cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 103 of 264
CVE-2013-5613P3CRITICALCVSS 9.8v18v19+1 more2013-12-11
CVE-2013-5613 [CRITICAL] CWE-416 CVE-2013-5613: Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox be Use-after-free vulnerability in the PresShell::DispatchSynthMouseMove function in Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via vectors involving synthetic mouse movement, related
nvd
CVE-2009-1890P3HIGHCVSS 7.1v112009-07-05
CVE-2009-1890 [HIGH] CWE-400 CVE-2009-1890: The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server The stream_reqbody_cl function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server before 2.3.3, when a reverse proxy is configured, does not properly handle an amount of streamed data that exceeds the Content-Length value, which allows remote attackers to cause a denial of service (CPU consumption) via crafted requests.
nvd
CVE-2010-5304P3HIGHCVSS 7.5v19v20+1 more2020-02-05
CVE-2010-5304 [HIGH] CWE-476 CVE-2010-5304: A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain Clien A NULL pointer dereference flaw was found in the way LibVNCServer before 0.9.9 handled certain ClientCutText message. A remote attacker could use this flaw to crash the VNC server by sending a specially crafted ClientCutText message from a VNC client.
nvd
CVE-2020-8622P3MEDIUMCVSS 6.5v31v322020-08-21
CVE-2020-8622 [MEDIUM] CWE-617 CVE-2020-8622: In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the se
nvd
CVE-2021-38593P3HIGHCVSS 7.5v35v362021-08-12
CVE-2021-38593 [HIGH] CWE-787 CVE-2021-38593: Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath Qt 5.x before 5.15.6 and 6.x through 6.1.2 has an out-of-bounds write in QOutlineMapper::convertPath (called from QRasterPaintEngine::fill and QPaintEngineEx::stroke).
nvd
CVE-2020-13574P3HIGHCVSS 7.5v33v342021-02-10
CVE-2020-13574 [HIGH] CWE-476 CVE-2020-13574: A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2. A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2020-13577P3HIGHCVSS 7.5v33v342021-02-10
CVE-2020-13577 [HIGH] CWE-476 CVE-2020-13577: A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2. A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2020-13578P3HIGHCVSS 7.5v33v342021-02-10
CVE-2020-13578 [HIGH] CWE-476 CVE-2020-13578: A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2. A denial-of-service vulnerability exists in the WS-Security plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2021-21205P3HIGHCVSS 8.1v32v33+1 more2021-04-26
CVE-2021-21205 [HIGH] CVE-2021-21205: Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed Insufficient policy enforcement in navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-25693P3HIGHCVSS 8.1v32v33+1 more2020-12-03
CVE-2020-25693 [HIGH] CWE-190 CVE-2020-25693: A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overfl A flaw was found in CImg in versions prior to 2.9.3. Integer overflows leading to heap buffer overflows in load_pnm() can be triggered by a specially crafted input file processed by CImg, which can lead to an impact to application availability or data integrity.
nvd
CVE-2021-41819P3HIGHCVSS 7.5v34v352022-01-01
CVE-2021-41819 [HIGH] CWE-565 CVE-2021-41819: CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affe CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
nvd
CVE-2018-10771P3CRITICALCVSS 9.8v30v31+1 more2018-05-07
CVE-2018-10771 [CRITICAL] CWE-787 CVE-2018-10771: Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows rem Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
nvd
CVE-2019-14818P3HIGHCVSS 7.5v312019-11-14
CVE-2019-14818 [HIGH] CWE-401 CVE-2019-14818: A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18 A flaw was found in all dpdk version 17.x.x before 17.11.8, 16.x.x before 16.11.10, 18.x.x before 18.11.4 and 19.x.x before 19.08.1 where a malicious master, or a container with access to vhost_user socket, can send specially crafted VRING_SET_NUM messages, resulting in a memory leak including file descriptors. This flaw could lead to a denial of serv
nvd
CVE-2022-21681P3HIGHCVSS 7.5v362022-01-14
CVE-2022-21681 [HIGH] CWE-400 CVE-2022-21681: Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.re Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issu
nvd
CVE-2019-16785P3HIGHCVSS 7.5v30v312019-12-20
CVE-2019-16785 [HIGH] CWE-444 CVE-2019-16785: Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the l Waitress through version 1.3.1 implemented a "MAY" part of the RFC7230 which states: "Although the line terminator for the start-line and header fields is the sequence CRLF, a recipient MAY recognize a single LF as a line terminator and ignore any preceding CR." Unfortunately if a front-end server does not parse header fields with an LF the same way a
nvd
CVE-2019-7639P3HIGHCVSS 8.1v28v292019-02-08
CVE-2019-7639 [HIGH] CWE-863 CVE-2019-7639: An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to y An issue was discovered in gsi-openssh-server 7.9p1 on Fedora 29. If PermitPAMUserChange is set to yes in the /etc/gsissh/sshd_config file, logins succeed with a valid username and an incorrect password, even though a failure entry is recorded in the /var/log/messages file.
nvd
CVE-2019-9854P3HIGHCVSS 7.8v292019-09-06
CVE-2019-9854 [HIGH] CVE-2019-9854: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on v LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2019-9852, to avoid a d
nvd
CVE-2019-9852P3HIGHCVSS 7.8v292019-08-15
CVE-2019-9852 [HIGH] CWE-116 CVE-2019-9852: LibreOffice has a feature where documents can specify that pre-installed macros can be executed on v LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of the LibreOffice install. Protection was added, to address CVE-2018-16858, to
nvd
CVE-2020-28033P3HIGHCVSS 7.5v31v32+1 more2020-11-02
CVE-2020-28033 [HIGH] CVE-2020-28033: WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated WordPress before 5.5.2 mishandles embeds from disabled sites on a multisite network, as demonstrated by allowing a spam embed.
nvd
CVE-2008-3424P3HIGHCVSS 7.5v92008-07-31
CVE-2008-3424 [HIGH] CWE-863 CVE-2008-3424: Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRI Condor before 7.0.4 does not properly handle wildcards in the ALLOW_WRITE, DENY_WRITE, HOSTALLOW_WRITE, or HOSTDENY_WRITE configuration variables in authorization policy lists, which might allow remote attackers to bypass intended access restrictions.
nvd
Fedoraproject Fedora vulnerabilities | cvebase