Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 148 of 264
CVE-2019-3011P4MEDIUMCVSS 6.5v29v30+1 more2019-10-16
CVE-2019-3011 [MEDIUM] CVE-2019-3011: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported vers
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to ca
nvd
CVE-2019-9325P3MEDIUMCVSS 6.5v30v312019-09-27
CVE-2019-9325 [MEDIUM] CWE-125 CVE-2019-9325: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to
In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112001302
nvd
CVE-2021-35597P4MEDIUMCVSS 6.5v33v34+1 more2021-10-20
CVE-2021-35597 [MEDIUM] CVE-2021-35597: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2024-32021P3HIGHCVSS 7.1v402024-05-14
CVE-2024-32021 [HIGH] CVE-2024-32021: Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2,
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, when cloning a local source repository that contains symlinks via the filesystem, Git may create hardlinks to arbitrary user-readable files on the same filesystem as the target repository in the `objects/` directory. Cloning a local repository over t
nvd
CVE-2020-14769P4MEDIUMCVSS 6.5v31v32+1 more2020-10-21
CVE-2020-14769 [MEDIUM] CVE-2020-14769: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.49 and prior, 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabil
nvd
CVE-2020-14775P4MEDIUMCVSS 6.5v31v32+1 more2020-10-21
CVE-2020-14775 [MEDIUM] CVE-2020-14775: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.31 and prior and 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2020-2780P4MEDIUMCVSS 6.5v30v31+1 more2020-04-15
CVE-2020-2780 [MEDIUM] CVE-2020-2780: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2015-5154P4HIGHCVSS 7.2v21v22+1 more2015-08-12
CVE-2015-5154 [HIGH] CWE-119 CVE-2015-5154: Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the
Heap-based buffer overflow in the IDE subsystem in QEMU, as used in Xen 4.5.x and earlier, when the container has a CDROM drive enabled, allows local guest users to execute arbitrary code on the host via unspecified ATAPI commands.
nvd
CVE-2020-26257P4MEDIUMCVSS 6.5v32v332020-12-09
CVE-2020-26257 [MEDIUM] CWE-79 CVE-2020-26257: Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homese
Matrix is an ecosystem for open federated Instant Messaging and VoIP. Synapse is a reference "homeserver" implementation of Matrix. A malicious or poorly-implemented homeserver can inject malformed events into a room by specifying a different room id in the path of a `/send_join`, `/send_leave`, `/invite` or `/exchange_third_party_invite` request. Th
nvd
CVE-2021-41091P3MEDIUMCVSS 6.3v34v352021-10-04
CVE-2021-41091 [MEDIUM] CWE-281 CVE-2021-41091: Moby is an open-source project created by Docker to enable software containerization. A bug was foun
Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where the data directory (typically `/var/lib/docker`) contained subdirectories with insufficiently restricted permissions, allowing otherwise unprivileged Linux users to traverse directory contents and execute programs. When
nvd
CVE-2021-35564P4MEDIUMCVSS 5.3v33v34+1 more2021-10-20
CVE-2021-35564 [MEDIUM] CVE-2021-35564: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component
Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Keytool). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compr
nvd
CVE-2020-14539P4MEDIUMCVSS 6.5v31v32+1 more2020-07-15
CVE-2020-14539 [MEDIUM] CVE-2020-14539: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabil
nvd
CVE-2020-14576P4MEDIUMCVSS 6.5v31v32+1 more2020-07-15
CVE-2020-14576 [MEDIUM] CVE-2020-14576: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: UDF). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unaut
nvd
CVE-2021-3743P4HIGHCVSS 7.1v342022-03-04
CVE-2021-3743 [HIGH] CWE-125 CVE-2021-3743: An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux k
An out-of-bounds (OOB) memory read flaw was found in the Qualcomm IPC router protocol in the Linux kernel. A missing sanity check allows a local attacker to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-2172P4MEDIUMCVSS 6.5v32v33+1 more2021-04-22
CVE-2021-2172 [MEDIUM] CVE-2021-2172: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to caus
nvd
CVE-2021-2178P4MEDIUMCVSS 6.5v32v33+1 more2021-04-22
CVE-2021-2178 [MEDIUM] CVE-2021-2178: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supporte
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2020-13645P4MEDIUMCVSS 6.5v31v322020-05-28
CVE-2020-13645 [MEDIUM] CWE-295 CVE-2020-13645: In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname v
In GNOME glib-networking through 2.64.2, the implementation of GTlsClientConnection skips hostname verification of the server's TLS certificate if the application fails to specify the expected server identity. This is in contrast to its intended documented behavior, to fail the certificate verification. Applications that fail to provide the server i
nvd
CVE-2013-4222P4MEDIUMCVSS 6.5v202013-09-30
CVE-2013-4222 [MEDIUM] CWE-522 CVE-2013-4222: OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does
OpenStack Identity (Keystone) Folsom, Grizzly 2013.1.3 and earlier, and Havana before havana-3 does not properly revoke user tokens when a tenant is disabled, which allows remote authenticated users to retain access via the token.
nvd
CVE-2020-14591P4MEDIUMCVSS 6.5v31v32+1 more2020-07-15
CVE-2020-14591 [MEDIUM] CVE-2020-14591: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plug-in). Suppor
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Audit Plug-in). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abi
nvd
CVE-2020-15225P3MEDIUMCVSS 6.5v34v352021-04-29
CVE-2020-15225 [MEDIUM] CWE-681 CVE-2020-15225: django-filter is a generic system for filtering Django QuerySets based on user selections. In django
django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated `NumberFilter` instances, whose value was later converted to an integer, were subject to potential DoS from maliciously input using exponential format with sufficiently large exponents. Version 2.4
nvd