cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 146 of 264
CVE-2022-26126P4HIGHCVSS 7.8v34v35+1 more2022-03-03
CVE-2022-26126 [HIGH] CWE-119 CVE-2022-26126: Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non Buffer overflow vulnerabilities exist in FRRouting through 8.1.0 due to the use of strdup with a non-zero-terminated binary string in isis_nb_notifications.c.
nvd
CVE-2020-15395P4HIGHCVSS 7.8v322020-06-30
CVE-2020-15395 [HIGH] CWE-125 CVE-2020-15395: In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fil In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing).
nvd
CVE-2015-8400P4HIGHCVSS 7.4v22v232016-01-12
CVE-2015-8400 [HIGH] CWE-254 CVE-2015-8400: The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier fo The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.
nvd
CVE-2019-19005P4HIGHCVSS 7.8v342021-02-11
CVE-2019-19005 [HIGH] CVE-2019-19005: A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact v A bitmap double free in main.c in autotrace 0.31.1 allows attackers to cause an unspecified impact via a malformed bitmap image. This may occur after the use-after-free in CVE-2017-9182.
nvd
CVE-2020-19752P4HIGHCVSS 7.5v33v342021-09-07
CVE-2020-19752 [HIGH] CWE-476 CVE-2020-19752: The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference. The find_color_or_error function in gifsicle 1.92 contains a NULL pointer dereference.
nvd
CVE-2021-42612P4HIGHCVSS 7.8v352022-05-24
CVE-2021-42612 [HIGH] CWE-416 CVE-2021-42612: A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentati A use after free in cleanup_index in index.c in Halibut 1.2 allows an attacker to cause a segmentation fault or possibly have other unspecified impact via a crafted text document.
nvd
CVE-2022-2982P4HIGHCVSS 7.8v372022-08-25
CVE-2022-2982 [HIGH] CWE-416 CVE-2022-2982: Use After Free in GitHub repository vim/vim prior to 9.0.0260. Use After Free in GitHub repository vim/vim prior to 9.0.0260.
nvd
CVE-2022-2862P4HIGHCVSS 7.8v372022-08-17
CVE-2022-2862 [HIGH] CWE-416 CVE-2022-2862: Use After Free in GitHub repository vim/vim prior to 9.0.0221. Use After Free in GitHub repository vim/vim prior to 9.0.0221.
nvd
CVE-2020-16154P4HIGHCVSS 7.8v352021-12-13
CVE-2020-16154 [HIGH] CWE-347 CVE-2020-16154: The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass. The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.
nvd
CVE-2021-3842P4HIGHCVSS 7.5v352022-01-04
CVE-2021-3842 [HIGH] CWE-1333 CVE-2021-3842: nltk is vulnerable to Inefficient Regular Expression Complexity nltk is vulnerable to Inefficient Regular Expression Complexity
nvd
CVE-2021-43818P3HIGHCVSS 7.1v34v352021-12-13
CVE-2021-43818 [HIGH] CWE-74 CVE-2021-43818: lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HT lxml is a library for processing XML and HTML in the Python language. Prior to version 4.6.5, the HTML Cleaner in lxml.html lets certain crafted script content pass through, as well as script content in SVG files embedded using data URIs. Users that employ the HTML cleaner in a security relevant context should upgrade to lxml 4.6.5 to receive a patch.
nvd
CVE-2022-3109P4HIGHCVSS 7.5v362022-12-16
CVE-2022-3109 [HIGH] CWE-476 CVE-2022-3109: An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks chec An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.
nvd
CVE-2021-35565P4MEDIUMCVSS 5.3v33v34+1 more2021-10-20
CVE-2021-35565 [MEDIUM] CVE-2021-35565: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle
nvd
CVE-2023-4752P4HIGHCVSS 7.8v37v38+1 more2023-09-04
CVE-2023-4752 [HIGH] CWE-416 CVE-2023-4752: Use After Free in GitHub repository vim/vim prior to 9.0.1858. Use After Free in GitHub repository vim/vim prior to 9.0.1858.
nvd
CVE-2023-5535P4HIGHCVSS 7.8v37v38+1 more2023-10-11
CVE-2023-5535 [HIGH] CWE-416 CVE-2023-5535: Use After Free in GitHub repository vim/vim prior to v9.0.2010. Use After Free in GitHub repository vim/vim prior to v9.0.2010.
nvd
CVE-2023-4733P4HIGHCVSS 7.8v37v38+1 more2023-09-04
CVE-2023-4733 [HIGH] CWE-416 CVE-2023-4733: Use After Free in GitHub repository vim/vim prior to 9.0.1840. Use After Free in GitHub repository vim/vim prior to 9.0.1840.
nvd
CVE-2023-4750P4HIGHCVSS 7.8v37v38+1 more2023-09-04
CVE-2023-4750 [HIGH] CWE-416 CVE-2023-4750: Use After Free in GitHub repository vim/vim prior to 9.0.1857. Use After Free in GitHub repository vim/vim prior to 9.0.1857.
nvd
CVE-2022-3296P4HIGHCVSS 7.8v35v36+1 more2022-09-25
CVE-2022-3296 [HIGH] CWE-121 CVE-2022-3296: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
nvd
CVE-2022-3324P4HIGHCVSS 7.8v35v36+1 more2022-09-27
CVE-2022-3324 [HIGH] CWE-121 CVE-2022-3324: Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
nvd
CVE-2022-29824P4MEDIUMCVSS 6.5v34v35+1 more2022-05-03
CVE-2022-29824 [MEDIUM] CWE-190 CVE-2022-29824: In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software using libxml2's buffer functions, for example libxslt through 1.1.35, is af
nvd
Fedoraproject Fedora vulnerabilities | cvebase