Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 113 of 264
CVE-2021-45469P3HIGHCVSS 7.8v34v352021-12-23
CVE-2021-45469 [HIGH] CWE-125 CVE-2021-45469: In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds
In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.
nvd
CVE-2020-26121P3HIGHCVSS 7.5v332020-09-27
CVE-2020-26121 [HIGH] CWE-863 CVE-2020-26121: An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can i
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a mishandled distinction between an upload restriction and a create restriction. An attacker cannot leve
nvd
CVE-2015-5704P3HIGHCVSS 7.8v21v222017-09-25
CVE-2015-5704 [HIGH] CWE-77 CVE-2015-5704: scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell co
scripts/licensecheck.pl in devscripts before 2.15.7 allows local users to execute arbitrary shell commands.
nvd
CVE-2021-45417P3HIGHCVSS 7.8v352022-01-20
CVE-2021-45417 [HIGH] CWE-787 CVE-2021-45417: AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as X
AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.
nvd
CVE-2022-41322P3HIGHCVSS 7.8v36v372022-09-23
CVE-2022-41322 [HIGH] CWE-116 CVE-2022-41322: In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
nvd
CVE-2023-50010P3HIGHCVSS 7.8v38v39+1 more2024-04-19
CVE-2023-50010 [HIGH] CWE-120 CVE-2023-50010: FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demons
FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component.
nvd
CVE-2023-26081P3HIGHCVSS 7.5v372023-02-20
CVE-2023-26081 [HIGH] CWE-668 CVE-2023-26081: In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating pa
In Epiphany (aka GNOME Web) through 43.0, untrusted web content can trick users into exfiltrating passwords, because autofill occurs in sandboxed contexts.
nvd
CVE-2021-27803P3HIGHCVSS 7.5v32v33+1 more2021-02-26
CVE-2021-27803 [HIGH] CVE-2021-27803: A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-F
A vulnerability was discovered in how p2p/p2p_pd.c in wpa_supplicant before 2.10 processes P2P (Wi-Fi Direct) provision discovery requests. It could result in denial of service or other impact (potentially execution of arbitrary code), for an attacker within radio range.
nvd
CVE-2022-41751P3HIGHCVSS 7.8v35v36+1 more2022-10-17
CVE-2022-41751 [HIGH] CWE-78 CVE-2022-41751: Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
nvd
CVE-2022-30789P3HIGHCVSS 7.8v35v362022-05-26
CVE-2022-30789 [HIGH] CWE-787 CVE-2022-30789: A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
nvd
CVE-2022-30786P3HIGHCVSS 7.8v35v362022-05-26
CVE-2022-30786 [HIGH] CWE-787 CVE-2022-30786: A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G th
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
nvd
CVE-2022-30788P3HIGHCVSS 7.8v35v362022-05-26
CVE-2022-30788 [HIGH] CWE-787 CVE-2022-30788: A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
nvd
CVE-2023-43787P3HIGHCVSS 7.8v382023-10-10
CVE-2023-43787 [HIGH] CWE-122 CVE-2023-43787: A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. T
A vulnerability was found in libX11 due to an integer overflow within the XCreateImage() function. This flaw allows a local user to trigger an integer overflow and execute arbitrary code with elevated privileges.
nvd
CVE-2018-16867P3HIGHCVSS 7.8v292018-12-12
CVE-2018-16867 [HIGH] CWE-362 CVE-2018-16867: A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the
A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code executio
nvd
CVE-2020-15396P3HIGHCVSS 7.8v31v322020-06-30
CVE-2020-15396 [HIGH] CWE-362 CVE-2020-15396: In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-
In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.
nvd
CVE-2021-28952P3HIGHCVSS 7.8v32v33+1 more2021-03-20
CVE-2021-28952 [HIGH] CWE-120 CVE-2021-28952: An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire de
An issue was discovered in the Linux kernel through 5.11.8. The sound/soc/qcom/sdm845.c soundwire device driver has a buffer overflow when an unexpected port ID number is encountered, aka CID-1c668e1c0a0f. (This has been fixed in 5.12-rc4.)
nvd
CVE-2023-38552P3HIGHCVSS 7.5v37v38+1 more2023-10-18
CVE-2023-38552 [HIGH] CWE-345 CVE-2023-38552: When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the a
When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check.
Impacts:
This vulnerability affects all users using the experimental policy mechanism in all active
nvd
CVE-2024-0409P3HIGHCVSS 7.8v392024-01-18
CVE-2024-0409 [HIGH] CWE-787 CVE-2024-0409: A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong typ
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.
nvd
CVE-2022-3171P3HIGHCVSS 7.5v372022-10-12
CVE-2022-3171 [HIGH] CWE-20 CVE-2022-3171: A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.
A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be converted back-n-forth between mutable and immutable forms, resulting in pot
nvd
CVE-2021-38166P3HIGHCVSS 7.8v33v342021-08-07
CVE-2021-38166 [HIGH] CWE-190 CVE-2021-38166: In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-
In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.
nvd