Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 118 of 264
CVE-2021-28041P3HIGHCVSS 7.1v33v342021-03-05
CVE-2021-28041 [HIGH] CWE-415 CVE-2021-28041: ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenario
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
nvd
CVE-2022-2000P3HIGHCVSS 7.8v352022-06-09
CVE-2022-2000 [HIGH] CWE-787 CVE-2022-2000: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2020-13575P3HIGHCVSS 7.5v33v342021-02-10
CVE-2020-13575 [HIGH] CWE-476 CVE-2020-13575: A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP
A denial-of-service vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2021-32920P3HIGHCVSS 7.5v32v33+1 more2021-05-13
CVE-2021-32920 [HIGH] CVE-2021-32920: Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation reque
Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.
nvd
CVE-2021-32740P3HIGHCVSS 7.5v33v342021-07-06
CVE-2021-32740 [HIGH] CWE-400 CVE-2021-32740: Addressable is an alternative implementation to the URI implementation that is part of Ruby's standa
Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a maliciously crafted template may result in uncontrolled resource consumption, leadi
nvd
CVE-2017-9108P3HIGHCVSS 7.5v31v322020-06-18
CVE-2017-9108 [HIGH] CWE-119 CVE-2017-9108: An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin
An issue was discovered in adns before 1.5.2. adnshost mishandles a missing final newline on a stdin read. It is wrong to increment used as well as setting r, since used is incremented according to r, later. Rather one should be doing what read() would have done. Without this fix, adnshost may read and process one byte beyond the buffer, perhaps crashin
nvd
CVE-2019-19583P3HIGHCVSS 7.5v30v312019-12-11
CVE-2019-19583 [HIGH] CVE-2019-19583: An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial
An issue was discovered in Xen through 4.12.x allowing x86 HVM/PVH guest OS users to cause a denial of service (guest OS crash) because VMX VMEntry checks mishandle a certain case. Please see XSA-260 for background on the MovSS shadow. Please see XSA-156 for background on the need for #DB interception. The VMX VMEntry checks do not like the exact combination o
nvd
CVE-2008-5021P3CRITICALCVSS 9.3v8v92008-11-13
CVE-2008-5021 [CRITICAL] CWE-362 CVE-2008-5021: nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.
nsFrameManager in Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by modifying properties of a file input element while it is still being initialized, then using the blur method to a
nvd
CVE-2020-35376P3HIGHCVSS 7.5v32v332020-12-26
CVE-2020-35376 [HIGH] CWE-787 CVE-2020-35376: Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font ch
Xpdf 4.02 allows stack consumption because of an incorrect subroutine reference in a Type 1C font charstring, related to the FoFiType1C::getOp() function.
nvd
CVE-2022-0586P3HIGHCVSS 7.5v34v352022-02-14
CVE-2022-0586 [HIGH] CWE-835 CVE-2022-0586: Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows den
Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-30499P3HIGHCVSS 7.8v34v35+1 more2021-05-27
CVE-2021-30499 [HIGH] CWE-119 CVE-2021-30499: A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to me
A flaw was found in libcaca. A buffer overflow of export.c in function export_troff might lead to memory corruption and other potential consequences.
nvd
CVE-2022-29536P3HIGHCVSS 7.5v34v35+1 more2022-04-20
CVE-2022-29536 [HIGH] CWE-787 CVE-2022-29536: In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer ove
In GNOME Epiphany before 41.4 and 42.x before 42.2, an HTML document can trigger a client buffer overflow (in ephy_string_shorten in the UI process) via a long page title. The issue occurs because the number of bytes for a UTF-8 ellipsis character is not properly considered.
nvd
CVE-2020-14382P3HIGHCVSS 7.8v31v332020-09-16
CVE-2020-14382 [HIGH] CWE-787 CVE-2020-14382: A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format
A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file 'lib/luks2/luks2_json_metadata.c' in function hdr_validate_segments(struct crypt_device *cd, json_obje
nvd
CVE-2017-9106P3HIGHCVSS 7.5v31v322020-06-18
CVE-2017-9106 [HIGH] CWE-119 CVE-2017-9106: An issue was discovered in adns before 1.5.2. adns_rr_info mishandles a bogus *datap. The general pa
An issue was discovered in adns before 1.5.2. adns_rr_info mishandles a bogus *datap. The general pattern for formatting integers is to sprintf into a fixed-size buffer. This is correct if the input is in the right range; if it isn't, the buffer may be overrun (depending on the sizes of the types on the current platform). Of course the inputs ought to b
nvd
CVE-2022-2509P3HIGHCVSS 7.5v352022-08-01
CVE-2022-2509 [HIGH] CWE-415 CVE-2022-2509: A vulnerability found in gnutls. This security flaw happens because of a double free error occurs du
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.
nvd
CVE-2020-27823P3HIGHCVSS 7.8v32v332021-05-13
CVE-2020-27823 [HIGH] CWE-20 CVE-2020-27823: A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y o
A flaw was found in OpenJPEG’s encoder. This flaw allows an attacker to pass specially crafted x,y offset input to OpenJPEG to use during encoding. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2022-0583P3HIGHCVSS 7.5v34v352022-02-14
CVE-2022-0583 [HIGH] CWE-787 CVE-2022-0583: Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial o
Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-14929P3HIGHCVSS 7.5v31v322020-06-19
CVE-2020-14929 [HIGH] CVE-2020-14929: Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain c
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
nvd
CVE-2021-28861P3HIGHCVSS 7.4v35v36+1 more2022-08-23
CVE-2021-28861 [HIGH] CWE-601 CVE-2021-28861: Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protec
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It
nvd
CVE-2024-31497P3MEDIUMCVSS 5.9v38v39+1 more2024-04-15
CVE-2024-31497 [MEDIUM] CWE-338 CVE-2024-31497: In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly rea
nvd