Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 140 of 264
CVE-2020-13254P3MEDIUMCVSS 5.9v322020-06-03
CVE-2020-13254 [MEDIUM] CWE-295 CVE-2020-13254: An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. In cases where a memcached backend does not perform key validation, passing malformed cache keys could result in a key collision, and potential data leakage.
nvd
CVE-2022-32546P3HIGHCVSS 7.8v362022-06-16
CVE-2022-32546 [HIGH] CWE-190 CVE-2022-32546: A vulnerability was found in ImageMagick, causing an outside the range of representable values of ty
A vulnerability was found in ImageMagick, causing an outside the range of representable values of type 'unsigned long' at coders/pcl.c, when crafted or untrusted input is processed. This leads to a negative impact to application availability or other problems related to undefined behavior.
nvd
CVE-2022-32547P3HIGHCVSS 7.8v362022-06-16
CVE-2022-32547 [HIGH] CWE-704 CVE-2022-32547: In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignme
In ImageMagick, there is load of misaligned address for type 'double', which requires 8 byte alignment and for type 'float', which requires 4 byte alignment at MagickCore/property.c. Whenever crafted or untrusted input is processed by ImageMagick, this causes a negative impact to application availability or other problems related to undefined behavior
nvd
CVE-2022-1886P3HIGHCVSS 7.8v352022-05-26
CVE-2022-1886 [HIGH] CWE-122 CVE-2022-1886: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2343P3HIGHCVSS 7.8v352022-07-08
CVE-2022-2343 [HIGH] CWE-122 CVE-2022-2343: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0044.
nvd
CVE-2010-4197P3CRITICALCVSS 9.8v132010-11-06
CVE-2010-4197 [CRITICAL] CWE-416 CVE-2010-4197: Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before
Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text editing.
nvd
CVE-2010-4204P3CRITICALCVSS 9.8v132010-11-06
CVE-2010-4204 [CRITICAL] CVE-2010-4204: WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, acce
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, accesses a frame object after this object has been destroyed, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2022-2344P3HIGHCVSS 7.8v352022-07-08
CVE-2022-2344 [HIGH] CWE-122 CVE-2022-2344: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0045.
nvd
CVE-2022-2264P3HIGHCVSS 7.8v35v362022-07-01
CVE-2022-2264 [HIGH] CWE-122 CVE-2022-2264: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.
nvd
CVE-2014-9668P3HIGHCVSS 7.5v20v212015-02-08
CVE-2014-9668 [HIGH] CWE-119 CVE-2014-9668: The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length ca
The woff_open_font function in sfnt/sfobjs.c in FreeType before 2.5.4 proceeds with offset+length calculations without restricting length values, which allows remote attackers to cause a denial of service (integer overflow and heap-based buffer overflow) or possibly have unspecified other impact via a crafted Web Open Font Format (WOFF) file.
nvd
CVE-2015-5291P3MEDIUMCVSS 6.8v21v22+1 more2015-11-02
CVE-2015-5291 [MEDIUM] CWE-119 CVE-2015-5291: Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x
Heap-based buffer overflow in PolarSSL 1.x before 1.2.17 and ARM mbed TLS (formerly PolarSSL) 1.3.x before 1.3.14 and 2.x before 2.1.2 allows remote SSL servers to cause a denial of service (client crash) and possibly execute arbitrary code via a long hostname to the server name indication (SNI) extension, which is not properly handled when creating a
nvd
CVE-2021-32838P3HIGHCVSS 7.5v33v342021-09-20
CVE-2021-32838 [HIGH] CWE-400 CVE-2021-32838: Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX bef
Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This is fixed in version 0.5.1.
nvd
CVE-2021-22922P3MEDIUMCVSS 6.5v332021-08-05
CVE-2021-22922 [MEDIUM] CWE-840 CVE-2021-22922: When curl is instructed to download content using the metalink feature, thecontents is verified agai
When curl is instructed to download content using the metalink feature, thecontents is verified against a hash provided in the metalink XML file.The metalink XML file points out to the client how to get the same contentfrom a set of different URLs, potentially hosted by different servers and theclient can then download the file from one or several o
nvd
CVE-2020-20740P3HIGHCVSS 7.8v32v332020-11-20
CVE-2020-20740 [HIGH] CWE-787 CVE-2020-20740: PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_ver
PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().
nvd
CVE-2023-49528P3HIGHCVSS 8.0v38v39+1 more2024-04-12
CVE-2023-49528 [HIGH] CWE-122 CVE-2023-49528: Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execu
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.
nvd
CVE-2021-42614P3HIGHCVSS 7.8v352022-05-24
CVE-2021-42614 [HIGH] CWE-416 CVE-2021-42614: A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a se
A use after free in info_width_internal in bk_info.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have unspecified other impact via a crafted text document.
nvd
CVE-2022-40188P3HIGHCVSS 7.5v35v36+1 more2022-09-23
CVE-2022-40188 [HIGH] CWE-407 CVE-2022-40188: Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) be
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
nvd
CVE-2020-4047P3MEDIUMCVSS 6.8v32v332020-06-12
CVE-2020-4047 [MEDIUM] CWE-80 CVE-2020-4047: In affected versions of WordPress, authenticated users with upload permissions (like authors) are ab
In affected versions of WordPress, authenticated users with upload permissions (like authors) are able to inject JavaScript into some media file attachment pages in a certain way. This can lead to script execution in the context of a higher privileged user when the file is viewed by them. This has been patched in version 5.4.2, along with all the previ
nvd
CVE-2014-9114P3HIGHCVSS 7.8v20v212017-03-31
CVE-2014-9114 [HIGH] CWE-77 CVE-2014-9114: Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.
nvd
CVE-2023-50967P3HIGHCVSS 7.5v38v39+1 more2024-03-20
CVE-2023-50967 [HIGH] CWE-400 CVE-2023-50967: latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
nvd