Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 104 of 264
CVE-2022-23946P3HIGHCVSS 7.8v352022-02-04
CVE-2022-23946 [HIGH] CWE-121 CVE-2022-23946: A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNum
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2023-4431P3HIGHCVSS 8.1v37v38+1 more2023-08-23
CVE-2023-4431 [HIGH] CWE-125 CVE-2023-4431: Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attac
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2019-11494P3HIGHCVSS 7.5v29v302019-05-08
CVE-2019-11494 [HIGH] CWE-476 CVE-2019-11494: In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the c
In the IMAP Server in Dovecot 2.3.3 through 2.3.5.2, the submission-login service crashes when the client disconnects prematurely during the AUTH command.
nvd
CVE-2021-46669P3HIGHCVSS 7.5v35v362022-02-01
CVE-2021-46669 [HIGH] CWE-416 CVE-2021-46669: MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BI
MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.
nvd
CVE-2022-23804P3HIGHCVSS 7.8v352022-02-16
CVE-2022-23804 [HIGH] CWE-121 CVE-2022-23804: A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCo
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2022-23803P3HIGHCVSS 7.8v352022-02-16
CVE-2022-23803 [HIGH] CWE-121 CVE-2022-23803: A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCo
A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2019-16236P3HIGHCVSS 7.5v29v30+1 more2019-09-11
CVE-2019-16236 [HIGH] CWE-862 CVE-2019-16236: Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
Dino before 2019-09-10 does not check roster push authorization in module/roster/module.vala.
nvd
CVE-2021-33560P3HIGHCVSS 7.5v33v342021-06-08
CVE-2021-33560 [HIGH] CWE-203 CVE-2021-33560: Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponen
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
nvd
CVE-2020-17367P3HIGHCVSS 7.8v31v322020-08-11
CVE-2020-17367 [HIGH] CWE-88 CVE-2020-17367: Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, wh
Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.
nvd
CVE-2016-1232P3HIGHCVSS 7.5v22v232016-01-12
CVE-2016-1232 [HIGH] CVE-2016-1232: The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the sec
The mod_dialback module in Prosody before 0.9.9 does not properly generate random values for the secret token for server-to-server dialback authentication, which makes it easier for attackers to spoof servers via a brute force attack.
nvd
CVE-2021-31204P3HIGHCVSS 7.8v32v33+1 more2021-05-11
CVE-2021-31204 [HIGH] CVE-2021-31204: .NET and Visual Studio Elevation of Privilege Vulnerability
.NET and Visual Studio Elevation of Privilege Vulnerability
nvd
CVE-2012-1155P3HIGHCVSS 7.5v15v16+1 more2019-11-14
CVE-2012-1155 [HIGH] CWE-200 CVE-2012-1155: Moodle has a database activity export permission issue where the export function of the database act
Moodle has a database activity export permission issue where the export function of the database activity module exports all entries even those from groups the user does not belong to
nvd
CVE-2020-27828P3HIGHCVSS 7.8v32v332020-12-11
CVE-2020-27828 [HIGH] CWE-20 CVE-2020-27828: There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper
There's a flaw in jasper's jpc encoder in versions prior to 2.0.23. Crafted input provided to jasper by an attacker could cause an arbitrary out-of-bounds write. This could potentially affect data confidentiality, integrity, or application availability.
nvd
CVE-2017-9104P3CRITICALCVSS 9.8v31v322020-06-18
CVE-2017-9104 [CRITICAL] CWE-400 CVE-2017-9104: An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is
An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
nvd
CVE-2024-28757P3HIGHCVSS 7.5v38v39+1 more2024-03-10
CVE-2024-28757 [HIGH] CWE-776 CVE-2024-28757: libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
nvd
CVE-2019-3885P3HIGHCVSS 7.5v302019-04-18
CVE-2019-3885 [HIGH] CWE-416 CVE-2019-3885: A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in
A use-after-free flaw was found in pacemaker up to and including version 2.0.1 which could result in certain sensitive information to be leaked via the system logs.
nvd
CVE-2023-44488P3HIGHCVSS 7.5v372023-09-30
CVE-2023-44488 [HIGH] CWE-755 CVE-2023-44488: VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
VP9 in libvpx before 1.13.1 mishandles widths, leading to a crash related to encoding.
nvd
CVE-2020-29661P3HIGHCVSS 7.8v32v332020-12-09
CVE-2020-29661 [HIGH] CWE-416 CVE-2020-29661: A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/
A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.
nvd
CVE-2021-45116P3HIGHCVSS 7.5v352022-01-05
CVE-2021-45116 [HIGH] CWE-20 CVE-2021-45116: An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to
An issue was discovered in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1. Due to leveraging the Django Template Language's variable resolution logic, the dictsort template filter was potentially vulnerable to information disclosure, or an unintended method call, if passed a suitably crafted key.
nvd
CVE-2016-7966P3HIGHCVSS 7.3v252016-12-23
CVE-2016-7966 [HIGH] CWE-94 CVE-2016-7966: Through a malicious URL that contained a quote character it was possible to inject HTML code in KMai
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML, which greatly reduces the available HTML functionality. Although it is possible to include an HTML comment indicato
nvd