Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 145 of 264
CVE-2022-1927P4HIGHCVSS 7.8v34v35+1 more2022-05-29
CVE-2022-1927 [HIGH] CWE-126 CVE-2022-1927: Buffer Over-read in GitHub repository vim/vim prior to 8.2.
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-0554P3HIGHCVSS 7.8v342022-02-10
CVE-2022-0554 [HIGH] CWE-823 CVE-2022-0554: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2019-19648P4HIGHCVSS 7.8v33v342019-12-09
CVE-2019-19648 [HIGH] CWE-125 CVE-2019-19648: In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsist
In the macho_parse_file functionality in macho/macho.c of YARA 3.11.0, command_size may be inconsistent with the real size. A specially crafted MachO file can cause an out-of-bounds memory access, resulting in Denial of Service (application crash) or potential code execution.
nvd
CVE-2022-1154P3HIGHCVSS 7.8v34v352022-03-30
CVE-2022-1154 [HIGH] CWE-416 CVE-2022-1154: Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
nvd
CVE-2023-31490P3HIGHCVSS 7.5v37v38+1 more2023-05-09
CVE-2023-31490 [HIGH] CVE-2023-31490: An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via t
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
nvd
CVE-2022-0443P4HIGHCVSS 7.8v34v352022-02-02
CVE-2022-0443 [HIGH] CWE-416 CVE-2022-0443: Use After Free in GitHub repository vim/vim prior to 8.2.
Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-0413P4HIGHCVSS 7.8v34v352022-01-30
CVE-2022-0413 [HIGH] CWE-416 CVE-2022-0413: Use After Free in GitHub repository vim/vim prior to 8.2.
Use After Free in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2285P4HIGHCVSS 7.8v35v362022-07-02
CVE-2022-2285 [HIGH] CWE-190 CVE-2022-2285: Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
Integer Overflow or Wraparound in GitHub repository vim/vim prior to 9.0.
nvd
CVE-2021-28021P4HIGHCVSS 7.8v34v352021-10-15
CVE-2021-28021 [HIGH] CWE-787 CVE-2021-28021: Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a craf
Buffer overflow vulnerability in function stbi__extend_receive in stb_image.h in stb 2.26 via a crafted JPEG file.
nvd
CVE-2021-45078P3HIGHCVSS 7.8v34v352021-12-15
CVE-2021-45078 [HIGH] CVE-2021-45078: stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial o
stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix for CVE-2018-12699.
nvd
CVE-2022-2206P4HIGHCVSS 7.8v35v362022-06-26
CVE-2022-2206 [HIGH] CWE-125 CVE-2022-2206: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2289P4HIGHCVSS 7.8v35v362022-07-03
CVE-2022-2289 [HIGH] CWE-416 CVE-2022-2289: Use After Free in GitHub repository vim/vim prior to 9.0.
Use After Free in GitHub repository vim/vim prior to 9.0.
nvd
CVE-2018-18408P4CRITICALCVSS 9.8v28v292018-10-17
CVE-2018-18408 [CRITICAL] CWE-416 CVE-2018-18408: A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets tri
A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecified other impact.
nvd
CVE-2022-2345P4HIGHCVSS 7.8v352022-07-08
CVE-2022-2345 [HIGH] CWE-416 CVE-2022-2345: Use After Free in GitHub repository vim/vim prior to 9.0.0046.
Use After Free in GitHub repository vim/vim prior to 9.0.0046.
nvd
CVE-2019-13281P4HIGHCVSS 7.8v29v30+1 more2019-07-04
CVE-2019-13281 [HIGH] CWE-787 CVE-2019-13281: In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stre
In Xpdf 4.01.01, a heap-based buffer overflow could be triggered in DCTStream::decodeImage() in Stream.cc when writing to frameBuf memory. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service, an information leak, or possibly unspecified ot
nvd
CVE-2013-7089P4HIGHCVSS 7.5v17v182019-11-15
CVE-2013-7089 [HIGH] CWE-200 CVE-2013-7089: ClamAV before 0.97.7: dbg_printhex possible information leak
ClamAV before 0.97.7: dbg_printhex possible information leak
nvd
CVE-2022-0676P4HIGHCVSS 7.8v35v362022-02-22
CVE-2022-0676 [HIGH] CWE-122 CVE-2022-0676: Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
nvd
CVE-2019-13282P4HIGHCVSS 7.8v29v30+1 more2019-07-04
CVE-2019-13282 [HIGH] CWE-125 CVE-2019-13282: In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in F
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in SampledFunction::transform in Function.cc when using a large index for samples. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf file to cause Denial of Service or an information leak, or possibly ha
nvd
CVE-2019-13283P4HIGHCVSS 7.8v29v30+1 more2019-07-04
CVE-2019-13283 [HIGH] CWE-125 CVE-2019-13283: In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse i
In Xpdf 4.01.01, a heap-based buffer over-read could be triggered in strncpy from FoFiType1::parse in fofi/FoFiType1.cc because it does not ensure the source string has a valid length before making a fixed-length copy. It can, for example, be triggered by sending a crafted PDF document to the pdftotext tool. It allows an attacker to use a crafted pdf
nvd
CVE-2019-14934P4HIGHCVSS 7.8v29v30+1 more2019-08-11
CVE-2019-14934 [HIGH] CWE-787 CVE-2019-14934: An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a
An issue was discovered in PDFResurrect before 0.18. pdf_load_pages_kids in pdf.c doesn't validate a certain size value, which leads to a malloc failure and out-of-bounds write.
nvd