cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 134 of 264
CVE-2021-37969P3HIGHCVSS 7.8v33v352021-10-08
CVE-2021-37969 [HIGH] CWE-59 CVE-2021-37969: Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 all Inappropriate implementation in Google Updater in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to perform local privilege escalation via a crafted file.
nvd
CVE-2021-41799P3HIGHCVSS 7.5v33v34+1 more2021-10-11
CVE-2021-41799 [HIGH] CWE-770 CVE-2021-41799: MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query pr MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). ApiQueryBacklinks (action=query&list=backlinks) can cause a full table scan.
nvd
CVE-2023-49501P3HIGHCVSS 8.0v38v39+1 more2024-04-19
CVE-2023-49501 [HIGH] CWE-122 CVE-2023-49501: Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbi Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.
nvd
CVE-2011-4088P3HIGHCVSS 7.5v162020-01-31
CVE-2011-4088 [HIGH] CWE-200 CVE-2011-4088: ABRT might allow attackers to obtain sensitive information from crash reports. ABRT might allow attackers to obtain sensitive information from crash reports.
nvd
CVE-2021-25220P3MEDIUMCVSS 6.8v34v35+1 more2022-03-23
CVE-2021-25220 [MEDIUM] CWE-444 CVE-2021-25220: BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with
nvd
CVE-2021-3905P3HIGHCVSS 7.5v352022-08-23
CVE-2021-3905 [HIGH] CWE-401 CVE-2021-3905: A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attac A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
nvd
CVE-2023-51795P3HIGHCVSS 8.0v38v39+1 more2024-04-19
CVE-2023-51795 [HIGH] CWE-122 CVE-2023-51795: Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arb Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame
nvd
CVE-2019-2740P3MEDIUMCVSS 6.5v29v302019-07-23
CVE-2019-2740 [MEDIUM] CVE-2019-2740: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported v Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: XML). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2022-34749P3HIGHCVSS 7.5v372022-07-25
CVE-2022-34749 [HIGH] CWE-1333 CVE-2022-34749: In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.
nvd
CVE-2022-0943P3HIGHCVSS 7.8v34v362022-03-14
CVE-2022-0943 [HIGH] CWE-122 CVE-2022-0943: Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563. Heap-based Buffer Overflow occurs in vim in GitHub repository vim/vim prior to 8.2.4563.
nvd
CVE-2011-1526P3MEDIUMCVSS 6.5v14v152011-07-11
CVE-2011-1526 [MEDIUM] CWE-269 CVE-2011-1526: ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and ea ftpd.c in the GSS-API FTP daemon in MIT Kerberos Version 5 Applications (aka krb5-appl) 1.0.1 and earlier does not check the krb5_setegid return value, which allows remote authenticated users to bypass intended group access restrictions, and create, overwrite, delete, or read files, via standard FTP commands, related to missing autoconf tests in a con
nvd
CVE-2022-45939P3HIGHCVSS 7.8v36v372022-11-28
CVE-2022-45939 [HIGH] CWE-78 CVE-2022-45939: GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working
nvd
CVE-2019-16235P3HIGHCVSS 7.5v29v30+1 more2019-09-11
CVE-2019-16235 [HIGH] CWE-346 CVE-2019-16235: Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_me Dino before 2019-09-10 does not properly check the source of a carbons message in module/xep/0280_message_carbons.vala.
nvd
CVE-2023-38802P3HIGHCVSS 7.5v37v38+1 more2023-08-29
CVE-2023-38802 [HIGH] CWE-354 CVE-2023-38802: FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
nvd
CVE-2024-22640P3HIGHCVSS 7.5v402024-04-19
CVE-2024-22640 [HIGH] CWE-1333 CVE-2024-22640: TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an un TCPDF version <=6.6.5 is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing an untrusted HTML page with a crafted color.
nvd
CVE-2021-3410P3HIGHCVSS 7.8v34v352021-02-23
CVE-2021-3410 [HIGH] CWE-119 CVE-2021-3410: A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca A flaw was found in libcaca v0.99.beta19. A buffer overflow issue in caca_resize function in libcaca/caca/canvas.c may lead to local execution of arbitrary code in the user context.
nvd
CVE-2024-24479P3HIGHCVSS 7.5v402024-02-21
CVE-2024-24479 [HIGH] CWE-120 CVE-2024-24479: A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service vi A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
nvd
CVE-2019-2805P3MEDIUMCVSS 6.5v29v302019-07-23
CVE-2019-2805 [MEDIUM] CVE-2019-2805: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supporte Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabi
nvd
CVE-2019-2974P3MEDIUMCVSS 6.5v29v30+1 more2019-10-16
CVE-2019-2974 [MEDIUM] CVE-2019-2974: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2019-13313P3HIGHCVSS 7.8v29v302019-07-05
CVE-2019-13313 [HIGH] CWE-200 CVE-2019-13313: libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
nvd
Fedoraproject Fedora vulnerabilities | cvebase