cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 147 of 264
CVE-2020-24977P4MEDIUMCVSS 6.5v31v32+1 more2020-09-04
CVE-2020-24977 [MEDIUM] CWE-125 CVE-2020-24977: GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesIntern GNOME project libxml2 v2.9.10 has a global buffer over-read vulnerability in xmlEncodeEntitiesInternal at libxml2/entities.c. The issue has been fixed in commit 50f06b3e.
nvd
CVE-2022-38150P3HIGHCVSS 7.5v35v362022-08-11
CVE-2022-38150 [HIGH] CWE-400 CVE-2022-38150: In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to asser In Varnish Cache 7.0.0, 7.0.1, 7.0.2, and 7.1.0, it is possible to cause the Varnish Server to assert and automatically restart through forged HTTP/1 backend responses. An attack uses a crafted reason phrase of the backend response status line. This is fixed in 7.0.3 and 7.1.1.
nvd
CVE-2016-5384P4HIGHCVSS 7.8v23v242016-08-13
CVE-2016-5384 [HIGH] CWE-415 CVE-2016-5384: fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary fr fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
nvd
CVE-2019-5819P4HIGHCVSS 7.8v29v302019-06-27
CVE-2019-5819 [HIGH] CWE-20 CVE-2019-5819: Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allo Insufficient data validation in developer tools in Google Chrome on OS X prior to 74.0.3729.108 allowed a local attacker to execute arbitrary code via a crafted string copied to clipboard.
nvd
CVE-2023-34432P4HIGHCVSS 7.8v382023-07-10
CVE-2023-34432 [HIGH] CWE-122 CVE-2023-34432: A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/format A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.
nvd
CVE-2023-44271P4HIGHCVSS 7.5v382023-11-03
CVE-2023-44271 [HIGH] CWE-770 CVE-2023-44271: An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably alloc An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
nvd
CVE-2022-1769P4HIGHCVSS 7.8v34v35+1 more2022-05-17
CVE-2022-1769 [HIGH] CWE-126 CVE-2022-1769: Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974. Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.
nvd
CVE-2013-4161P4HIGHCVSS 7.8v18v192019-12-31
CVE-2013-4161 [HIGH] CVE-2013-4161: gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was imprope gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.
nvd
CVE-2019-3500P4HIGHCVSS 7.8v28v29+1 more2019-01-02
CVE-2019-3500 [HIGH] CWE-532 CVE-2019-3500: aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and pass aria2c in aria2 1.33.1, when --log is used, can store an HTTP Basic Authentication username and password in a file, which might allow local users to obtain sensitive information by reading this file.
nvd
CVE-2022-32205P4MEDIUMCVSS 4.3v352022-07-07
CVE-2022-32205 [MEDIUM] CWE-770 CVE-2022-32205: A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl a A malicious server can serve excessive amounts of `Set-Cookie:` headers in a HTTP response to curl and curl < 7.84.0 stores all of them. A sufficiently large amount of (big) cookies make subsequent HTTP requests to this, or other servers to which the cookies match, create requests that become larger than the threshold that curl uses internally to av
nvd
CVE-2023-33204P4HIGHCVSS 7.8v37v382023-05-18
CVE-2023-33204 [HIGH] CVE-2023-33204: sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
nvd
CVE-2023-51791P4HIGHCVSS 7.8v38v39+1 more2024-04-19
CVE-2023-51791 [HIGH] CWE-125 CVE-2023-51791: Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arb Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.
nvd
CVE-2024-3772P4HIGHCVSS 7.5v382024-04-15
CVE-2024-3772 [HIGH] CWE-1333 CVE-2024-3772: Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
nvd
CVE-2016-10937P4HIGHCVSS 7.5v30v312019-09-08
CVE-2016-10937 [HIGH] CWE-295 CVE-2016-10937: IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate. IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
nvd
CVE-2023-41909P4HIGHCVSS 7.5v37v38+1 more2023-09-05
CVE-2023-41909 [HIGH] CWE-476 CVE-2023-41909: An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
nvd
CVE-2008-2575P3MEDIUMCVSS 6.8v7v8+1 more2008-06-06
CVE-2008-2575 [MEDIUM] CWE-78 CVE-2008-2575: cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell cbrPager before 0.9.17 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a (1) ZIP (aka .cbz) or (2) RAR (aka .cbr) archive filename.
nvd
CVE-2022-25313P4MEDIUMCVSS 6.5v34v352022-02-18
CVE-2022-25313 [MEDIUM] CWE-674 CVE-2022-25313: In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.
nvd
CVE-2023-34241P4HIGHCVSS 7.1v37v382023-06-22
CVE-2023-34241 [HIGH] CWE-416 CVE-2023-34241: OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like op OpenPrinting CUPS is a standards-based, open source printing system for Linux and other Unix-like operating systems. Starting in version 2.0.0 and prior to version 2.4.6, CUPS logs data of free memory to the logging service AFTER the connection has been closed, when it should have logged the data right before. This is a use-after-free bug that impacts
nvd
CVE-2020-14619P4MEDIUMCVSS 6.5v31v32+1 more2020-07-15
CVE-2020-14619 [MEDIUM] CVE-2020-14619: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2021-3114P4MEDIUMCVSS 6.5v332021-01-26
CVE-2021-3114 [MEDIUM] CWE-682 CVE-2021-3114: In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect output In Go before 1.14.14 and 1.15.x before 1.15.7, crypto/elliptic/p224.go can generate incorrect outputs, related to an underflow of the lowest limb during the final complete reduction in the P-224 field.
nvd
Fedoraproject Fedora vulnerabilities | cvebase