cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 153 of 264
CVE-2022-3235P4HIGHCVSS 7.8v35v36+1 more2022-09-18
CVE-2022-3235 [HIGH] CWE-416 CVE-2022-3235: Use After Free in GitHub repository vim/vim prior to 9.0.0490. Use After Free in GitHub repository vim/vim prior to 9.0.0490.
nvd
CVE-2022-3256P4HIGHCVSS 7.8v35v36+1 more2022-09-22
CVE-2022-3256 [HIGH] CWE-416 CVE-2022-3256: Use After Free in GitHub repository vim/vim prior to 9.0.0530. Use After Free in GitHub repository vim/vim prior to 9.0.0530.
nvd
CVE-2022-3099P4HIGHCVSS 7.8v35v36+1 more2022-09-03
CVE-2022-3099 [HIGH] CWE-416 CVE-2022-3099: Use After Free in GitHub repository vim/vim prior to 9.0.0360. Use After Free in GitHub repository vim/vim prior to 9.0.0360.
nvd
CVE-2022-2849P4HIGHCVSS 7.8v372022-08-17
CVE-2022-2849 [HIGH] CWE-122 CVE-2022-2849: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.
nvd
CVE-2021-41500P4HIGHCVSS 7.5v342021-12-17
CVE-2021-41500 [HIGH] CWE-697 CVE-2021-41500: Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmo Incomplete string comparison vulnerability exits in cvxopt.org cvxop <= 1.2.6 in APIs (cvxopt.cholmod.diag, cvxopt.cholmod.getfactor, cvxopt.cholmod.solve, cvxopt.cholmod.spsolve), which allows attackers to conduct Denial of Service attacks by construct fake Capsule objects.
nvd
CVE-2022-37047P4HIGHCVSS 7.8v35v36+1 more2022-08-18
CVE-2022-37047 [HIGH] CVE-2022-37047: The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940.
nvd
CVE-2022-37048P4HIGHCVSS 7.8v35v36+1 more2022-08-18
CVE-2022-37048 [HIGH] CVE-2022-37048: The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941.
nvd
CVE-2022-37049P4HIGHCVSS 7.8v35v36+1 more2022-08-18
CVE-2022-37049 [HIGH] CVE-2022-37049: The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.
nvd
CVE-2023-46849P4HIGHCVSS 7.5v392023-11-11
CVE-2023-46849 [HIGH] CWE-369 CVE-2023-46849: Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.
nvd
CVE-2024-31582P4HIGHCVSS 7.8v38v39+1 more2024-04-17
CVE-2024-31582 [HIGH] CWE-122 CVE-2024-31582: FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input.
nvd
CVE-2023-41358P4HIGHCVSS 7.5v37v38+1 more2023-08-29
CVE-2023-41358 [HIGH] CWE-476 CVE-2023-41358: An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attri An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
nvd
CVE-2020-15983P4HIGHCVSS 7.8v31v32+1 more2020-11-03
CVE-2020-15983 [HIGH] CWE-20 CVE-2020-15983: Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a l Insufficient data validation in webUI in Google Chrome on ChromeOS prior to 86.0.4240.75 allowed a local attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2021-35561P4MEDIUMCVSS 5.3v33v34+1 more2021-10-20
CVE-2021-35561 [MEDIUM] CVE-2021-35561: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Utility). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compr
nvd
CVE-2019-13117P4MEDIUMCVSS 5.3v312019-07-01
CVE-2019-13117 [MEDIUM] CWE-908 CVE-2019-13117: In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitiali In numbers.c in libxslt 1.1.33, an xsl:number with certain format strings could lead to a uninitialized read in xsltNumberFormatInsertNumbers. This could allow an attacker to discern whether a byte on the stack contains the characters A, a, I, i, or 0, or any other character.
nvd
CVE-2019-6341P4MEDIUMCVSS 5.4v28v292019-03-26
CVE-2019-6341 [MEDIUM] CWE-79 CVE-2019-6341: In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to In Drupal 7 versions prior to 7.65; Drupal 8.6 versions prior to 8.6.13;Drupal 8.5 versions prior to 8.5.14. Under certain circumstances the File module/subsystem allows a malicious user to upload a file that can trigger a cross-site scripting (XSS) vulnerability.
nvd
CVE-2015-8370P3HIGHCVSS 7.4v232015-12-16
CVE-2015-8370 [HIGH] CWE-264 CVE-2015-8370: Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypas Multiple integer underflows in Grub2 1.98 through 2.02 allow physically proximate attackers to bypass authentication, obtain sensitive information, or cause a denial of service (disk corruption) via backspace characters in the (1) grub_username_get function in grub-core/normal/auth.c or the (2) grub_password_get function in lib/crypto.c, which trigger a
nvd
CVE-2007-6601P4HIGHCVSS 7.2v7v82008-01-09
CVE-2007-6601 [HIGH] CVE-2007-6601: The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7 The DBLink module in PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21, when local trust or ident authentication is used, allows remote attackers to gain privileges via unspecified vectors. NOTE: this issue exists because of an incomplete fix for CVE-2007-3278.
nvd
CVE-2021-35586P4MEDIUMCVSS 5.3v33v34+1 more2021-10-20
CVE-2021-35586 [MEDIUM] CVE-2021-35586: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: ImageIO). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compr
nvd
CVE-2021-35578P4MEDIUMCVSS 5.3v33v34+1 more2021-10-20
CVE-2021-35578 [MEDIUM] CVE-2021-35578: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Oracle Gra
nvd
CVE-2019-9433P3MEDIUMCVSS 6.5v30v312019-09-27
CVE-2019-9433 [MEDIUM] CWE-20 CVE-2019-9433: In libvpx, there is a possible information disclosure due to improper input validation. This could l In libvpx, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-80479354
nvd
Fedoraproject Fedora vulnerabilities | cvebase