Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 135 of 264
CVE-2013-4251P3HIGHCVSS 7.8v18v19+1 more2019-11-04
CVE-2013-4251 [HIGH] CWE-269 CVE-2013-4251: The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
nvd
CVE-2021-39252P3HIGHCVSS 7.8v33v352021-09-07
CVE-2021-39252 [HIGH] CWE-125 CVE-2021-39252: A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.
A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.
nvd
CVE-2021-39253P3HIGHCVSS 7.8v33v352021-09-07
CVE-2021-39253 [HIGH] CWE-125 CVE-2021-39253: A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22
A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.
nvd
CVE-2021-37980P3HIGHCVSS 7.4v332021-11-02
CVE-2021-37980 [HIGH] CVE-2021-37980: Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote atta
Inappropriate implementation in Sandbox in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially bypass site isolation via Windows.
nvd
CVE-2021-33287P3HIGHCVSS 7.8v33v352021-09-07
CVE-2021-33287 [HIGH] CWE-787 CVE-2021-33287: In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntf
In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.
nvd
CVE-2022-27776P3MEDIUMCVSS 6.5v36v372022-06-02
CVE-2022-27776 [MEDIUM] CWE-522 CVE-2022-27776: A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authenticati
A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.
nvd
CVE-2019-16237P3HIGHCVSS 7.5v29v30+1 more2019-09-11
CVE-2019-16237 [HIGH] CWE-346 CVE-2019-16237: Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_messa
Dino before 2019-09-10 does not properly check the source of an MAM message in module/xep/0313_message_archive_management.vala.
nvd
CVE-2022-28390P3HIGHCVSS 7.8v34v35+1 more2022-04-03
CVE-2022-28390 [HIGH] CWE-415 CVE-2022-28390: ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
nvd
CVE-2015-3622P4MEDIUMCVSS 4.3v212015-05-12
CVE-2015-3622 [MEDIUM] CWE-119 CVE-2015-3622: The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote atta
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.
nvd
CVE-2021-28709P3HIGHCVSS 7.8v34v352021-11-24
CVE-2021-28709 [HIGH] CVE-2021-28709: issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple
issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control certain
nvd
CVE-2021-28705P3HIGHCVSS 7.8v34v352021-11-24
CVE-2021-28705 [HIGH] CWE-755 CVE-2021-28705: issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple
issues with partially successful P2M updates on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] x86 HVM and PVH guests may be started in populate-on-demand (PoD) mode, to provide a way for them to later easily have more memory assigned. Guests are permitted to control
nvd
CVE-2023-51798P3HIGHCVSS 7.8v38v39+1 more2024-04-19
CVE-2023-51798 [HIGH] CWE-120 CVE-2023-51798: Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arb
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.
nvd
CVE-2023-3966P3HIGHCVSS 7.5v39v402024-02-22
CVE-2023-3966 [HIGH] CWE-248 CVE-2023-3966: A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, w
A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.
nvd
CVE-2019-19270P3HIGHCVSS 7.5v30v312019-11-26
CVE-2019-19270 [HIGH] CWE-295 CVE-2019-19270: An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the approp
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow clients whose certificates have been revoked to proceed with a connection to
nvd
CVE-2021-35567P3MEDIUMCVSS 6.8v33v34+1 more2021-10-20
CVE-2021-35567 [MEDIUM] CVE-2021-35567: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows low privileged attacker with network access via Kerberos to compromise Java SE, O
nvd
CVE-2024-27021P3HIGHCVSS 7.8v38v39+1 more2024-05-01
CVE-2024-27021 [HIGH] CWE-667 CVE-2024-27021: In the Linux kernel, the following vulnerability has been resolved: r8169: fix LED-related deadlock
In the Linux kernel, the following vulnerability has been resolved:
r8169: fix LED-related deadlock on module removal
Binding devm_led_classdev_register() to the netdev is problematic
because on module removal we get a RTNL-related deadlock. Fix this
by avoiding the device-managed LED functions.
Note: We can safely call led_classdev_unregister() for
nvd
CVE-2024-4854P3HIGHCVSS 7.5v39v402024-05-14
CVE-2024-4854 [HIGH] CWE-835 CVE-2024-4854: MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
nvd
CVE-2020-13482P3HIGHCVSS 7.4v32v332020-05-25
CVE-2020-13482 [HIGH] CWE-295 CVE-2020-13482: EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to pe
EM-HTTP-Request 1.1.5 uses the library eventmachine in an insecure way that allows an attacker to perform a man-in-the-middle attack against users of the library. The hostname in a TLS server certificate is not verified.
nvd
CVE-2019-14907P3MEDIUMCVSS 6.5v30v312020-01-21
CVE-2019-14907 [MEDIUM] CWE-125 CVE-2019-14907: All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue
All samba versions 4.9.x before 4.9.18, 4.10.x before 4.10.12 and 4.11.x before 4.11.5 have an issue where if it is set with "log level = 3" (or above) then the string obtained from the client, after a failed character conversion, is printed. Such strings can be provided during the NTLMSSP authentication exchange. In the Samba AD DC in particular, t
nvd
CVE-2024-5458P3MEDIUMCVSS 5.3v402024-06-09
CVE-2024-5458 [MEDIUM] CWE-345 CVE-2024-5458: In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic er
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, due to a code logic error, filtering functions such as filter_var when validating URLs (FILTER_VALIDATE_URL) for certain types of URLs the function will result in invalid user information (username + password part of URLs) being treated as valid user information. This may le
nvd