Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 132 of 264
CVE-2021-21332P3HIGHCVSS 8.2v342021-03-26
CVE-2021-21332 [HIGH] CWE-79 CVE-2021-21332: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the password reset endpoint served via Synapse was vulnerable to cross-site scripting (XSS) attacks. The impact depends on the configuration of the domain that S
nvd
CVE-2020-9369P3HIGHCVSS 7.5v30v31+1 more2020-02-24
CVE-2020-9369 [HIGH] CWE-400 CVE-2020-9369: Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption f
Sympa 6.2.38 through 6.2.52 allows remote attackers to cause a denial of service (disk consumption from temporary files, and a flood of notifications to listmasters) via a series of requests with malformed parameters.
nvd
CVE-2016-6866P3HIGHCVSS 7.5v24v252017-02-15
CVE-2016-6866 [HIGH] CWE-476 CVE-2016-6866: slock allows attackers to bypass the screen lock via vectors involving an invalid password hash, whi
slock allows attackers to bypass the screen lock via vectors involving an invalid password hash, which triggers a NULL pointer dereference and crash.
nvd
CVE-2019-1010142P3HIGHCVSS 7.5v29v302019-07-19
CVE-2019-1010142 [HIGH] CWE-835 CVE-2019-1010142: scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption an
scapy 2.4.0 is affected by: Denial of Service. The impact is: infinite loop, resource consumption and program unresponsive. The component is: _RADIUSAttrPacketListField.getfield(self..). The attack vector is: over the network or in a pcap. both work.
nvd
CVE-2021-20270P3HIGHCVSS 7.5v332021-03-23
CVE-2021-20270 [HIGH] CWE-835 CVE-2021-20270: An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when pe
An infinite loop in SMLLexer in Pygments versions 1.5 to 2.7.3 may lead to denial of service when performing syntax highlighting of a Standard ML (SML) source file, as demonstrated by input that only contains the "exception" keyword.
nvd
CVE-2019-14459P3HIGHCVSS 7.5v29v302019-07-31
CVE-2019-14459 [HIGH] CWE-190 CVE-2019-14459: nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_
nfdump 1.6.17 and earlier is affected by an integer overflow in the function Process_ipfix_template_withdraw in ipfix.c that can be abused in order to crash the process remotely (denial of service).
nvd
CVE-2022-37451P3HIGHCVSS 7.5v35v362022-08-06
CVE-2022-37451 [HIGH] CWE-763 CVE-2022-37451: Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not u
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
nvd
CVE-2014-1490P3CRITICALCVSS 9.3v19v202014-02-06
CVE-2014-1490 [CRITICAL] CWE-362 CVE-2014-1490: Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozill
Race condition in libssl in Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, allows remote attackers to cause a denial of service (use-after-free) or possibly have unspecified other impact via vectors involv
nvd
CVE-2019-1010057P3HIGHCVSS 7.8v29v302019-07-16
CVE-2019-1010057 [HIGH] CWE-787 CVE-2019-1010057: nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range fro
nfdump 1.6.16 and earlier is affected by: Buffer Overflow. The impact is: The impact could range from a denial of service to local code execution. The component is: nfx.c:546, nffile_inline.c:83, minilzo.c (redistributed). The attack vector is: nfdump must read and process a specially crafted file. The fixed version is: after commit 9f0fe9563366f6
nvd
CVE-2021-35556P3MEDIUMCVSS 5.3v33v34+1 more2021-10-20
CVE-2021-35556 [MEDIUM] CWE-693 CVE-2021-35556: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Swing). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to
nvd
CVE-2020-27638P3HIGHCVSS 7.5v31v32+1 more2020-10-22
CVE-2020-27638 [HIGH] CWE-617 CVE-2020-27638: receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets wi
receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.
nvd
CVE-2020-6510P3HIGHCVSS 7.8v31v322020-07-22
CVE-2020-6510 [HIGH] CWE-787 CVE-2020-6510: Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote att
Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2015-7213P3MEDIUMCVSS 6.8v22v232015-12-16
CVE-2015-7213 [MEDIUM] CWE-189 CVE-2015-7213: Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefrigh
Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute arbitrary code via a crafted MP4 video file that triggers a buffer overflow.
nvd
CVE-2022-0417P3HIGHCVSS 7.8v34v352022-02-01
CVE-2022-0417 [HIGH] CWE-122 CVE-2022-0417: Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
nvd
CVE-2021-3575P3HIGHCVSS 7.8v33v342022-03-04
CVE-2021-3575 [HIGH] CWE-787 CVE-2021-3575: A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompre
A heap-based buffer overflow was found in openjpeg in color.c:379:42 in sycc420_to_rgb when decompressing a crafted .j2k file. An attacker could use this to execute arbitrary code with the permissions of the application compiled against openjpeg.
nvd
CVE-2022-0408P3HIGHCVSS 7.8v34v352022-01-30
CVE-2022-0408 [HIGH] CWE-121 CVE-2022-0408: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2304P3HIGHCVSS 7.8v35v362022-07-05
CVE-2022-2304 [HIGH] CWE-121 CVE-2022-2304: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
nvd
CVE-2017-18926P3HIGHCVSS 7.1v31v32+1 more2020-11-06
CVE-2017-18926 [HIGH] CWE-787 CVE-2017-18926: raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 mi
raptor_xml_writer_start_element_common in raptor_xml_writer.c in Raptor RDF Syntax Library 2.0.15 miscalculates the maximum nspace declarations for the XML writer, leading to heap-based buffer overflows (sometimes seen in raptor_qname_format_as_xml).
nvd
CVE-2022-2288P3HIGHCVSS 7.8v35v362022-07-03
CVE-2022-2288 [HIGH] CWE-787 CVE-2022-2288: Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.
Out-of-bounds Write in GitHub repository vim/vim prior to 9.0.
nvd
CVE-2021-3281P3MEDIUMCVSS 5.3v332021-02-02
CVE-2021-3281 [MEDIUM] CWE-22 CVE-2021-3281: In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extra
In Django 2.2 before 2.2.18, 3.0 before 3.0.12, and 3.1 before 3.1.6, the django.utils.archive.extract method (used by "startapp --template" and "startproject --template") allows directory traversal via an archive with absolute paths or relative paths with dot segments.
nvd