Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 119 of 264
CVE-2020-24387P3HIGHCVSS 7.5v332020-10-19
CVE-2020-24387 [HIGH] CWE-125 CVE-2020-24387: An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The func
An issue was discovered in the yh_create_session() function of yubihsm-shell through 2.0.2. The function does not explicitly check the returned session id from the device. An invalid session id would lead to out-of-bounds read and write operations in the session array. This could be used by an attacker to cause a denial of service attack.
nvd
CVE-2015-7204P3MEDIUMCVSS 6.8v22v232015-12-16
CVE-2015-7204 [MEDIUM] CWE-17 CVE-2015-7204: Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows
Mozilla Firefox before 43.0 does not properly store the properties of unboxed objects, which allows remote attackers to execute arbitrary code via crafted JavaScript variable assignments.
nvd
CVE-2019-12098P3HIGHCVSS 7.4v30v312019-05-15
CVE-2019-12098 [HIGH] CWE-295 CVE-2019-12098: In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exch
In the client side of Heimdal before 7.6.0, failure to verify anonymous PKINIT PA-PKINIT-KX key exchange permits a man-in-the-middle attack. This issue is in krb5_init_creds_step in lib/krb5/init_creds_pw.c.
nvd
CVE-2024-32465P3HIGHCVSS 7.8v402024-05-14
CVE-2024-32465 [HIGH] CVE-2024-32465: Git is a revision control system. The Git project recommends to avoid working in untrusted repositor
Git is a revision control system. The Git project recommends to avoid working in untrusted repositories, and instead to clone it first with `git clone --no-local` to obtain a clean copy. Git has specific protections to make that a safe operation even with an untrusted source repository, but vulnerabilities allow those protections to be bypassed. In the contex
nvd
CVE-2022-36440P3HIGHCVSS 7.5v36v37+1 more2023-04-03
CVE-2022-36440 [HIGH] CWE-617 CVE-2022-36440: A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function.
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
nvd
CVE-2020-35475P3HIGHCVSS 7.5v332020-12-18
CVE-2020-35475 [HIGH] CWE-79 CVE-2020-35475: In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can co
In MediaWiki before 1.35.1, the messages userrights-expiry-current and userrights-expiry-none can contain raw HTML. XSS can happen when a user visits Special:UserRights but does not have rights to change all userrights, and the table on the left side has unchangeable groups in it. (The right column with the changeable groups is not affected and is esca
nvd
CVE-2019-20454P3HIGHCVSS 7.5v312020-02-14
CVE-2019-20454 [HIGH] CWE-125 CVE-2019-20454: An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and us
An out-of-bounds read was discovered in PCRE before 10.34 when the pattern \X is JIT compiled and used to match specially crafted subjects in non-UTF mode. Applications that use PCRE to parse untrusted input may be vulnerable to this flaw, which would allow an attacker to crash the application. The flaw occurs in do_extuni_no_utf in pcre2_jit_compile.
nvd
CVE-2021-21198P3HIGHCVSS 7.4v32v33+1 more2021-04-09
CVE-2021-21198 [HIGH] CWE-125 CVE-2021-21198: Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had
Out of bounds read in IPC in Google Chrome prior to 89.0.4389.114 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2022-45934P3HIGHCVSS 7.8v372022-11-27
CVE-2022-45934 [HIGH] CWE-190 CVE-2022-45934: An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_
An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
nvd
CVE-2021-33194P3HIGHCVSS 7.5v362021-05-26
CVE-2021-33194 [HIGH] CWE-835 CVE-2021-33194: golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of ser
golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.
nvd
CVE-2020-8252P3HIGHCVSS 7.8v332020-09-18
CVE-2020-8252 [HIGH] CWE-120 CVE-2020-8252: The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incor
The implementation of realpath in libuv < 10.22.1, < 12.18.4, and < 14.9.0 used within Node.js incorrectly determined the buffer size which can result in a buffer overflow if the resolved path is longer than 256 bytes.
nvd
CVE-2022-45059P3HIGHCVSS 7.5v35v36+1 more2022-11-09
CVE-2022-45059 [HIGH] CWE-444 CVE-2022-45059: An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smugglin
An issue was discovered in Varnish Cache 7.x before 7.1.2 and 7.2.x before 7.2.1. A request smuggling attack can be performed on Varnish Cache servers by requesting that certain headers are made hop-by-hop, preventing the Varnish Cache servers from forwarding critical headers to the backend.
nvd
CVE-2020-25869P3HIGHCVSS 7.5v332020-09-27
CVE-2020-25869 [HIGH] CWE-863 CVE-2020-25869: An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34
An information leak was discovered in MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4. Handling of actor ID does not necessarily use the correct database or correct wiki.
nvd
CVE-2020-13757P3HIGHCVSS 7.5v31v322020-06-01
CVE-2020-13757 [HIGH] CWE-327 CVE-2020-13757: Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceiv
Python-RSA before 4.1 ignores leading '\0' bytes during decryption of ciphertext. This could conceivably have a security-relevant impact, e.g., by helping an attacker to infer that an application uses Python-RSA, or if the length of accepted ciphertext affects application behavior (such as by causing excessive memory allocation).
nvd
CVE-2022-3204P3HIGHCVSS 7.5v35v36+1 more2022-09-26
CVE-2022-3204 [HIGH] CWE-400 CVE-2022-3204: A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered i
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers.
nvd
CVE-2019-12447P3HIGHCVSS 7.3v29v302019-05-29
CVE-2019-12447 [HIGH] CVE-2019-12447: An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles fi
An issue was discovered in GNOME gvfs 1.29.4 through 1.41.2. daemon/gvfsbackendadmin.c mishandles file ownership because setfsuid is not used.
nvd
CVE-2022-38784P3HIGHCVSS 7.8v35v36+1 more2022-08-30
CVE-2022-38784 [HIGH] CVE-2022-38784: Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Strea
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.
nvd
CVE-2019-25051P3HIGHCVSS 7.8v342021-07-20
CVE-2019-25051 [HIGH] CWE-787 CVE-2019-25051: objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called
objstack in GNU Aspell 0.60.8 has a heap-based buffer overflow in acommon::ObjStack::dup_top (called from acommon::StringMap::add and acommon::Config::lookup_list).
nvd
CVE-2024-24476P3HIGHCVSS 7.5v402024-02-21
CVE-2024-24476 [HIGH] CWE-119 CVE-2024-24476: A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service vi
A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
nvd
CVE-2021-3839P3HIGHCVSS 7.5v352022-08-23
CVE-2021-3839 [HIGH] CWE-125 CVE-2021-3839: A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not valida
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.
nvd