cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 125 of 264
CVE-2021-30536P3HIGHCVSS 8.1v33v342021-06-07
CVE-2021-30536 [HIGH] CWE-125 CVE-2021-30536: Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potenti Out of bounds read in V8 in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.
nvd
CVE-2020-12762P3HIGHCVSS 7.8v30v31+1 more2020-05-09
CVE-2020-12762 [HIGH] CWE-190 CVE-2020-12762: json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demons json-c through 0.14 has an integer overflow and out-of-bounds write via a large JSON file, as demonstrated by printbuf_memappend.
nvd
CVE-2021-33644P3HIGHCVSS 8.1v35v36+1 more2022-08-10
CVE-2021-33644 [HIGH] CWE-125 CVE-2021-33644: An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read.
nvd
CVE-2020-14058P3HIGHCVSS 7.5v312020-06-30
CVE-2020-14058 [HIGH] CVE-2020-14058: An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dange An issue was discovered in Squid before 4.12 and 5.x before 5.0.3. Due to use of a potentially dangerous function, Squid and the default certificate validation helper are vulnerable to a Denial of Service when opening a TLS connection to an attacker-controlled server for HTTPS. This occurs because unrecognized error values are mapped to NULL, but later code e
nvd
CVE-2020-36279P3HIGHCVSS 7.5v32v332021-03-12
CVE-2020-36279 [HIGH] CWE-125 CVE-2020-36279: Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adapt Leptonica before 1.80.0 allows a heap-based buffer over-read in rasteropGeneralLow, related to adaptmap_reg.c and adaptmap.c.
nvd
CVE-2021-25219P3MEDIUMCVSS 5.3v33v34+1 more2021-10-27
CVE-2021-25219 [MEDIUM] CVE-2021-25219: In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9. In BIND 9.3.0 -> 9.11.35, 9.12.0 -> 9.16.21, and versions 9.9.3-S1 -> 9.11.35-S1 and 9.16.8-S1 -> 9.16.21-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.18 of the BIND 9.17 development branch, exploitation of broken authoritative servers using a flaw in response processing can cause degradation in BIND resolver performance.
nvd
CVE-2021-31292P3HIGHCVSS 7.5v33v342021-07-26
CVE-2021-31292 [HIGH] CWE-190 CVE-2021-31292: An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based An integer overflow in CrwMap::encode0x1810 of Exiv2 0.27.3 allows attackers to trigger a heap-based buffer overflow and cause a denial of service (DOS) via crafted metadata.
nvd
CVE-2021-30184P3HIGHCVSS 7.8v32v33+1 more2021-04-07
CVE-2021-30184 [HIGH] CWE-120 CVE-2021-30184: GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) GNU Chess 6.2.7 allows attackers to execute arbitrary code via crafted PGN (Portable Game Notation) data. This is related to a buffer overflow in the use of a .tmp.epd temporary file in the cmd_pgnload and cmd_pgnreplay functions in frontend/cmd.cc.
nvd
CVE-2013-1817P3HIGHCVSS 7.5v182019-11-20
CVE-2013-1817 [HIGH] CWE-200 CVE-2013-1817: MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allow MediaWiki before 1.19.4 and 1.20.x before 1.20.3 contains an error in the api.php script which allows remote attackers to obtain sensitive information.
nvd
CVE-2019-19886P3HIGHCVSS 7.5v30v31+1 more2020-01-21
CVE-2019-19886 [HIGH] CWE-404 CVE-2019-19886: Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when Trustwave ModSecurity 3.0.0 through 3.0.3 allows an attacker to send crafted requests that may, when sent quickly in large volumes, lead to the server becoming slow or unresponsive (Denial of Service) because of a flaw in Transaction::addRequestHeader in transaction.cc.
nvd
CVE-2015-9541P3HIGHCVSS 7.5v31v322020-01-24
CVE-2015-9541 [HIGH] CVE-2015-9541: Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is Qt through 5.14 allows an exponential XML entity expansion attack via a crafted SVG document that is mishandled in QXmlStreamReader, a related issue to CVE-2003-1564.
nvd
CVE-2022-2309P3HIGHCVSS 7.5v36v372022-07-05
CVE-2022-2309 [HIGH] CWE-476 CVE-2022-2309: NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This NULL Pointer Dereference allows attackers to cause a denial of service (or application crash). This only applies when lxml is used together with libxml2 2.9.10 through 2.9.14. libxml2 2.9.9 and earlier are not affected. It allows triggering crashes through forged input data, given a vulnerable code sequence in the application. The vulnerability is caused
nvd
CVE-2021-28676P3HIGHCVSS 7.5v332021-06-02
CVE-2021-28676 [HIGH] CWE-835 CVE-2021-28676: An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.
nvd
CVE-2019-9894P3HIGHCVSS 7.5v28v292019-03-21
CVE-2019-9894 [HIGH] CWE-320 CVE-2019-9894: A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before ho A remotely triggerable memory overwrite in RSA key exchange in PuTTY before 0.71 can occur before host key verification.
nvd
CVE-2020-6555P3HIGHCVSS 7.6v332020-09-21
CVE-2020-6555 [HIGH] CWE-125 CVE-2020-6555: Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obt Out of bounds read in WebGL in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2021-26813P3HIGHCVSS 7.5v32v33+1 more2021-03-03
CVE-2021-26813 [HIGH] CWE-1333 CVE-2021-26813: markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerab markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.
nvd
CVE-2020-36280P3HIGHCVSS 7.5v32v332021-03-12
CVE-2020-36280 [HIGH] CWE-125 CVE-2020-36280: Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to ti Leptonica before 1.80.0 allows a heap-based buffer over-read in pixReadFromTiffStream, related to tiffio.c.
nvd
CVE-2019-19918P3HIGHCVSS 7.8v31v32+1 more2019-12-20
CVE-2019-19918 [HIGH] CWE-787 CVE-2019-19918: Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c. Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.
nvd
CVE-2014-1487P3HIGHCVSS 7.5v19v202014-02-06
CVE-2014-1487 [HIGH] CWE-346 CVE-2014-1487: The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunder The Web workers implementation in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to bypass the Same Origin Policy and obtain sensitive authentication information via vectors involving error messages.
nvd
CVE-2022-2125P3HIGHCVSS 7.8v35v362022-06-19
CVE-2022-2125 [HIGH] CWE-122 CVE-2022-2125: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
Fedoraproject Fedora vulnerabilities | cvebase