Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 131 of 264
CVE-2018-14462P3HIGHCVSS 7.5v29v30+1 more2019-10-03
CVE-2018-14462 [HIGH] CWE-125 CVE-2018-14462: The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
The ICMP parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp.c:icmp_print().
nvd
CVE-2018-14882P3HIGHCVSS 7.5v29v30+1 more2019-10-03
CVE-2018-14882 [HIGH] CWE-125 CVE-2018-14882: The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
nvd
CVE-2018-16230P3HIGHCVSS 7.5v29v30+1 more2019-10-03
CVE-2018-16230 [HIGH] CWE-125 CVE-2018-16230: The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_RE
The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_attr_print() (MP_REACH_NLRI).
nvd
CVE-2016-6323P3HIGHCVSS 7.5v23v24+1 more2016-10-07
CVE-2016-6323 [HIGH] CWE-284 CVE-2016-6323: The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution con
The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as demonstrated by applications compiled using gccgo, related to backtrace generation.
nvd
CVE-2016-2124P3MEDIUMCVSS 5.9v33v34+1 more2022-02-18
CVE-2016-2124 [MEDIUM] CWE-287 CVE-2016-2124: A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw t
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentication was required.
nvd
CVE-2019-18804P3HIGHCVSS 7.5v30v312019-11-07
CVE-2019-18804 [HIGH] CWE-476 CVE-2019-18804: DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.c
DjVuLibre 3.5.27 has a NULL pointer dereference in the function DJVU::filter_fv at IW44EncodeCodec.cpp.
nvd
CVE-2016-3110P3HIGHCVSS 7.5v28v29+1 more2016-09-26
CVE-2016-3110 [HIGH] CWE-20 CVE-2016-3110: mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of s
mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.
nvd
CVE-2017-13751P3HIGHCVSS 7.5v32v332017-08-29
CVE-2017-13751 [HIGH] CWE-617 CVE-2017-13751: There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.
There is a reachable assertion abort in the function calcstepsizes() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
nvd
CVE-2017-13752P3HIGHCVSS 7.5v32v332017-08-29
CVE-2017-13752 [HIGH] CWE-617 CVE-2017-13752: There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0
There is a reachable assertion abort in the function jpc_dequantize() in jpc/jpc_dec.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
nvd
CVE-2017-13747P3HIGHCVSS 7.5v32v332017-08-29
CVE-2017-13747 [HIGH] CWE-617 CVE-2017-13747: There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0
There is a reachable assertion abort in the function jpc_floorlog2() in jpc/jpc_math.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
nvd
CVE-2017-13749P3HIGHCVSS 7.5v32v332017-08-29
CVE-2017-13749 [HIGH] CWE-617 CVE-2017-13749: There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer
There is a reachable assertion abort in the function jpc_pi_nextrpcl() in jpc/jpc_t2cod.c in JasPer 2.0.12 that will lead to a remote denial of service attack.
nvd
CVE-2016-9243P3HIGHCVSS 7.5v23v24+1 more2017-03-27
CVE-2016-9243 [HIGH] CVE-2016-9243: HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algor
HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
nvd
CVE-2016-2146P3HIGHCVSS 7.5v232016-04-15
CVE-2016-2146 [HIGH] CWE-119 CVE-2016-2146: The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data re
The am_read_post_data function in mod_auth_mellon before 0.11.1 does not limit the amount of data read, which allows remote attackers to cause a denial of service (worker process crash, web server deadlock, or memory consumption) via a large amount of POST data.
nvd
CVE-2020-18032P3HIGHCVSS 7.8v33v342021-04-29
CVE-2020-18032 [HIGH] CWE-120 CVE-2020-18032: Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows rem
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
nvd
CVE-2019-5429P3HIGHCVSS 7.8v282019-04-29
CVE-2019-5429 [HIGH] CWE-426 CVE-2019-5429: Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a mal
Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory.
nvd
CVE-2021-23437P3HIGHCVSS 7.5v33v342021-09-03
CVE-2021-23437 [HIGH] CWE-125 CVE-2021-23437: The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (Re
The package pillow 5.2.0 and before 8.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the getrgb function.
nvd
CVE-2015-8387P3HIGHCVSS 7.3v222015-12-02
CVE-2015-8387 [HIGH] CWE-190 CVE-2015-8387: PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remot
PCRE before 8.38 mishandles (?123) subroutine calls and related subroutine calls, which allows remote attackers to cause a denial of service (integer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
nvd
CVE-2021-33582P3HIGHCVSS 7.5v34v352021-09-01
CVE-2021-33582 [HIGH] CWE-407 CVE-2021-33582: Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes slow. This is fixed in 3.4.2, 3.2.8, and 3.0.16.
nvd
CVE-2019-9897P3HIGHCVSS 7.5v28v292019-03-21
CVE-2019-9897 [HIGH] CVE-2019-9897: Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY v
Multiple denial-of-service attacks that can be triggered by writing to the terminal exist in PuTTY versions before 0.71.
nvd
CVE-2020-13962P3HIGHCVSS 7.5v31v32+1 more2020-06-09
CVE-2020-13962 [HIGH] CVE-2020-13962: Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandle
Qt 5.12.2 through 5.14.2, as used in unofficial builds of Mumble 1.3.0 and other products, mishandles OpenSSL's error queue, which can cause a denial of service to QSslSocket users. Because errors leak in unrelated TLS sessions, an unrelated session may be disconnected when any handshake fails. (Mumble 1.3.1 is not affected, regardless of the Qt version.)
nvd