Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 122 of 264
CVE-2021-22212P3HIGHCVSS 7.4v342021-06-08
CVE-2021-22212 [HIGH] CWE-327 CVE-2021-22212: ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys
ntpkeygen can generate keys that ntpd fails to parse. NTPsec 1.2.0 allows ntpkeygen to generate keys with '#' characters. ntpd then either pads, shortens the key, or fails to load these keys entirely, depending on the key type and the placement of the '#'. This results in the administrator not being able to use the keys as expected or the keys are sho
nvd
CVE-2009-2625P4MEDIUMCVSS 5.0v10v112009-08-06
CVE-2009-2625 [MEDIUM] CVE-2009-2625: XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE
XMLScanner.java in Apache Xerces2 Java, as used in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15 and JDK and JRE 5.0 before Update 20, and in other products, allows remote attackers to cause a denial of service (infinite loop and application hang) via malformed XML input, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2022-34903P3MEDIUMCVSS 6.5v35v362022-07-01
CVE-2022-34903 [MEDIUM] CWE-74 CVE-2022-34903: GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information fr
GnuPG through 2.3.6, in unusual situations where an attacker possesses any secret-key information from a victim's keyring and other constraints (e.g., use of GPGME) are met, allows signature forgery via injection into the status line.
nvd
CVE-2014-0198P4MEDIUMCVSS 4.3v19v202014-05-06
CVE-2014-0198 [MEDIUM] CWE-476 CVE-2014-0198: The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS
The do_ssl3_write function in s3_pkt.c in OpenSSL 1.x through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, does not properly manage a buffer pointer during certain recursive calls, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via vectors that trigger an alert condition.
nvd
CVE-2019-9199P3HIGHCVSS 8.8v29v302019-02-26
CVE-2019-9199 [HIGH] CWE-476 CVE-2019-9199: PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer d
PoDoFo::Impose::PdfTranslator::setSource() in pdftranslator.cpp in PoDoFo 0.9.6 has a NULL pointer dereference that can (for example) be triggered by sending a crafted PDF file to the podofoimpose binary. It allows an attacker to cause Denial of Service (Segmentation fault) or possibly have unspecified other impact.
nvd
CVE-2014-8630P3MEDIUMCVSS 6.5v20v212015-02-01
CVE-2014-8630 [MEDIUM] CWE-77 CVE-2014-8630: Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before
Bugzilla before 4.0.16, 4.1.x and 4.2.x before 4.2.12, 4.3.x and 4.4.x before 4.4.7, and 5.x before 5.0rc1 allows remote authenticated users to execute arbitrary commands by leveraging the editcomponents privilege and triggering crafted input to a two-argument Perl open call, as demonstrated by shell metacharacters in a product name.
nvd
CVE-2008-3282P3HIGHCVSS 7.8v8v92008-08-29
CVE-2008-3282 [HIGH] CVE-2008-3282: Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory a
Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in the memory allocator in OpenOffice.org (OOo) 2.4.1, on 64-bit platforms, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted document, related to a "numeric truncation error," a different vulnerability tha
nvd
CVE-2018-14469P3HIGHCVSS 7.5v29v30+1 more2019-10-03
CVE-2018-14469 [HIGH] CWE-125 CVE-2018-14469: The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().
The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().
nvd
CVE-2018-14880P3HIGHCVSS 7.5v29v30+1 more2019-10-03
CVE-2018-14880 [HIGH] CWE-125 CVE-2018-14880: The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr(
The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().
nvd
CVE-2022-23267P3HIGHCVSS 7.5v34v35+1 more2022-05-10
CVE-2022-23267 [HIGH] CVE-2022-23267: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2016-7972P3HIGHCVSS 7.5v23v24+1 more2017-03-03
CVE-2016-7972 [HIGH] CWE-399 CVE-2016-7972: The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attacker
The check_allocations function in libass/ass_shaper.c in libass before 0.13.4 allows remote attackers to cause a denial of service (memory allocation failure) via unspecified vectors.
nvd
CVE-2019-11050P3MEDIUMCVSS 6.5v30v312019-12-23
CVE-2019-11050 [MEDIUM] CWE-125 CVE-2019-11050: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2017-6362P3HIGHCVSS 7.5v262017-09-07
CVE-2017-6362 [HIGH] CWE-415 CVE-2017-6362: Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attacke
Double free vulnerability in the gdImagePngPtr function in libgd2 before 2.2.5 allows remote attackers to cause a denial of service via vectors related to a palette with no colors.
nvd
CVE-2022-35957P3MEDIUMCVSS 6.6v372022-09-20
CVE-2022-35957 [MEDIUM] CWE-290 CVE-2022-35957: Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5
Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the grafana instance. All installations should be upgraded as soon as possible. As
nvd
CVE-2022-31052P3MEDIUMCVSS 6.5v35v362022-06-28
CVE-2022-31052 [MEDIUM] CWE-674 CVE-2022-31052: Synapse is an open source home server implementation for the Matrix chat network. In versions prior
Synapse is an open source home server implementation for the Matrix chat network. In versions prior to 1.61.1 URL previews of some web pages can exhaust the available stack space for the Synapse process due to unbounded recursion. This is sometimes recoverable and leads to an error for the request causing the problem, but in other cases the Synapse p
nvd
CVE-2022-29117P3HIGHCVSS 7.5v34v35+1 more2022-05-10
CVE-2022-29117 [HIGH] CWE-400 CVE-2022-29117: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2021-44686P3HIGHCVSS 7.5v342021-12-07
CVE-2021-44686 [HIGH] CWE-400 CVE-2021-44686: calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression
calibre before 5.32.0 contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service) in html_preprocess_rules in ebooks/conversion/preprocess.py.
nvd
CVE-2019-11047P3MEDIUMCVSS 6.5v30v312019-12-23
CVE-2019-11047 [MEDIUM] CWE-125 CVE-2019-11047: When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() functio
When PHP EXIF extension is parsing EXIF information from an image, e.g. via exif_read_data() function, in PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 it is possible to supply it with data what will cause it to read past the allocated buffer. This may lead to information disclosure or crash.
nvd
CVE-2022-29145P3HIGHCVSS 7.5v34v35+1 more2022-05-10
CVE-2022-29145 [HIGH] CWE-400 CVE-2022-29145: .NET and Visual Studio Denial of Service Vulnerability
.NET and Visual Studio Denial of Service Vulnerability
nvd
CVE-2014-8502P3HIGHCVSS 7.5v19v20+1 more2014-12-09
CVE-2014-8502 [HIGH] CWE-119 CVE-2014-8502: Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and
Heap-based buffer overflow in the pe_print_edata function in bfd/peXXigen.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a truncated export table in a PE file.
nvd