Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 126 of 264
CVE-2022-1942P3HIGHCVSS 7.8v352022-05-31
CVE-2022-1942 [HIGH] CWE-122 CVE-2022-1942: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2021-32677P3HIGHCVSS 8.1v342021-06-09
CVE-2021-32677 [HIGH] CWE-352 CVE-2021-32677: FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. F
FastAPI is a web framework for building APIs with Python 3.6+ based on standard Python type hints. FastAPI versions lower than 0.65.2 that used cookies for authentication in path operations that received JSON payloads sent by browsers were vulnerable to a Cross-Site Request Forgery (CSRF) attack. In versions lower than 0.65.2, FastAPI would try to rea
nvd
CVE-2022-1897P3HIGHCVSS 7.8v34v35+1 more2022-05-27
CVE-2022-1897 [HIGH] CWE-787 CVE-2022-1897: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-26981P3HIGHCVSS 7.8v362022-03-13
CVE-2022-26981 [HIGH] CWE-120 CVE-2022-26981: Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (cal
Liblouis through 3.21.0 has a buffer overflow in compilePassOpcode in compileTranslationTable.c (called, indirectly, by tools/lou_checktable.c).
nvd
CVE-2021-45463P3HIGHCVSS 7.8v34v352021-12-23
CVE-2021-45463 [HIGH] CVE-2021-45463: load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command lin
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before 0.4.34 are used in GIMP releases before 2.10.30; however, this does not imply that GI
nvd
CVE-2021-3634P3MEDIUMCVSS 6.5v33v34+1 more2021-08-31
CVE-2021-3634 [MEDIUM] CWE-787 CVE-2021-3634: A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shar
A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange, previous session_id is kept and used as an input to new secret_hash. Historically
nvd
CVE-2021-4186P3HIGHCVSS 7.5v34v352021-12-30
CVE-2021-4186 [HIGH] CWE-476 CVE-2021-4186: Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet inje
Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-43518P3HIGHCVSS 7.8v35v362021-12-15
CVE-2021-43518 [HIGH] CWE-120 CVE-2021-43518: Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate
Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted map that will overwrite client's stack causing denial of service or code execution.
nvd
CVE-2022-2129P3HIGHCVSS 7.8v35v362022-06-19
CVE-2022-2129 [HIGH] CWE-787 CVE-2022-2129: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2020-11865P3HIGHCVSS 7.8v312020-05-11
CVE-2020-11865 [HIGH] CWE-119 CVE-2020-11865: libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.
nvd
CVE-2021-30498P3HIGHCVSS 7.8v34v35+1 more2021-05-26
CVE-2021-30498 [HIGH] CWE-787 CVE-2021-30498: A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to
A flaw was found in libcaca. A heap buffer overflow in export.c in function export_tga might lead to memory corruption and other potential consequences.
nvd
CVE-2022-32084P3HIGHCVSS 7.5v35v36+1 more2022-07-01
CVE-2022-32084 [HIGH] CVE-2022-32084: MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
nvd
CVE-2022-32089P3HIGHCVSS 7.5v35v36+1 more2022-07-01
CVE-2022-32089 [HIGH] CVE-2022-32089: MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_le
MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.
nvd
CVE-2022-32081P3HIGHCVSS 7.5v35v36+1 more2022-07-01
CVE-2022-32081 [HIGH] CWE-416 CVE-2022-32081: MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual
MariaDB v10.4 to v10.7 was discovered to contain an use-after-poison in prepare_inplace_add_virtual at /storage/innobase/handler/handler0alter.cc.
nvd
CVE-2020-36430P3HIGHCVSS 7.8v342021-07-20
CVE-2020-36430 [HIGH] CWE-787 CVE-2020-36430: libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_fon
libass 0.15.x before 0.15.1 has a heap-based buffer overflow in decode_chars (called from decode_font and process_text) because the wrong integer data type is used for subtraction.
nvd
CVE-2022-29968P3HIGHCVSS 7.8v34v35+1 more2022-05-02
CVE-2022-29968 [HIGH] CWE-909 CVE-2022-29968: An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks i
An issue was discovered in the Linux kernel through 5.17.5. io_rw_init_file in fs/io_uring.c lacks initialization of kiocb->private.
nvd
CVE-2020-16094P3HIGHCVSS 7.5v31v32+1 more2020-07-28
CVE-2020-16094 [HIGH] CWE-674 CVE-2020-16094: In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack
In imap_scan_tree_recursive in Claws Mail through 3.17.6, a malicious IMAP server can trigger stack consumption because of unlimited recursion into subdirectories during a rebuild of the folder tree.
nvd
CVE-2020-24388P3HIGHCVSS 7.5v332020-10-19
CVE-2020-24388 [HIGH] CWE-20 CVE-2020-24388: An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The funct
An issue was discovered in the _send_secure_msg() function of yubihsm-shell through 2.0.2. The function does not validate the embedded length field of a message received from the device. This could lead to an oversized memcpy() call that will crash the running process. This could be used by an attacker to cause a denial of service.
nvd
CVE-2022-27470P3HIGHCVSS 7.8v34v35+1 more2022-05-04
CVE-2022-27470 [HIGH] CWE-787 CVE-2022-27470: SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_R
SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.
nvd
CVE-2021-30577P3HIGHCVSS 7.8v33v34+1 more2021-08-03
CVE-2021-30577 [HIGH] CWE-732 CVE-2021-30577: Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remot
Insufficient policy enforcement in Installer in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform local privilege escalation via a crafted file.
nvd