Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 121 of 264
CVE-2020-26880P3HIGHCVSS 7.8v32v33+1 more2020-10-07
CVE-2020-26880 [HIGH] CWE-269 CVE-2020-26880: Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root
Sympa through 6.2.57b.2 allows a local privilege escalation from the sympa user account to full root access by modifying the sympa.conf configuration file (which is owned by sympa) and parsing it through the setuid sympa_newaliases-wrapper executable.
nvd
CVE-2021-26930P3HIGHCVSS 7.8v32v332021-02-17
CVE-2021-26930 [HIGH] CVE-2021-26930: An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service request
An issue was discovered in the Linux kernel 3.11 through 5.10.16, as used by Xen. To service requests to the PV backend, the driver maps grant references provided by the frontend. In this process, errors may be encountered. In one case, an error encountered earlier might be discarded by later processing, resulting in the caller assuming successful mapping, an
nvd
CVE-2022-26358P3HIGHCVSS 7.8v34v352022-04-05
CVE-2022-26358 [HIGH] CVE-2022-26358: IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to mu
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for
nvd
CVE-2022-26360P3HIGHCVSS 7.8v34v352022-04-05
CVE-2022-26360 [HIGH] CVE-2022-26360: IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to mu
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for
nvd
CVE-2022-26361P3HIGHCVSS 7.8v34v352022-04-05
CVE-2022-26361 [HIGH] CVE-2022-26361: IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to mu
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for
nvd
CVE-2022-26359P3HIGHCVSS 7.8v34v352022-04-05
CVE-2022-26359 [HIGH] CVE-2022-26359: IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to mu
IOMMU: RMRR (VT-d) and unity map (AMD-Vi) handling issues T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for
nvd
CVE-2022-23033P3HIGHCVSS 7.8v342022-01-25
CVE-2022-23033 [HIGH] CWE-404 CVE-2022-23033: arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more ent
arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to INVALID_MFN) do not actually clear the pagetable entry if the entry doesn't have the valid bit set. It is possible to have a valid p
nvd
CVE-2024-27000P3HIGHCVSS 7.8v38v39+1 more2024-05-01
CVE-2024-27000 [HIGH] CVE-2024-27000: In the Linux kernel, the following vulnerability has been resolved: serial: mxs-auart: add spinlock
In the Linux kernel, the following vulnerability has been resolved:
serial: mxs-auart: add spinlock around changing cts state
The uart_handle_cts_change() function in serial_core expects the caller
to hold uport->lock. For example, I have seen the below kernel splat,
when the Bluetooth driver is loaded on an i.MX28 board.
[ 85.119255] ------------[ cut here
nvd
CVE-2023-0664P3HIGHCVSS 7.8v372023-03-29
CVE-2023-0664 [HIGH] CWE-250 CVE-2023-0664: A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able
A flaw was found in the QEMU Guest Agent service for Windows. A local unprivileged user may be able to manipulate the QEMU Guest Agent's Windows installer via repair custom actions to elevate their privileges on the system.
nvd
CVE-2021-28375P3HIGHCVSS 7.8v32v33+1 more2021-03-15
CVE-2021-28375 [HIGH] CVE-2021-28375: An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/
An issue was discovered in the Linux kernel through 5.11.6. fastrpc_internal_invoke in drivers/misc/fastrpc.c does not prevent user applications from sending kernel RPC messages, aka CID-20c40794eb85. This is a related issue to CVE-2019-2308.
nvd
CVE-2024-27008P3HIGHCVSS 7.8v38v39+1 more2024-05-01
CVE-2024-27008 [HIGH] CWE-125 CVE-2024-27008: In the Linux kernel, the following vulnerability has been resolved: drm: nv04: Fix out of bounds ac
In the Linux kernel, the following vulnerability has been resolved:
drm: nv04: Fix out of bounds access
When Output Resource (dcb->or) value is assigned in
fabricate_dcb_output(), there may be out of bounds access to
dac_users array in case dcb->or is zero because ffs(dcb->or) is
used as index there.
The 'or' argument of fabricate_dcb_output() must b
nvd
CVE-2019-10218P3MEDIUMCVSS 6.5v29v312019-11-06
CVE-2019-10218 [MEDIUM] CWE-22 CVE-2019-10218: A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, wh
A flaw was found in the samba client, all samba versions before samba 4.11.2, 4.10.10 and 4.9.15, where a malicious server can supply a pathname to the client with separators. This could allow the client to access files and folders outside of the SMB network pathnames. An attacker could use this vulnerability to create files outside of the current wo
nvd
CVE-2024-31578P3HIGHCVSS 7.5v38v39+1 more2024-04-17
CVE-2024-31578 [HIGH] CWE-416 CVE-2024-31578: FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init fu
FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.
nvd
CVE-2021-29510P3HIGHCVSS 7.5v33v342021-05-13
CVE-2021-29510 [HIGH] CWE-835 CVE-2021-29510: Pydantic is a data validation and settings management using Python type hinting. In affected version
Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU). Pydantic has been patched with fixes available in the following versions: v1.
nvd
CVE-2020-0081P3HIGHCVSS 7.8v322020-04-17
CVE-2020-0081 [HIGH] CWE-415 CVE-2020-0081: In finalize of AssetManager.java, there is possible memory corruption due to a double free. This cou
In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-144028297
nvd
CVE-2020-11078P3MEDIUMCVSS 6.8v31v322020-05-20
CVE-2020-11078 [MEDIUM] CWE-93 CVE-2020-11078: In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.
In httplib2 before version 0.18.0, an attacker controlling unescaped part of uri for `httplib2.Http.request()` could change request headers and body, send additional hidden requests to same server. This vulnerability impacts software that uses httplib2 with uri constructed by string concatenation, as opposed to proper urllib building with escaping. T
nvd
CVE-2018-16229P3HIGHCVSS 7.5v29v30+1 more2019-10-03
CVE-2018-16229 [HIGH] CWE-125 CVE-2018-16229: The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().
The DCCP parser in tcpdump before 4.9.3 has a buffer over-read in print-dccp.c:dccp_print_option().
nvd
CVE-2011-3045P3HIGHCVSS 8.8v15v16+1 more2012-03-22
CVE-2011-3045 [HIGH] CVE-2011-3045: Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as
Integer signedness error in the png_inflate function in pngrutil.c in libpng before 1.4.10beta01, as used in Google Chrome before 17.0.963.83 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PNG file, a different vulnerability than CVE-2011-3026.
nvd
CVE-2021-33640P3CRITICALCVSS 9.8v36v372022-12-19
CVE-2021-33640 [CRITICAL] CWE-416 CVE-2021-33640: After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called
After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).
nvd
CVE-2020-27779P3HIGHCVSS 7.5v33v342021-03-03
CVE-2020-27779 [HIGH] CWE-285 CVE-2020-27779: A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot l
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentialit
nvd