Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 155 of 264
CVE-2021-22207P4MEDIUMCVSS 6.5v33v342021-04-23
CVE-2021-22207 [MEDIUM] CWE-770 CVE-2021-22207: Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 all
Excessive memory consumption in MS-WSP dissector in Wireshark 3.4.0 to 3.4.4 and 3.2.0 to 3.2.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2023-32681P4MEDIUMCVSS 6.1v372023-05-26
CVE-2023-32681 [MEDIUM] CWE-200 CVE-2023-32681: Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization head
Requests is a HTTP library. Since Requests 2.3.0, Requests has been leaking Proxy-Authorization headers to destination servers when redirected to an HTTPS endpoint. This is a product of how we use `rebuild_proxies` to reattach the `Proxy-Authorization` header to requests. For HTTP connections sent through the tunnel, the proxy will identify the head
nvd
CVE-2020-28591P4MEDIUMCVSS 6.5v32v33+1 more2021-03-03
CVE-2020-28591 [MEDIUM] CWE-20 CVE-2020-28591: An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functional
An out-of-bounds read vulnerability exists in the AMF File AMFParserContext::endElement() functionality of Slic3r libslic3r 1.3.0 and Master Commit 92abbc42. A specially crafted AMF file can lead to information disclosure. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2019-2914P4MEDIUMCVSS 6.5v29v30+1 more2019-10-16
CVE-2019-2914 [MEDIUM] CVE-2019-2914: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can
nvd
CVE-2022-26280P4MEDIUMCVSS 6.5v362022-03-28
CVE-2022-26280 [MEDIUM] CWE-125 CVE-2022-26280: Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_
Libarchive v3.6.0 was discovered to contain an out-of-bounds read via the component zipx_lzma_alone_init.
nvd
CVE-2020-4030P4MEDIUMCVSS 6.5v31v322020-06-22
CVE-2020-4030 [MEDIUM] CWE-125 CVE-2020-4030: In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass s
In FreeRDP before version 2.1.2, there is an out of bounds read in TrioParse. Logging might bypass string length checks due to an integer overflow. This is fixed in version 2.1.2.
nvd
CVE-2021-21212P4MEDIUMCVSS 6.5v32v33+1 more2021-04-26
CVE-2021-21212 [MEDIUM] CVE-2021-21212: Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowe
Incorrect security UI in Network Config UI in Google Chrome on ChromeOS prior to 90.0.4430.72 allowed a remote attacker to potentially compromise WiFi connection security via a malicious WAP.
nvd
CVE-2022-3551P4MEDIUMCVSS 6.5v35v36+1 more2022-10-17
CVE-2022-3551 [MEDIUM] CWE-404 CVE-2022-3551: A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by th
A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211052.
nvd
CVE-2020-15113P4HIGHCVSS 7.1v322020-08-05
CVE-2020-15113 [HIGH] CWE-281 CVE-2020-15113: In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory
In etcd before versions 3.3.23 and 3.4.10, certain directory paths are created (etcd data directory and the directory path when provided to automatically generate self-signed certificates for TLS connections with clients) with restricted access permissions (700) by using the os.MkdirAll. This function does not perform any permission checks when a given
nvd
CVE-2023-6270P4HIGHCVSS 7.0v392024-01-04
CVE-2023-6270 [HIGH] CWE-416 CVE-2023-6270: A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() fu
A flaw was found in the ATA over Ethernet (AoE) driver in the Linux kernel. The aoecmd_cfg_pkts() function improperly updates the refcnt on `struct net_device`, and a use-after-free can be triggered by racing between the free on the struct and the access through the `skbtxq` global queue. This could lead to a denial of service condition or potential cod
nvd
CVE-2022-24737P4MEDIUMCVSS 6.5v34v35+1 more2022-03-07
CVE-2022-24737 [MEDIUM] CWE-200 CVE-2022-24737: HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users
HTTPie is a command-line HTTP client. HTTPie has the practical concept of sessions, which help users to persistently store some of the state that belongs to the outgoing requests and incoming responses on the disk for further usage. Before 3.1.0, HTTPie didn‘t distinguish between cookies and hosts they belonged. This behavior resulted in the exposur
nvd
CVE-2021-3524P4MEDIUMCVSS 6.5v32v33+1 more2021-05-17
CVE-2021-3524 [MEDIUM] CVE-2021-3524: A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.2
A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file generates a header injection in the response when the CORS request is made. In addition, t
nvd
CVE-2020-12050P4HIGHCVSS 7.0v30v31+1 more2020-04-30
CVE-2020-12050 [HIGH] CWE-362 CVE-2020-12050: SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition lea
SQLiteODBC 0.9996, as packaged for certain Linux distributions as 0.9996-4, has a race condition leading to root privilege escalation because any user can replace a /tmp/sqliteodbc$$ file with new contents that cause loading of an arbitrary library.
nvd
CVE-2022-2961P4HIGHCVSS 7.0v362022-08-29
CVE-2022-2961 [HIGH] CWE-416 CVE-2022-2961: A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user trigg
A use-after-free flaw was found in the Linux kernel’s PLP Rose functionality in the way a user triggers a race condition by calling bind while simultaneously triggering the rose_bind() function. This flaw allows a local user to crash or potentially escalate their privileges on the system.
nvd
CVE-2021-28972P4MEDIUMCVSS 6.7v32v33+1 more2021-03-22
CVE-2021-28972 [MEDIUM] CWE-120 CVE-2021-28972: In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driv
In drivers/pci/hotplug/rpadlpar_sysfs.c in the Linux kernel through 5.11.8, the RPA PCI Hotplug driver has a user-tolerable buffer overflow when writing a new device name to the driver from userspace, allowing userspace to write data to the kernel stack frame directly. This occurs because add_slot_store and remove_slot_store mishandle drc_name '\0'
nvd
CVE-2022-42011P4MEDIUMCVSS 6.5v35v36+1 more2022-10-10
CVE-2022-42011 [MEDIUM] CWE-129 CVE-2022-42011: An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type.
nvd
CVE-2022-42012P4MEDIUMCVSS 6.5v35v36+1 more2022-10-10
CVE-2022-42012 [MEDIUM] CWE-20 CVE-2022-42012: An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format.
nvd
CVE-2020-14928P3MEDIUMCVSS 5.9v312020-07-17
CVE-2020-14928 [MEDIUM] CWE-74 CVE-2020-14928: evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3
evolution-data-server (eds) through 3.36.3 has a STARTTLS buffering issue that affects SMTP and POP3. When a server sends a "begin TLS" response, eds reads additional data and evaluates it in a TLS context, aka "response injection."
nvd
CVE-2023-4001P4MEDIUMCVSS 6.8v38v392024-01-15
CVE-2023-4001 [MEDIUM] CWE-290 CVE-2023-4001: An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device t
An authentication bypass flaw was found in GRUB due to the way that GRUB uses the UUID of a device to search for the configuration file that contains the password hash for the GRUB password protection feature. An attacker capable of attaching an external drive such as a USB stick containing a file system with a duplicate UUID (the same as in the "/boo
nvd
CVE-2024-23280P4MEDIUMCVSS 6.5v38v39+1 more2024-03-08
CVE-2024-23280 [MEDIUM] CWE-74 CVE-2024-23280: An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 1
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
nvd