Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 133 of 264
CVE-2022-32091P3HIGHCVSS 7.5v35v36+1 more2022-07-01
CVE-2022-32091 [HIGH] CWE-416 CVE-2022-32091: MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsaniti
MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.
nvd
CVE-2022-2210P3HIGHCVSS 7.8v35v362022-06-27
CVE-2022-2210 [HIGH] CWE-787 CVE-2022-2210: Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Write in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-32545P3HIGHCVSS 7.8v362022-06-16
CVE-2022-32545 [HIGH] CWE-190 CVE-2022-32545: A vulnerability was found in ImageMagick, causing an outside the range of representable values of ty
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned char' at coders/psd.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
nvd
CVE-2020-11866P3HIGHCVSS 7.8v312020-05-11
CVE-2020-11866 [HIGH] CWE-416 CVE-2020-11866: libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.
nvd
CVE-2020-28030P3HIGHCVSS 7.5v32v332020-11-02
CVE-2020-28030 [HIGH] CWE-682 CVE-2020-28030: In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/
In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.
nvd
CVE-2020-14409P3HIGHCVSS 7.8v332021-01-19
CVE-2020-14409 [HIGH] CWE-190 CVE-2020-14409: SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap
SDL (Simple DirectMedia Layer) through 2.0.12 has an Integer Overflow (and resultant SDL_memcpy heap corruption) in SDL_BlitCopy in video/SDL_blit_copy.c via a crafted .BMP file.
nvd
CVE-2023-5157P3HIGHCVSS 7.5v382023-09-27
CVE-2023-5157 [HIGH] CWE-400 CVE-2023-5157: A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
nvd
CVE-2007-5593P3MEDIUMCVSS 6.8v72007-10-19
CVE-2007-5593 [MEDIUM] CWE-94 CVE-2007-5593: install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows r
install.php in Drupal 5.x before 5.3, when the configured database server is not reachable, allows remote attackers to execute arbitrary code via vectors that cause settings.php to be modified.
nvd
CVE-2021-28878P3HIGHCVSS 7.5v32v33+1 more2021-04-11
CVE-2021-28878 [HIGH] CWE-119 CVE-2021-28878: In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked
In the standard library in Rust before 1.52.0, the Zip implementation calls __iterator_get_unchecked() more than once for the same index (under certain conditions) when next_back() and next() are used together. This bug could lead to a memory safety violation due to an unmet safety requirement for the TrustedRandomAccess trait.
nvd
CVE-2016-3704P3HIGHCVSS 7.5v242017-06-13
CVE-2016-3704 [HIGH] CWE-255 CVE-2016-3704: Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
Pulp before 2.8.5 uses bash's $RANDOM in an unsafe way to generate passwords.
nvd
CVE-2022-0546P3HIGHCVSS 7.8v342022-02-24
CVE-2022-0546 [HIGH] CWE-190 CVE-2022-0546: A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds hea
A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.
nvd
CVE-2019-19787P3HIGHCVSS 7.8v32v33+1 more2019-12-13
CVE-2019-19787 [HIGH] CWE-787 CVE-2019-19787: ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c v
ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file.
nvd
CVE-2019-19785P3HIGHCVSS 7.8v32v33+1 more2019-12-13
CVE-2019-19785 [HIGH] CWE-787 CVE-2019-19785: ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65
ATasm 1.06 has a stack-based buffer overflow in the to_comma() function in asm.c via a crafted .m65 file.
nvd
CVE-2019-19786P3HIGHCVSS 7.8v32v33+1 more2019-12-13
CVE-2019-19786 [HIGH] CWE-787 CVE-2019-19786: ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafte
ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.
nvd
CVE-2022-32082P3HIGHCVSS 7.5v35v36+1 more2022-07-01
CVE-2022-32082 [HIGH] CWE-617 CVE-2022-32082: MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
nvd
CVE-2020-14040P3HIGHCVSS 7.5v322020-06-17
CVE-2020-14040 [HIGH] CWE-835 CVE-2020-14040: The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to th
The x/text package before 0.3.3 for Go has a vulnerability in encoding/unicode that could lead to the UTF-16 decoder entering an infinite loop, causing the program to crash or run out of memory. An attacker could provide a single byte to a UTF16 decoder instantiated with UseBOM or ExpectBOM to trigger an infinite loop if the String function on the Dec
nvd
CVE-2022-0581P3HIGHCVSS 7.5v34v352022-02-14
CVE-2022-0581 [HIGH] CWE-416 CVE-2022-0581: Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of
Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-17487P3HIGHCVSS 7.5v32v332020-08-11
CVE-2020-17487 [HIGH] CVE-2020-17487: radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_pa
radare2 4.5.0 misparses signature information in PE files, causing a segmentation fault in r_x509_parse_algorithmidentifier in libr/util/x509.c. This is due to a malformed object identifier in IMAGE_DIRECTORY_ENTRY_SECURITY.
nvd
CVE-2016-2166P3MEDIUMCVSS 6.5v232016-04-12
CVE-2016-2166 [MEDIUM] CWE-200 CVE-2016-2166: The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnect
The (1) proton.reactor.Connector, (2) proton.reactor.Container, and (3) proton.utils.BlockingConnection classes in Apache Qpid Proton before 0.12.1 improperly use an unencrypted connection for an amqps URI scheme when SSL support is unavailable, which might allow man-in-the-middle attackers to obtain sensitive information or modify data via unspecifie
nvd
CVE-2022-3517P3HIGHCVSS 7.5v36v372022-10-17
CVE-2022-3517 [HIGH] CWE-400 CVE-2022-3517: A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of
A vulnerability was found in the minimatch package. This flaw allows a Regular Expression Denial of Service (ReDoS) when calling the braceExpand function with specific arguments, resulting in a Denial of Service.
nvd