cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 127 of 264
CVE-2019-14816P3HIGHCVSS 7.8v29v302019-09-20
CVE-2019-14816 [HIGH] CWE-122 CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wif There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code.
nvd
CVE-2021-45848P3HIGHCVSS 7.5v342022-03-15
CVE-2021-45848 [HIGH] CWE-116 CVE-2021-45848: Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Sou Denial of service (DoS) vulnerability in Nicotine+ 3.0.3 and later allows a user with a modified Soulseek client to crash Nicotine+ by sending a file download request with a file path containing a null character.
nvd
CVE-2021-46829P3HIGHCVSS 7.8v352022-07-24
CVE-2021-46829 [HIGH] CWE-190 CVE-2021-46829: GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit systems.
nvd
CVE-2016-6185P3HIGHCVSS 7.8v22v23+1 more2016-08-02
CVE-2016-6185 [HIGH] CVE-2016-6185: The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a st The XSLoader::load method in XSLoader in Perl does not properly locate .so files when called in a string eval, which might allow local users to execute arbitrary code via a Trojan horse library under the current working directory.
nvd
CVE-2024-22871P3HIGHCVSS 7.5v38v39+1 more2024-02-29
CVE-2024-22871 [HIGH] CWE-502 CVE-2024-22871: An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service ( An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.
nvd
CVE-2010-4494P3HIGHCVSS 7.5v142010-12-07
CVE-2010-4494 [HIGH] CWE-415 CVE-2010-4494: Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.5 Double free vulnerability in libxml2 2.7.8 and other versions, as used in Google Chrome before 8.0.552.215 and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to XPath handling.
nvd
CVE-2021-28543P3HIGHCVSS 7.5v342021-03-16
CVE-2021-28543 [HIGH] CWE-476 CVE-2021-28543: Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon r Varnish varnish-modules before 0.17.1 allows remote attackers to cause a denial of service (daemon restart) in some configurations. This does not affect organizations that only install the Varnish Cache product; however, it is common to install both Varnish Cache and varnish-modules. Specifically, an assertion failure or NULL pointer dereference can b
nvd
CVE-2022-46663P3HIGHCVSS 7.5v372023-02-07
CVE-2022-46663 [HIGH] CVE-2022-46663: In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sen In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.
nvd
CVE-2024-2955P3HIGHCVSS 7.5v39v402024-03-26
CVE-2024-2955 [HIGH] CWE-762 CVE-2024-2955: T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via pa T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file
nvd
CVE-2022-1733P3HIGHCVSS 7.8v34v35+1 more2022-05-17
CVE-2022-1733 [HIGH] CWE-122 CVE-2022-1733: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.
nvd
CVE-2021-3928P3HIGHCVSS 7.8v33v34+1 more2021-11-05
CVE-2021-3928 [HIGH] CWE-457 CVE-2021-3928: vim is vulnerable to Use of Uninitialized Variable vim is vulnerable to Use of Uninitialized Variable
nvd
CVE-2023-2603P3HIGHCVSS 7.8v37v382023-06-06
CVE-2023-2603 [HIGH] CWE-190 CVE-2023-2603: A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
nvd
CVE-2021-41617P3HIGHCVSS 7.0v33v34+1 more2021-09-26
CVE-2021-41617 [HIGH] CVE-2021-41617: sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and AuthorizedPrincipalsCommand may run with privileges associated with group memberships of the sshd process, if the configuration spec
nvd
CVE-2023-41164P3HIGHCVSS 7.5v392023-11-03
CVE-2023-41164 [HIGH] CWE-1284 CVE-2023-41164: In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_i In Django 3.2 before 3.2.21, 4.1 before 4.1.11, and 4.2 before 4.2.5, django.utils.encoding.uri_to_iri() is subject to a potential DoS (denial of service) attack via certain inputs with a very large number of Unicode characters.
nvd
CVE-2023-22970P3HIGHCVSS 7.8v37v382023-05-26
CVE-2023-22970 [HIGH] CVE-2023-22970: Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file. Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
nvd
CVE-2022-26490P3HIGHCVSS 7.8v34v352022-03-06
CVE-2022-26490 [HIGH] CWE-120 CVE-2022-26490: st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.1 st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
nvd
CVE-2023-29403P3HIGHCVSS 7.8v382023-06-08
CVE-2023-29403 [HIGH] CWE-668 CVE-2023-29403: On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/s On Unix platforms, the Go runtime does not behave differently when a binary is run with the setuid/setgid bits. This can be dangerous in certain cases, such as when dumping memory state, or assuming the status of standard i/o file descriptors. If a setuid/setgid binary is executed with standard I/O file descriptors closed, opening any files can result
nvd
CVE-2022-4141P3HIGHCVSS 7.8v36v372022-11-25
CVE-2022-4141 [HIGH] CWE-122 CVE-2022-4141: Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.
nvd
CVE-2020-35733P3HIGHCVSS 7.5v332021-01-15
CVE-2020-35733 [HIGH] CWE-295 CVE-2020-35733: An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an An issue was discovered in Erlang/OTP before 23.2.2. The ssl application 10.2 accepts and trusts an invalid X.509 certificate chain to a trusted root Certification Authority.
nvd
CVE-2022-30784P3HIGHCVSS 7.8v35v362022-05-26
CVE-2022-30784 [HIGH] CWE-120 CVE-2022-30784: A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8 A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
nvd
Fedoraproject Fedora vulnerabilities | cvebase