cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 105 of 264
CVE-2019-15151P3CRITICALCVSS 9.8v32v332019-08-18
CVE-2019-15151 [CRITICAL] CWE-415 CVE-2019-15151: AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h. AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.
nvd
CVE-2021-38512P3HIGHCVSS 7.5v342021-08-10
CVE-2021-38512 [HIGH] CWE-444 CVE-2021-38512: An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggli An issue was discovered in the actix-http crate before 3.0.0-beta.9 for Rust. HTTP/1 request smuggling (aka HRS) can occur, potentially leading to credential disclosure.
nvd
CVE-2021-38562P3HIGHCVSS 7.5v352021-10-18
CVE-2021-38562 [HIGH] CWE-203 CVE-2021-38562: Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
nvd
CVE-2020-15114P3HIGHCVSS 7.7v322020-08-06
CVE-2020-15114 [HIGH] CWE-400 CVE-2020-15114: In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic In etcd before versions 3.3.23 and 3.4.10, the etcd gateway is a simple TCP proxy to allow for basic service discovery and access. However, it is possible to include the gateway address as an endpoint. This results in a denial of service, since the endpoint can become stuck in a loop of requesting itself until there are no more available file descript
nvd
CVE-2023-50009P3HIGHCVSS 8.0v38v39+1 more2024-04-19
CVE-2023-50009 [HIGH] CWE-122 CVE-2023-50009: FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.
nvd
CVE-2022-3080P3HIGHCVSS 7.5v35v36+1 more2022-09-21
CVE-2022-3080 [HIGH] CWE-613 CVE-2022-3080: By sending specific queries to the resolver, an attacker can cause named to crash. By sending specific queries to the resolver, an attacker can cause named to crash.
nvd
CVE-2016-1238P3HIGHCVSS 7.8v23v242016-08-02
CVE-2016-1238 [HIGH] CWE-264 CVE-2016-1238: (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (1) cpan/Archive-Tar/bin/ptar, (2) cpan/Archive-Tar/bin/ptardiff, (3) cpan/Archive-Tar/bin/ptargrep, (4) cpan/CPAN/scripts/cpan, (5) cpan/Digest-SHA/shasum, (6) cpan/Encode/bin/enc2xs, (7) cpan/Encode/bin/encguess, (8) cpan/Encode/bin/piconv, (9) cpan/Encode/bin/ucmlint, (10) cpan/Encode/bin/unidump, (11) cpan/ExtUtils-MakeMaker/bin/instmodsh, (12) cpan
nvd
CVE-2021-28116P3MEDIUMCVSS 5.3v33v342021-03-09
CVE-2021-28116 [MEDIUM] CWE-125 CVE-2021-28116: Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure beca Squid through 4.14 and 5.x through 5.0.5, in some configurations, allows information disclosure because of an out-of-bounds read in WCCP protocol data. This can be leveraged as part of a chain for remote code execution as nobody.
nvd
CVE-2023-38200P3HIGHCVSS 7.5v382023-07-24
CVE-2023-38200 [HIGH] CWE-400 CVE-2023-38200: A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a rem A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.
nvd
CVE-2020-25670P3HIGHCVSS 7.8v32v33+1 more2021-05-26
CVE-2020-25670 [HIGH] CWE-416 CVE-2020-25670: A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after- A vulnerability was found in Linux Kernel where refcount leak in llcp_sock_bind() causing use-after-free which might lead to privilege escalations.
nvd
CVE-2020-28924P3HIGHCVSS 7.5v332020-11-19
CVE-2020-28924 [HIGH] CWE-331 CVE-2020-28924: An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, t An issue was discovered in Rclone before 1.53.3. Due to the use of a weak random number generator, the password generator has been producing weak passwords with much less entropy than advertised. The suggested passwords depend deterministically on the time the second rclone was started. This limits the entropy of the passwords enormously. These passwo
nvd
CVE-2021-37576P3HIGHCVSS 7.8v33v342021-07-26
CVE-2021-37576 [HIGH] CWE-787 CVE-2021-37576: arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM arch/powerpc/kvm/book3s_rtas.c in the Linux kernel through 5.13.5 on the powerpc platform allows KVM guest OS users to cause host OS memory corruption via rtas_args.nargs, aka CID-f62f3c20647e.
nvd
CVE-2021-28091P3HIGHCVSS 7.5v33v342021-06-04
CVE-2021-28091 [HIGH] CWE-347 CVE-2021-28091: Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature. Lasso all versions prior to 2.7.0 has improper verification of a cryptographic signature.
nvd
CVE-2023-39351P3HIGHCVSS 7.5v37v38+1 more2023-08-31
CVE-2023-39351 [HIGH] CWE-476 CVE-2023-39351: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions of FreeRDP are subject to a Null Pointer Dereference leading a crash in the RemoteFX (rfx) handling. Inside the `rfx_process_message_tileset` function, the program allocates tiles using `rfx_allocate_tiles` for the number of numT
nvd
CVE-2024-1676P3MEDIUMCVSS 5.4v38v392024-02-21
CVE-2024-1676 [MEDIUM] CWE-79 CVE-2024-1676: Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-29217P3HIGHCVSS 7.5v35v362022-05-24
CVE-2022-29217 [HIGH] CWE-327 CVE-2022-29217: PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorith PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported. The application can specify `jwt.algorithms.get_default_algorithms()` to get
nvd
CVE-2020-25671P3HIGHCVSS 7.8v32v33+1 more2021-05-26
CVE-2020-25671 [HIGH] CWE-416 CVE-2020-25671: A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use- A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.
nvd
CVE-2022-1055P3HIGHCVSS 7.8v352022-03-29
CVE-2022-1055 [HIGH] CWE-416 CVE-2022-1055: A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to g A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a local attacker to gain privilege escalation. The exploit requires unprivileged user namespaces. We recommend upgrading past commit 04c2a47ffb13c29778e2a14e414ad4cb5a5db4b5
nvd
CVE-2021-33289P3HIGHCVSS 7.8v33v352021-09-07
CVE-2021-33289 [HIGH] CWE-787 CVE-2021-33289: In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.
nvd
CVE-2021-33285P3HIGHCVSS 7.8v33v34+1 more2021-09-07
CVE-2021-33285 [HIGH] CWE-787 CVE-2021-33285: In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is
nvd
Fedoraproject Fedora vulnerabilities | cvebase