Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 143 of 264
CVE-2020-28242P3MEDIUMCVSS 6.5v332020-11-06
CVE-2020-28242 [MEDIUM] CWE-674 CVE-2020-28242: An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x befor
An issue was discovered in Asterisk Open Source 13.x before 13.37.1, 16.x before 16.14.1, 17.x before 17.8.1, and 18.x before 18.0.1 and Certified Asterisk before 16.8-cert5. If Asterisk is challenged on an outbound INVITE and the nonce is changed in each response, Asterisk will continually send INVITEs in a loop. This causes Asterisk to consume mor
nvd
CVE-2023-4527P3MEDIUMCVSS 6.5v37v38+1 more2023-09-18
CVE-2023-4527 [MEDIUM] CWE-121 CVE-2023-4527: A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family
A flaw was found in glibc. When the getaddrinfo function is called with the AF_UNSPEC address family and the system is configured with no-aaaa mode via /etc/resolv.conf, a DNS response via TCP larger than 2048 bytes can potentially disclose stack contents through the function returned address data, and may cause a crash.
nvd
CVE-2024-23263P3MEDIUMCVSS 6.5v38v39+1 more2024-03-08
CVE-2024-23263 [MEDIUM] CWE-20 CVE-2024-23263: A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2014-1400P3MEDIUMCVSS 6.5v19v202018-04-10
CVE-2014-1400 [MEDIUM] CWE-284 CVE-2014-1400: The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote
The entity_access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions and read unpublished comments via unspecified vectors.
nvd
CVE-2024-23284P3MEDIUMCVSS 6.5v38v39+1 more2024-03-08
CVE-2024-23284 [MEDIUM] CWE-693 CVE-2024-23284: A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
nvd
CVE-2024-31208P3MEDIUMCVSS 6.5v38v39+1 more2024-04-23
CVE-2024-31208 [MEDIUM] CWE-770 CVE-2024-31208: Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a r
Synapse is an open-source Matrix homeserver. A remote Matrix user with malicious intent, sharing a room with Synapse instances before 1.105.1, can dispatch specially crafted events to exploit a weakness in the V2 state resolution algorithm. This can induce high CPU consumption and accumulate excessive data in the database of such instances, resultin
nvd
CVE-2019-19580P3MEDIUMCVSS 6.6v312019-12-11
CVE-2019-19580 [MEDIUM] CVE-2019-19580: An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privile
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to gain host OS privileges by leveraging race conditions in pagetable promotion and demotion operations, because of an incomplete fix for CVE-2019-18421. XSA-299 addressed several critical issues in restartable PV type change operations. Despite extensive testing and auditing, some
nvd
CVE-2014-1399P3MEDIUMCVSS 6.5v19v202018-04-10
CVE-2014-1399 [MEDIUM] CWE-284 CVE-2014-1399: The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow
The entity wrapper access API in the Entity API module 7.x-1.x before 7.x-1.3 for Drupal might allow remote authenticated users to bypass intended access restrictions on referenced entities via unspecified vectors.
nvd
CVE-2020-25700P3MEDIUMCVSS 6.5v32v332020-11-19
CVE-2020-25700 [MEDIUM] CWE-89 CVE-2020-25700: In moodle, some database module web services allowed students to add entries within groups they did
In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.
nvd
CVE-2023-0003P3MEDIUMCVSS 6.5v37v38+1 more2023-02-08
CVE-2023-0003 [MEDIUM] CWE-73 CVE-2023-0003: A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an au
A file disclosure vulnerability in the Palo Alto Networks Cortex XSOAR server software enables an authenticated user with access to the web interface to read local files from the server.
nvd
CVE-2015-7220P4CRITICALCVSS 10.0v22v232015-12-16
CVE-2015-7220 [CRITICAL] CWE-119 CVE-2015-7220: Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0
Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2022-2553P3MEDIUMCVSS 6.5v35v362022-07-28
CVE-2022-2553 [MEDIUM] CWE-287 CVE-2022-2553: The authfile directive in the booth config file is ignored, preventing use of authentication in comm
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
nvd
CVE-2022-24512P3MEDIUMCVSS 6.3v34v35+1 more2022-03-09
CVE-2022-24512 [MEDIUM] CWE-94 CVE-2022-24512: .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
nvd
CVE-2022-24809P3MEDIUMCVSS 6.5v362024-04-16
CVE-2022-24809 [MEDIUM] CWE-476 CVE-2022-24809: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-only credentials can use a malformed OID in a `GET-NEXT` to the `nsVacmAccessTable` to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credenti
nvd
CVE-2022-21541P3MEDIUMCVSS 5.9v362022-07-19
CVE-2022-21541 [MEDIUM] CVE-2022-21541: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 7u343, 8u333, 11.0.15.1, 17.0.3.1, 18.0.1.1; Oracle GraalVM Enterprise Edition: 20.3.6, 21.3.2 and 22.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with netw
nvd
CVE-2022-30699P3MEDIUMCVSS 6.5v35v362022-08-01
CVE-2022-30699 [MEDIUM] CWE-613 CVE-2022-30699: NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost
NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to expire. The rogue nameserver delays the response so that the cached delegation
nvd
CVE-2024-3044P3MEDIUMCVSS 6.5v392024-05-14
CVE-2024-3044 [MEDIUM] CWE-356 CVE-2024-3044: Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an at
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previously deemed trusted but are now deemed untrusted.
nvd
CVE-2020-8492P4MEDIUMCVSS 6.5v31v322020-01-30
CVE-2020-8492 [MEDIUM] CWE-400 CVE-2020-8492: Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
nvd
CVE-2023-5455P3MEDIUMCVSS 6.5v38v39+1 more2024-01-10
CVE-2023-5455 [MEDIUM] CWE-352 CVE-2023-5455: A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported ver
A Cross-site request forgery vulnerability exists in ipa/session/login_password in all supported versions of IPA. This flaw allows an attacker to trick the user into submitting a request that could perform actions as the user, resulting in a loss of confidentiality and system integrity. During community penetration testing it was found that for certai
nvd
CVE-2008-2374P3CRITICALCVSS 9.8v8v92008-07-07
CVE-2008-2374 [CRITICAL] CWE-1284 CVE-2008-2374: src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34
src/sdp.c in bluez-libs 3.30 in BlueZ, and other bluez-libs before 3.34 and bluez-utils before 3.34 versions, does not validate string length fields in SDP packets, which allows remote SDP servers to cause a denial of service or possibly have unspecified other impact via a crafted length field that triggers excessive memory allocation or a buffer ov
nvd