Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 109 of 264
CVE-2021-4185P3HIGHCVSS 7.5v34v352021-12-30
CVE-2021-4185 [HIGH] CWE-835 CVE-2021-4185: Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service
Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4184P3HIGHCVSS 7.5v34v352021-12-30
CVE-2021-4184 [HIGH] CWE-835 CVE-2021-4184: Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial o
Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-4181P3HIGHCVSS 7.5v34v352021-12-30
CVE-2021-4181 [HIGH] CWE-125 CVE-2021-4181: Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service
Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-21202P3HIGHCVSS 8.6v32v33+1 more2021-04-26
CVE-2021-21202 [HIGH] CWE-416 CVE-2021-21202: Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convince
Use after free in extensions in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2024-38276P3HIGHCVSS 8.8v39v402024-06-18
CVE-2024-38276 [HIGH] CWE-352 CVE-2024-38276: Incorrect CSRF token checks resulted in multiple CSRF risks.
Incorrect CSRF token checks resulted in multiple CSRF risks.
nvd
CVE-2016-3960P3HIGHCVSS 8.8v22v23+1 more2016-04-19
CVE-2016-3960 [HIGH] CWE-264 CVE-2016-3960: Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a deni
Integer overflow in the x86 shadow pagetable code in Xen allows local guest OS users to cause a denial of service (host crash) or possibly gain privileges by shadowing a superpage mapping.
nvd
CVE-2021-21207P3HIGHCVSS 8.6v32v33+1 more2021-04-26
CVE-2021-21207 [HIGH] CWE-416 CVE-2021-21207: Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced
Use after free in IndexedDB in Google Chrome prior to 90.0.4430.72 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2020-15503P3HIGHCVSS 7.5v31v322020-07-02
CVE-2020-15503 [HIGH] CWE-20 CVE-2020-15503: LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, p
LibRaw before 0.20-RC1 lacks a thumbnail size range check. This affects decoders/unpack_thumb.cpp, postprocessing/mem_image.cpp, and utils/thumb_utils.cpp. For example, malloc(sizeof(libraw_processed_image_t)+T.tlength) occurs without validating T.tlength.
nvd
CVE-2015-8389P3CRITICALCVSS 9.8v222015-12-02
CVE-2015-8389 [CRITICAL] CWE-119 CVE-2015-8389: PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote at
PCRE before 8.38 mishandles the /(?:|a|){100}x/ pattern and related patterns, which allows remote attackers to cause a denial of service (infinite recursion) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
nvd
CVE-2020-35680P3HIGHCVSS 7.5v32v332020-12-24
CVE-2020-35680 [HIGH] CWE-476 CVE-2020-35680: smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers t
smtpd/lka_filter.c in OpenSMTPD before 6.8.0p1, in certain configurations, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted pattern of client activity, because the filter state machine does not properly maintain the I/O channel between the SMTP engine and the filters layer.
nvd
CVE-2021-25214P3MEDIUMCVSS 6.5v33v342021-04-29
CVE-2021-25214 [MEDIUM] CWE-617 CVE-2021-25214: In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S
In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the
nvd
CVE-2014-1519P3CRITICALCVSS 9.3v19v202014-04-30
CVE-2014-1519 [CRITICAL] CVE-2014-1519: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0 and SeaMon
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2020-6554P3HIGHCVSS 8.6v332020-09-21
CVE-2020-6554 [HIGH] CWE-416 CVE-2020-6554: Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to po
Use after free in extensions in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2021-21381P3HIGHCVSS 8.2v33v342021-03-11
CVE-2021-21381 [HIGH] CWE-74 CVE-2021-21381: Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux.
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In Flatpack since version 0.9.4 and before version 1.10.2 has a vulnerability in the "file forwarding" feature which can be used by an attacker to gain access to files that would not ordinarily be allowed by the app's permissions. By putting the special
nvd
CVE-2014-1518P3HIGHCVSS 8.8v19v202014-04-30
CVE-2014-1518 [HIGH] CVE-2014-1518: Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox E
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
nvd
CVE-2019-16865P3HIGHCVSS 7.5v30v312019-10-04
CVE-2019-16865 [HIGH] CWE-770 CVE-2019-16865: An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files,
An issue was discovered in Pillow before 6.2.0. When reading specially crafted invalid image files, the library can either allocate very large amounts of memory or take an extremely long period of time to process the image.
nvd
CVE-2021-4190P3HIGHCVSS 7.5v34v352021-12-30
CVE-2021-4190 [HIGH] CWE-834 CVE-2021-4190: Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection o
Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-41772P3HIGHCVSS 7.5v34v352021-11-08
CVE-2021-41772 [HIGH] CWE-20 CVE-2021-41772: Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP
Go before 1.16.10 and 1.17.x before 1.17.3 allows an archive/zip Reader.Open panic via a crafted ZIP archive containing an invalid name or an empty filename field.
nvd
CVE-2019-19246P3HIGHCVSS 7.5v312019-11-25
CVE-2019-19246 [HIGH] CWE-125 CVE-2019-19246: Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read
Oniguruma through 6.9.3, as used in PHP 7.3.x and other products, has a heap-based buffer over-read in str_lower_case_match in regexec.c.
nvd
CVE-2021-39140P3MEDIUMCVSS 6.3v33v34+1 more2021-08-23
CVE-2021-39140 [MEDIUM] CWE-502 CVE-2021-39140: XStream is a simple library to serialize objects to XML and back again. In affected versions this vu
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. No user is affected,
nvd