consumes CPU and memory.
nvd
CVE-2015-5194P3HIGHCVSS 7.5v21v222017-07-21
CVE-2015-5194 [HIGH] CWE-20 CVE-2015-5194: The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attacke The log_config_command function in ntp_parser.y in ntpd in NTP before 4.2.7p42 allows remote attackers to cause a denial of service (ntpd crash) via crafted logconfig commands.
nvd
CVE-2018-19591P3HIGHCVSS 7.5v28v292018-12-04
CVE-2018-19591 [HIGH] CWE-20 CVE-2018-19591: In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via In the GNU C Library (aka glibc or libc6) through 2.28, attempting to resolve a crafted hostname via getaddrinfo() leads to the allocation of a socket descriptor that is not closed. This is related to the if_nametoindex() function.
nvd
CVE-2024-23672P3MEDIUMCVSS 6.3v39v402024-03-13
CVE-2024-23672 [MEDIUM] CWE-459 CVE-2024-23672: Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSock Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Olde
nvd
CVE-2015-8868P3HIGHCVSS 7.8v232016-05-06
CVE-2015-8868 [HIGH] CWE-119 CVE-2015-8868: Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler befor Heap-based buffer overflow in the ExponentialFunction::ExponentialFunction function in Poppler before 0.40.0 allows remote attackers to cause a denial of service (memory corruption and crash) or possibly execute arbitrary code via an invalid blend mode in the ExtGState dictionary in a crafted PDF document.
nvd
CVE-2014-1477P3CRITICALCVSS 9.8v19v202014-02-06
CVE-2014-1477 [CRITICAL] CVE-2014-1477: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox E Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2020-5310P3HIGHCVSS 8.8v30v312020-01-03
CVE-2020-5310 [HIGH] CWE-190 CVE-2020-5310: libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to real libImaging/TiffDecode.c in Pillow before 6.2.2 has a TIFF decoding integer overflow, related to realloc.
nvd
CVE-2019-14734P3HIGHCVSS 8.8v32v332019-08-07
CVE-2019-14734 [HIGH] CWE-787 CVE-2019-14734: AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp. AdPlug 2.3.1 has multiple heap-based buffer overflows in CmtkLoader::load() in mtk.cpp.
nvd
CVE-2018-12545P3HIGHCVSS 7.5v282019-03-27
CVE-2018-12545 [HIGH] CWE-400 CVE-2018-12545: In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions i In Eclipse Jetty version 9.3.x and 9.4.x, the server is vulnerable to Denial of Service conditions if a remote client sends either large SETTINGs frames container containing many settings, or many small SETTINGs frames. The vulnerability is due to the additional CPU and memory allocations required to handle changed settings.
nvd
Fedoraproject Fedora vulnerabilities | cvebase