Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 139 of 264
CVE-2013-1816P3HIGHCVSS 7.5v182019-11-20
CVE-2013-1816 [HIGH] CWE-20 CVE-2013-1816: MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of servic
MediaWiki before 1.19.4 and 1.20.x before 1.20.3 allows remote attackers to cause a denial of service (application crash) by sending a specially crafted request.
nvd
CVE-2022-27664P3HIGHCVSS 7.5v36v372022-09-06
CVE-2022-27664 [HIGH] CVE-2022-27664: In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service be
In net/http in Go before 1.18.6 and 1.19.x before 1.19.1, attackers can cause a denial of service because an HTTP/2 connection can hang during closing if shutdown were preempted by a fatal error.
nvd
CVE-2020-24265P3HIGHCVSS 7.5v31v32+1 more2020-10-19
CVE-2020-24265 [HIGH] CWE-787 CVE-2020-24265: An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability i
An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in MemcmpInterceptorCommon() that can make tcpprep crash and cause a denial of service.
nvd
CVE-2020-24266P3HIGHCVSS 7.5v31v32+1 more2020-10-19
CVE-2020-24266 [HIGH] CWE-787 CVE-2020-24266: An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability i
An issue was discovered in tcpreplay tcpprep v4.3.3. There is a heap buffer overflow vulnerability in get_l2len() that can make tcpprep crash and cause a denial of service.
nvd
CVE-2016-3071P3HIGHCVSS 7.5v23v242016-04-18
CVE-2016-3071 [HIGH] CWE-20 CVE-2016-3071: Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKE
Libreswan 3.16 might allow remote attackers to cause a denial of service (daemon restart) via an IKEv2 aes_xcbc transform.
nvd
CVE-2022-0685P3HIGHCVSS 7.8v342022-02-20
CVE-2022-0685 [HIGH] CWE-823 CVE-2022-0685: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.
nvd
CVE-2021-22173P3HIGHCVSS 7.5v32v332021-02-17
CVE-2021-22173 [HIGH] CWE-401 CVE-2021-22173: Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet inj
Memory leak in USB HID dissector in Wireshark 3.4.0 to 3.4.2 allows denial of service via packet injection or crafted capture file
nvd
CVE-2022-1851P3HIGHCVSS 7.8v34v35+1 more2022-05-25
CVE-2022-1851 [HIGH] CWE-125 CVE-2022-1851: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2008-4577P3HIGHCVSS 7.5v8v92008-10-15
CVE-2008-4577 [HIGH] CWE-863 CVE-2008-4577: The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access
The ACL plugin in Dovecot before 1.1.4 treats negative access rights as if they are positive access rights, which allows attackers to bypass intended access restrictions.
nvd
CVE-2019-19917P3HIGHCVSS 7.8v31v32+1 more2019-12-20
CVE-2019-19917 [HIGH] CWE-120 CVE-2019-19917: Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.
nvd
CVE-2019-17592P3HIGHCVSS 7.5v312019-10-14
CVE-2019-17592 [HIGH] CWE-400 CVE-2019-17592: The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service.
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.
nvd
CVE-2022-2124P3HIGHCVSS 7.8v35v362022-06-19
CVE-2022-2124 [HIGH] CWE-126 CVE-2022-2124: Buffer Over-read in GitHub repository vim/vim prior to 8.2.
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2126P3HIGHCVSS 7.8v35v362022-06-19
CVE-2022-2126 [HIGH] CWE-125 CVE-2022-2126: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2182P3HIGHCVSS 7.8v35v362022-06-23
CVE-2022-2182 [HIGH] CWE-122 CVE-2022-2182: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2019-9210P3HIGHCVSS 7.8v302019-02-27
CVE-2019-9210 [HIGH] CWE-125 CVE-2019-9210: In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an
In AdvanceCOMP 2.1, png_compress in pngex.cc in advpng has an integer overflow upon encountering an invalid PNG size, which results in an attempted memcpy to write into a buffer that is too small. (There is also a heap-based buffer over-read.)
nvd
CVE-2022-1898P3HIGHCVSS 7.8v34v35+1 more2022-05-27
CVE-2022-1898 [HIGH] CWE-416 CVE-2022-1898: Use After Free in GitHub repository vim/vim prior to 8.2.
Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2207P3HIGHCVSS 7.8v35v362022-06-27
CVE-2022-2207 [HIGH] CWE-122 CVE-2022-2207: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2284P3HIGHCVSS 7.8v35v362022-07-02
CVE-2022-2284 [HIGH] CWE-122 CVE-2022-2284: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
nvd
CVE-2019-19911P3HIGHCVSS 7.5v302020-01-05
CVE-2019-19911 [HIGH] CWE-190 CVE-2019-19911: There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range fu
There is a DoS vulnerability in Pillow before 6.2.2 caused by FpxImagePlugin.py calling the range function on an unvalidated 32-bit integer if the number of bands is large. On Windows running 32-bit Python, this results in an OverflowError or MemoryError due to the 2 GB limit. However, on Linux running 64-bit Python this results in the process being t
nvd
CVE-2020-26521P3HIGHCVSS 7.5v332020-11-06
CVE-2020-26521 [HIGH] CWE-476 CVE-2020-26521: The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go
The JWT library in NATS nats-server before 2.1.9 allows a denial of service (a nil dereference in Go code).
nvd