Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 117 of 264
CVE-2021-33503P3HIGHCVSS 7.5v33v342021-06-29
CVE-2021-33503 [HIGH] CWE-400 CVE-2021-33503: An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ charact
An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.
nvd
CVE-2019-9631P3CRITICALCVSS 9.8v28v29+1 more2019-03-08
CVE-2019-9631 [CRITICAL] CWE-125 CVE-2019-9631: Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter
Poppler 0.74.0 has a heap-based buffer over-read in the CairoRescaleBox.cc downsample_row_box_filter function.
nvd
CVE-2014-9328P3HIGHCVSS 7.5v20v212015-02-03
CVE-2014-9328 [HIGH] CWE-119 CVE-2014-9328: ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer f
ClamAV before 0.98.6 allows remote attackers to have unspecified impact via a crafted upack packer file, related to a "heap out of bounds condition."
nvd
CVE-2013-4357P3HIGHCVSS 7.5v18v192019-12-31
CVE-2013-4357 [HIGH] CWE-120 CVE-2013-4357: The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use
The eglibc package before 2.14 incorrectly handled the getaddrinfo() function. An attacker could use this issue to cause a denial of service.
nvd
CVE-2021-41817P3HIGHCVSS 7.5v34v352022-01-01
CVE-2021-41817 [HIGH] CWE-1333 CVE-2021-41817: Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
nvd
CVE-2020-13164P3HIGHCVSS 7.5v31v322020-05-19
CVE-2020-13164 [HIGH] CWE-674 CVE-2020-13164: In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. Th
In Wireshark 3.2.0 to 3.2.3, 3.0.0 to 3.0.10, and 2.6.0 to 2.6.16, the NFS dissector could crash. This was addressed in epan/dissectors/packet-nfs.c by preventing excessive recursion, such as for a cycle in the directory graph on a filesystem.
nvd
CVE-2020-26575P3HIGHCVSS 7.5v32v332020-10-06
CVE-2020-26575 [HIGH] CWE-835 CVE-2020-26575: In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinit
In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.
nvd
CVE-2020-9428P3HIGHCVSS 7.5v30v31+1 more2020-02-27
CVE-2020-9428 [HIGH] CWE-125 CVE-2020-9428: In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. Thi
In Wireshark 3.2.0 to 3.2.1, 3.0.0 to 3.0.8, and 2.6.0 to 2.6.14, the EAP dissector could crash. This was addressed in epan/dissectors/packet-eap.c by using more careful sscanf parsing.
nvd
CVE-2021-27219P3HIGHCVSS 7.5v33v342021-02-15
CVE-2021-27219 [HIGH] CWE-681 CVE-2021-27219: An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_n
An issue was discovered in GNOME GLib before 2.66.6 and 2.67.x before 2.67.3. The function g_bytes_new has an integer overflow on 64-bit platforms due to an implicit cast from 64 bits to 32 bits. The overflow could potentially lead to memory corruption.
nvd
CVE-2023-36053P3HIGHCVSS 7.5v37v382023-07-03
CVE-2023-36053 [HIGH] CWE-1333 CVE-2023-36053: In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
nvd
CVE-2018-7262P3HIGHCVSS 7.5v272018-03-19
CVE-2018-7262 [HIGH] CWE-476 CVE-2018-7262: In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in
In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.
nvd
CVE-2020-14422P3MEDIUMCVSS 5.9v31v322020-06-18
CVE-2020-14422 [MEDIUM] CWE-330 CVE-2020-14422: Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IP
Lib/ipaddress.py in Python through 3.8.3 improperly computes hash values in the IPv4Interface and IPv6Interface classes, which might allow a remote attacker to cause a denial of service if an application is affected by the performance of a dictionary containing IPv4Interface or IPv6Interface objects, and this attacker can cause many dictionary entri
nvd
CVE-2022-27405P3HIGHCVSS 7.5v34v35+1 more2022-04-22
CVE-2022-27405 [HIGH] CWE-125 CVE-2022-27405: FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation vi
FreeType commit 53dfdcd8198d2b3201a23c4bad9190519ba918db was discovered to contain a segmentation violation via the function FNT_Size_Request.
nvd
CVE-2022-41556P3HIGHCVSS 7.5v352022-10-06
CVE-2022-41556 [HIGH] CWE-401 CVE-2022-41556: A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of mod_fastcgi is, for example, affected. This is fixed in 1.4.67.
nvd
CVE-2015-6566P3HIGHCVSS 8.4v212016-01-11
CVE-2015-6566 [HIGH] CWE-59 CVE-2015-6566: zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain pr
zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.
nvd
CVE-2022-1629P3HIGHCVSS 7.8v34v352022-05-10
CVE-2022-1629 [HIGH] CWE-126 CVE-2022-1629: Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vu
Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution
nvd
CVE-2022-38177P3HIGHCVSS 7.5v35v36+1 more2022-09-21
CVE-2022-38177 [HIGH] CWE-401 CVE-2022-38177: By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker ca
By spoofing the target resolver with responses that have a malformed ECDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
nvd
CVE-2019-8075P3HIGHCVSS 7.5v32v332019-09-27
CVE-2019-8075 [HIGH] CVE-2019-8075: Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerab
Adobe Flash Player version 32.0.0.192 and earlier versions have a Same Origin Policy Bypass vulnerability. Successful exploitation could lead to Information Disclosure in the context of the current user.
nvd
CVE-2022-0629P3HIGHCVSS 7.8v34v352022-02-17
CVE-2022-0629 [HIGH] CWE-121 CVE-2022-0629: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-38178P3HIGHCVSS 7.5v35v36+1 more2022-09-21
CVE-2022-38178 [HIGH] CWE-401 CVE-2022-38178: By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker ca
By spoofing the target resolver with responses that have a malformed EdDSA signature, an attacker can trigger a small memory leak. It is possible to gradually erode available memory to the point where named crashes for lack of resources.
nvd