Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 114 of 264
CVE-2021-3600P3HIGHCVSS 7.8v342024-01-08
CVE-2021-3600 [HIGH] CWE-125 CVE-2021-3600: It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds inf
It was discovered that the eBPF implementation in the Linux kernel did not properly track bounds information for 32 bit registers when performing div and mod operations. A local attacker could use this to possibly execute arbitrary code.
nvd
CVE-2020-15567P3HIGHCVSS 7.8v31v322020-07-07
CVE-2020-15567 [HIGH] CWE-362 CVE-2020-15567: An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or c
An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of non-atomic bitfield writes. Depending on the compiler version and optimisation
nvd
CVE-2022-2938P3HIGHCVSS 7.8v352022-08-23
CVE-2022-2938 [HIGH] CWE-416 CVE-2022-2938: A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the featu
A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects.
nvd
CVE-2022-42332P3HIGHCVSS 7.8v37v382023-03-21
CVE-2022-42332 [HIGH] CWE-416 CVE-2022-42332: x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translatio
x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory used for both shadow page tables as well as auxiliary data structures. To migrate or snapshot guests,
nvd
CVE-2021-28701P3HIGHCVSS 7.8v33v34+1 more2021-09-08
CVE-2021-28701 [HIGH] CWE-362 CVE-2021-28701: Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pa
Another race in XENMAPSPACE_grant_table handling Guests are permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, are de-allocated when a guest switches (back) from v2 to v1. Freeing such pages requires that the hypervi
nvd
CVE-2024-27018P3HIGHCVSS 7.8v38v39+1 more2024-05-01
CVE-2024-27018 [HIGH] CVE-2024-27018: In the Linux kernel, the following vulnerability has been resolved: netfilter: br_netfilter: skip c
In the Linux kernel, the following vulnerability has been resolved:
netfilter: br_netfilter: skip conntrack input hook for promisc packets
For historical reasons, when bridge device is in promisc mode, packets
that are directed to the taps follow bridge input hook path. This patch
adds a workaround to reset conntrack for these packets.
Jianbo Liu reports wa
nvd
CVE-2020-24386P3MEDIUMCVSS 6.8v322021-01-04
CVE-2020-24386 [MEDIUM] CVE-2020-24386: An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can
An issue was discovered in Dovecot before 2.3.13. By using IMAP IDLE, an authenticated attacker can trigger unhibernation via attacker-controlled parameters, leading to access to other users' email messages (and path disclosure).
nvd
CVE-2023-2135P3HIGHCVSS 7.5v36v37+1 more2023-04-19
CVE-2023-2135 [HIGH] CWE-416 CVE-2023-2135: Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who co
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-3551P3HIGHCVSS 7.8v33v342022-02-16
CVE-2021-3551 [HIGH] CWE-312 CVE-2021-3551: A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admi
A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2024-23835P3HIGHCVSS 7.5v38v392024-02-26
CVE-2024-23835 [HIGH] CWE-400 CVE-2024-23835: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.3, excessive memory use during pgsql parsing could lead to OOM-related crashes. This vulnerability is patched in 7.0.3. As workaround, users can disable the pgsql app layer parser.
nvd
CVE-2021-3571P3HIGHCVSS 7.1v33v342021-07-09
CVE-2021-3571 [HIGH] CWE-119 CVE-2021-3571: A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-e
A flaw was found in the ptp4l program of the linuxptp package. When ptp4l is operating on a little-endian architecture as a PTP transparent clock, a remote attacker could send a crafted one-step sync message to cause an information leak or crash. The highest threat from this vulnerability is to data confidentiality and system availability. This flaw aff
nvd
CVE-2010-2547P3HIGHCVSS 8.1v132010-08-05
CVE-2010-2547 [HIGH] CWE-416 CVE-2010-2547: Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote
Use-after-free vulnerability in kbx/keybox-blob.c in GPGSM in GnuPG 2.x through 2.0.16 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a certificate with a large number of Subject Alternate Names, which is not properly handled in a realloc operation when importing the certificate or verifying its sign
nvd
CVE-2015-4491P3MEDIUMCVSS 6.8v21v222015-08-16
CVE-2015-4491 [MEDIUM] CWE-189 CVE-2015-4491: Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, a
Integer overflow in the make_filter_table function in pixops/pixops.c in gdk-pixbuf before 2.31.5, as used in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Linux, Google Chrome on Linux, and other products, allows remote attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow and application crash
nvd
CVE-2009-3095P3MEDIUMCVSS 5.0v10v122009-09-08
CVE-2009-3095 [MEDIUM] CVE-2009-3095: The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access
The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.
nvd
CVE-2020-11033P3HIGHCVSS 7.2v31v322020-05-05
CVE-2020-11033 [HIGH] CWE-200 CVE-2020-11033: In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype wil
In GLPI from version 9.1 and before version 9.4.6, any API user with READ right on User itemtype will have access to full list of users when querying apirest.php/User. The response contains: - All api_tokens which can be used to do privileges escalations or read/update/delete data normally non accessible to the current user. - All personal_tokens can
nvd
CVE-2018-10811P3HIGHCVSS 7.5v282018-06-19
CVE-2018-10811 [HIGH] CWE-909 CVE-2018-10811: strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Va
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.
nvd
CVE-2010-4206P3HIGHCVSS 8.8v132010-11-06
CVE-2010-4206 [HIGH] CWE-787 CVE-2010-4206: Array index error in the FEBlend::apply function in WebCore/platform/graphics/filters/FEBlend.cpp in
Array index error in the FEBlend::apply function in WebCore/platform/graphics/filters/FEBlend.cpp in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted SVG document, related to effects in the application of
nvd
CVE-2019-8936P3HIGHCVSS 7.5v28v29+1 more2019-05-15
CVE-2019-8936 [HIGH] CWE-476 CVE-2019-8936: NTP through 4.2.8p12 has a NULL Pointer Dereference.
NTP through 4.2.8p12 has a NULL Pointer Dereference.
nvd
CVE-2020-12740P3CRITICALCVSS 9.1v31v322020-05-08
CVE-2020-12740 [CRITICAL] CWE-125 CVE-2020-12740: tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. Th
tcprewrite in Tcpreplay through 4.3.2 has a heap-based buffer over-read during a get_c operation. The issue is being triggered in the function get_ipv6_next() at common/get.c.
nvd
CVE-2019-10903P3HIGHCVSS 7.5v29v302019-04-09
CVE-2019-10903 [HIGH] CWE-125 CVE-2019-10903: In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. T
In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DCERPC SPOOLSS dissector could crash. This was addressed in epan/dissectors/packet-dcerpc-spoolss.c by adding a boundary check.
nvd