Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 152 of 264
CVE-2022-27940P4HIGHCVSS 7.8v35v36+1 more2022-03-26
CVE-2022-27940 [HIGH] CWE-125 CVE-2022-27940: tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
nvd
CVE-2022-0523P4HIGHCVSS 7.8v35v362022-02-08
CVE-2022-0523 [HIGH] CWE-416 CVE-2022-0523: Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.
nvd
CVE-2020-24342P4HIGHCVSS 7.8v332020-08-13
CVE-2020-24342 [HIGH] CWE-119 CVE-2020-24342: Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism w
Lua through 5.4.0 allows a stack redzone cross in luaO_pushvfstring because a protection mechanism wrongly calls luaD_callnoyield twice in a row.
nvd
CVE-2016-4021P4HIGHCVSS 7.5v22v23+1 more2016-05-26
CVE-2016-4021 [HIGH] CWE-399 CVE-2016-4021: The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to ca
The read_binary function in buffer.c in pgpdump before 0.30 allows context-dependent attackers to cause a denial of service (infinite loop and CPU consumption) via crafted input, as demonstrated by the \xa3\x03 string.
nvd
CVE-2021-26252P4HIGHCVSS 7.8v342022-02-24
CVE-2021-26252 [HIGH] CWE-787 CVE-2021-26252: A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx m
A flaw was found in htmldoc in v1.9.12. Heap buffer overflow in pspdf_prepare_page(),in ps-pdf.cxx may lead to execute arbitrary code and denial of service.
nvd
CVE-2016-1494P4MEDIUMCVSS 5.3v22v232016-01-13
CVE-2016-1494 [MEDIUM] CWE-20 CVE-2016-1494: The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof
The verify function in the RSA package for Python (Python-RSA) before 3.3 allows attackers to spoof signatures with a small public exponent via crafted signature padding, aka a BERserk attack.
nvd
CVE-2010-4743P4MEDIUMCVSS 6.8v13v142011-02-18
CVE-2010-4743 [MEDIUM] CVE-2010-4743: Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow
Heap-based buffer overflow in the getarena function in abc2ps.c in abcm2ps before 5.9.13 might allow remote attackers to execute arbitrary code via a crafted ABC file, a different vulnerability than CVE-2010-3441. NOTE: some of these details are obtained from third party information.
nvd
CVE-2021-33646P4HIGHCVSS 7.5v35v36+1 more2022-08-10
CVE-2021-33646 [HIGH] CWE-401 CVE-2021-33646: The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which
The th_read() function doesn’t free a variable t->th_buf.gnu_longname after allocating memory, which may cause a memory leak.
nvd
CVE-2021-33645P4HIGHCVSS 7.5v35v36+1 more2022-08-10
CVE-2021-33645 [HIGH] CWE-401 CVE-2021-33645: The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which
The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak.
nvd
CVE-2023-20588P4MEDIUMCVSS 5.5v37v38+1 more2023-08-08
CVE-2023-20588 [MEDIUM] CWE-369 CVE-2023-20588: A division-by-zero error on some AMD processors can potentially return speculative data resulting i
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.
nvd
CVE-2010-5298P4MEDIUMCVSS 4.0v19v202014-04-14
CVE-2010-5298 [MEDIUM] CWE-362 CVE-2010-5298: Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_
Race condition in the ssl3_read_bytes function in s3_pkt.c in OpenSSL through 1.0.1g, when SSL_MODE_RELEASE_BUFFERS is enabled, allows remote attackers to inject data across sessions or cause a denial of service (use-after-free and parsing error) via an SSL connection in a multithreaded environment.
nvd
CVE-2022-2819P4HIGHCVSS 7.8v352022-08-15
CVE-2022-2819 [HIGH] CWE-122 CVE-2022-2819: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
nvd
CVE-2022-2946P4HIGHCVSS 7.8v352022-08-23
CVE-2022-2946 [HIGH] CWE-416 CVE-2022-2946: Use After Free in GitHub repository vim/vim prior to 9.0.0246.
Use After Free in GitHub repository vim/vim prior to 9.0.0246.
nvd
CVE-2022-2817P4HIGHCVSS 7.8v352022-08-15
CVE-2022-2817 [HIGH] CWE-416 CVE-2022-2817: Use After Free in GitHub repository vim/vim prior to 9.0.0213.
Use After Free in GitHub repository vim/vim prior to 9.0.0213.
nvd
CVE-2022-2889P4HIGHCVSS 7.8v352022-08-19
CVE-2022-2889 [HIGH] CWE-416 CVE-2022-2889: Use After Free in GitHub repository vim/vim prior to 9.0.0225.
Use After Free in GitHub repository vim/vim prior to 9.0.0225.
nvd
CVE-2022-3016P4HIGHCVSS 7.8v372022-08-28
CVE-2022-3016 [HIGH] CWE-416 CVE-2022-3016: Use After Free in GitHub repository vim/vim prior to 9.0.0286.
Use After Free in GitHub repository vim/vim prior to 9.0.0286.
nvd
CVE-2022-3234P4HIGHCVSS 7.8v35v36+1 more2022-09-17
CVE-2022-3234 [HIGH] CWE-122 CVE-2022-3234: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
nvd
CVE-2022-3037P4HIGHCVSS 7.8v35v36+1 more2022-08-30
CVE-2022-3037 [HIGH] CWE-416 CVE-2022-3037: Use After Free in GitHub repository vim/vim prior to 9.0.0322.
Use After Free in GitHub repository vim/vim prior to 9.0.0322.
nvd
CVE-2022-3297P4HIGHCVSS 7.8v35v36+1 more2022-09-25
CVE-2022-3297 [HIGH] CWE-416 CVE-2022-3297: Use After Free in GitHub repository vim/vim prior to 9.0.0579.
Use After Free in GitHub repository vim/vim prior to 9.0.0579.
nvd
CVE-2022-3352P4HIGHCVSS 7.8v35v36+1 more2022-09-29
CVE-2022-3352 [HIGH] CWE-416 CVE-2022-3352: Use After Free in GitHub repository vim/vim prior to 9.0.0614.
Use After Free in GitHub repository vim/vim prior to 9.0.0614.
nvd