Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 128 of 264
CVE-2021-43612P3HIGHCVSS 7.5v36v37+1 more2023-04-15
CVE-2021-43612 [HIGH] CWE-787 CVE-2021-43612: In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to t
In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
nvd
CVE-2022-29162P3HIGHCVSS 7.8v34v35+1 more2022-05-17
CVE-2022-29162 [HIGH] CWE-276 CVE-2022-29162: runc is a CLI tool for spawning and running containers on Linux according to the OCI specification.
runc is a CLI tool for spawning and running containers on Linux according to the OCI specification. A bug was found in runc prior to version 1.1.2 where `runc exec --cap` created processes with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capabilities to elevate tho
nvd
CVE-2022-25761P3HIGHCVSS 7.5v372022-08-23
CVE-2022-25761 [HIGH] CWE-770 CVE-2022-25761: The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial
The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this vulnerability by sending an unlimited number of huge chunks (e.g. 2GB each) without
nvd
CVE-2021-45450P3HIGHCVSS 7.5v36v372021-12-21
CVE-2021-45450 [HIGH] CWE-327 CVE-2021-45450: In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow
In Mbed TLS before 2.28.0 and 3.x before 3.1.0, psa_cipher_generate_iv and psa_cipher_encrypt allow policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
nvd
CVE-2019-25058P3HIGHCVSS 7.8v34v35+1 more2022-02-24
CVE-2019-25058 [HIGH] CWE-863 CVE-2019-25058: An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running,
An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.
nvd
CVE-2021-23177P3HIGHCVSS 7.8v352022-08-23
CVE-2021-23177 [HIGH] CWE-59 CVE-2021-23177: An improper link resolution flaw while extracting an archive can lead to changing the access control
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local attacker may use this flaw to change the ACL of a file on the system and gain mor
nvd
CVE-2020-25595P3HIGHCVSS 7.8v31v32+1 more2020-09-23
CVE-2020-25595 [HIGH] CWE-269 CVE-2020-25595: An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register dat
An issue was discovered in Xen through 4.14.x. The PCI passthrough code improperly uses register data. Code paths in Xen's MSI handling have been identified that act on unsanitized values read back from device hardware registers. While devices strictly compliant with PCI specifications shouldn't be able to affect these registers, experience shows that
nvd
CVE-2020-6574P3HIGHCVSS 7.8v31v332020-09-21
CVE-2020-6574 [HIGH] CVE-2020-6574: Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed
Insufficient policy enforcement in installer in Google Chrome on OS X prior to 85.0.4183.102 allowed a local attacker to potentially achieve privilege escalation via a crafted binary.
nvd
CVE-2012-1615P3HIGHCVSS 7.8v16v172019-12-06
CVE-2012-1615 [HIGH] CWE-269 CVE-2012-1615: A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.
A Privilege Escalation vulnerability exits in Fedoraproject Sectool due to an incorrect DBus file.
nvd
CVE-2021-26934P3HIGHCVSS 7.8v32v332021-02-17
CVE-2021-26934 [HIGH] CVE-2021-26934: An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend alloca
An issue was discovered in the Linux kernel 4.18 through 5.10.16, as used by Xen. The backend allocation (aka be-alloc) mode of the drm_xen_front drivers was not meant to be a supported configuration, but this wasn't stated accordingly in its support status entry.
nvd
CVE-2020-11739P3HIGHCVSS 7.8v30v31+1 more2020-04-14
CVE-2020-11739 [HIGH] CWE-362 CVE-2020-11739: An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a processor is allowed to re-order the memory access with the preceding ones. In oth
nvd
CVE-2022-38076P3HIGHCVSS 7.8v37v38+1 more2023-08-11
CVE-2022-38076 [HIGH] CWE-20 CVE-2022-38076: Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may all
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2023-34318P3HIGHCVSS 7.8v382023-07-10
CVE-2023-34318 [HIGH] CWE-122 CVE-2023-34318: A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:1
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.
nvd
CVE-2021-28697P3HIGHCVSS 7.8v33v34+1 more2021-08-27
CVE-2021-28697 [HIGH] CWE-362 CVE-2021-28697: grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to
grant table v2 status pages may remain accessible after de-allocation Guest get permitted access to certain Xen-owned pages of memory. The majority of such pages remain allocated / associated with a guest for its entire lifetime. Grant table v2 status pages, however, get de-allocated when a guest switched (back) from v2 to v1. The freeing of such pages
nvd
CVE-2020-6477P3HIGHCVSS 7.8v31v322020-05-21
CVE-2020-6477 [HIGH] CWE-59 CVE-2020-6477: Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a l
Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.
nvd
CVE-2021-45451P3HIGHCVSS 7.5v36v372021-12-21
CVE-2021-45451 [HIGH] CWE-327 CVE-2021-45451: In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption wh
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
nvd
CVE-2024-34506P3HIGHCVSS 7.5v402024-05-05
CVE-2024-34506 [HIGH] CWE-400 CVE-2024-34506: An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service.
nvd
CVE-2021-3752P3HIGHCVSS 7.1v342022-02-16
CVE-2021-3752 [HIGH] CWE-416 CVE-2021-3752: A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls conn
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2021-28702P3HIGHCVSS 7.6v33v34+1 more2021-10-06
CVE-2021-28702 [HIGH] CWE-269 CVE-2021-28702: PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Re
PCI devices with RMRRs not deassigned correctly Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR"). These are typically used for platform tasks such as legacy USB emulation. If such a device is passed through to a guest, then on guest shutdown the device is not properly de
nvd
CVE-2021-36377P3HIGHCVSS 7.5v342021-07-12
CVE-2021-36377 [HIGH] CWE-295 CVE-2021-36377: Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
nvd