Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 137 of 264
CVE-2021-21393P3MEDIUMCVSS 6.5v342021-04-12
CVE-2021-21393 [MEDIUM] CWE-20 CVE-2021-21393: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memo
nvd
CVE-2014-9658P3HIGHCVSS 7.5v20v212015-02-08
CVE-2014-9658 [HIGH] CWE-125 CVE-2014-9658: The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minim
The tt_face_load_kern function in sfnt/ttkern.c in FreeType before 2.5.4 enforces an incorrect minimum table length, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted TrueType font.
nvd
CVE-2021-21394P3MEDIUMCVSS 6.5v342021-04-12
CVE-2021-21394 [MEDIUM] CWE-20 CVE-2021-21394: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 Synapse is missing input validation of some parameters on the endpoints used to confirm third-party identifiers could cause excessive use of disk space and memo
nvd
CVE-2021-22947P3MEDIUMCVSS 5.9v33v352021-09-29
CVE-2021-22947 [MEDIUM] CWE-310 CVE-2021-22947: When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS
When curl >= 7.20.0 and <= 7.78.0 connects to an IMAP or POP3 server to retrieve data using STARTTLS to upgrade to TLS security, the server can respond and send back multiple responses at once that curl caches. curl would then upgrade to TLS but not flush the in-queue of cached responses but instead continue using and trustingthe responses it got *b
nvd
CVE-2014-1398P3MEDIUMCVSS 6.5v19v202018-04-10
CVE-2014-1398 [MEDIUM] CWE-284 CVE-2014-1398: The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on comment, user and node statistics properties via unspecified vectors.
nvd
CVE-2020-28463P3MEDIUMCVSS 6.5v34v352021-02-18
CVE-2020-28463 [MEDIUM] CWE-918 CVE-2020-28463: All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags.
All versions of package reportlab are vulnerable to Server-side Request Forgery (SSRF) via img tags. In order to reduce risk, use trustedSchemes & trustedHosts (see in Reportlab's documentation) Steps to reproduce by Karan Bamal: 1. Download and install the latest package of reportlab 2. Go to demos -> odyssey -> dodyssey 3. In the text file odyssey
nvd
CVE-2021-1723P3HIGHCVSS 7.5v32v332021-01-12
CVE-2021-1723 [HIGH] CVE-2021-1723: ASP.NET Core and Visual Studio Denial of Service Vulnerability
ASP.NET Core and Visual Studio Denial of Service Vulnerability
nvd
CVE-2016-1231P3MEDIUMCVSS 5.9v22v232016-01-12
CVE-2016-1231 [MEDIUM] CWE-22 CVE-2016-1231: Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x
Directory traversal vulnerability in the HTTP file-serving module (mod_http_files) in Prosody 0.9.x before 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) in an unspecified path.
nvd
CVE-2016-0720P3HIGHCVSS 8.8v22v232017-04-21
CVE-2016-0720 [HIGH] CWE-352 CVE-2016-0720: Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.
nvd
CVE-2022-24808P3MEDIUMCVSS 6.5v362024-04-16
CVE-2022-24808 [MEDIUM] CWE-476 CVE-2022-24808: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a `SET` request to `NET-SNMP-AGENT-MIB::nsLogTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing
nvd
CVE-2021-32760P3MEDIUMCVSS 6.3v342021-07-19
CVE-2021-32760 [MEDIUM] CWE-668 CVE-2021-32760: containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 w
containerd is a container runtime. A bug was found in containerd versions prior to 1.4.8 and 1.5.4 where pulling and extracting a specially-crafted container image can result in Unix file permission changes for existing files in the host’s filesystem. Changes to file permissions can deny access to the expected owner of the file, widen access to othe
nvd
CVE-2021-41183P3MEDIUMCVSS 6.1v33v34+2 more2021-10-26
CVE-2021-41183 [MEDIUM] CWE-79 CVE-2021-41183: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various `*Text` options are now always treated as pure text, not HTML. A workaround is
nvd
CVE-2021-29063P3HIGHCVSS 7.5v33v34+1 more2021-06-21
CVE-2021-29063 [HIGH] CWE-770 CVE-2021-29063: A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through
A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.
nvd
CVE-2022-0197P3HIGHCVSS 8.8v34v352022-01-13
CVE-2022-0197 [HIGH] CWE-352 CVE-2022-0197: phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
nvd
CVE-2013-0170P3MEDIUMCVSS 6.8v16v17+1 more2013-02-08
CVE-2013-0170 [MEDIUM] CWE-416 CVE-2013-0170: Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvir
Use-after-free vulnerability in the virNetMessageFree function in rpc/virnetserverclient.c in libvirt 1.0.x before 1.0.2, 0.10.2 before 0.10.2.3, 0.9.11 before 0.9.11.9, and 0.9.6 before 0.9.6.4 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by triggering certain errors during an RPC connection, which
nvd
CVE-2022-0196P3HIGHCVSS 8.8v34v352022-01-13
CVE-2022-0196 [HIGH] CWE-352 CVE-2022-0196: phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
nvd
CVE-2023-39365P3MEDIUMCVSS 6.3v37v382023-09-05
CVE-2023-39365 [MEDIUM] CWE-89 CVE-2023-39365: Cacti is an open source operational monitoring and fault management framework. Issues with Cacti Reg
Cacti is an open source operational monitoring and fault management framework. Issues with Cacti Regular Expression validation combined with the external links feature can lead to limited SQL Injections and subsequent data leakage. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this v
nvd
CVE-2022-1632P3MEDIUMCVSS 6.5v34v352022-09-01
CVE-2022-1632 [MEDIUM] CWE-295 CVE-2022-1632: An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinatio
An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting in a loss of confidentiality.
nvd
CVE-2016-0721P3HIGHCVSS 8.1v22v232017-04-21
CVE-2016-0721 [HIGH] CWE-384 CVE-2016-0721: Session fixation vulnerability in pcsd in pcs before 0.9.157.
Session fixation vulnerability in pcsd in pcs before 0.9.157.
nvd
CVE-2016-9399P3HIGHCVSS 7.5v32v332017-03-23
CVE-2016-9399 [HIGH] CWE-617 CVE-2016-9399: The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial
The calcstepsizes function in jpc_dec.c in JasPer 1.900.22 allows remote attackers to cause a denial of service (assertion failure) via unspecified vectors.
nvd