Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 157 of 264
CVE-2018-14879P4HIGHCVSS 7.0v29v30+1 more2019-10-03
CVE-2018-14879 [HIGH] CWE-120 CVE-2018-14879: The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next
The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().
nvd
CVE-2024-2408P4MEDIUMCVSS 5.9v402024-06-09
CVE-2024-2408 [MEDIUM] CWE-203 CVE-2024-2408: The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which
The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: https://github.com/openssl/openssl/pull/13817 (rsa_pkcs1_implicit_rejection). These changes are part of OpenSS
nvd
CVE-2020-25672P4HIGHCVSS 7.5v32v33+1 more2021-05-25
CVE-2020-25672 [HIGH] CWE-401 CVE-2020-25672: A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
A memory leak vulnerability was found in Linux kernel in llcp_sock_connect
nvd
CVE-2010-4744P4CRITICALCVSS 10.0v13v142011-02-18
CVE-2010-4744 [CRITICAL] CVE-2010-4744: Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors
Multiple unspecified vulnerabilities in abcm2ps before 5.9.13 have unknown impact and attack vectors, a different issue than CVE-2010-3441.
nvd
CVE-2018-17142P4HIGHCVSS 7.5v28v292018-09-17
CVE-2018-17142 [HIGH] CWE-476 CVE-2018-17142: The html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>
The html package (aka x/net/html) through 2018-09-17 in Go mishandles , leading to a "panic: runtime error" in parseCurrentToken in parse.go during an html.Parse call.
nvd
CVE-2018-17143P4HIGHCVSS 7.5v28v292018-09-17
CVE-2018-17143 [HIGH] CWE-119 CVE-2018-17143: The html package (aka x/net/html) through 2018-09-17 in Go mishandles <template><tBody><isindex/acti
The html package (aka x/net/html) through 2018-09-17 in Go mishandles , leading to a "panic: runtime error" in inBodyIM in parse.go during an html.Parse call.
nvd
CVE-2010-0302P4HIGHCVSS 7.5v112010-03-05
CVE-2010-0302 [HIGH] CVE-2010-0302: Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect
Use-after-free vulnerability in the abstract file-descriptor handling interface in the cupsdDoSelect function in scheduler/select.c in the scheduler in cupsd in CUPS before 1.4.4, when kqueue or epoll is used, allows remote attackers to cause a denial of service (daemon crash or hang) via a client disconnection during listing of a large number of print jobs, re
nvd
CVE-2024-29133P4MEDIUMCVSS 5.4v39v402024-03-21
CVE-2024-29133 [MEDIUM] CWE-787 CVE-2024-29133: Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1, which fixes the issue.
nvd
CVE-2023-3347P4MEDIUMCVSS 5.9v382023-07-20
CVE-2023-3347 [MEDIUM] CWE-347 CVE-2023-3347: A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not e
A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to perform attacks, such as a man-in-the-middle attack, by intercepting the net
nvd
CVE-2022-1160P4HIGHCVSS 7.8v34v35+1 more2022-03-30
CVE-2022-1160 [HIGH] CWE-122 CVE-2022-1160: heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
nvd
CVE-2019-8379P4HIGHCVSS 7.8v352019-02-17
CVE-2019-8379 [HIGH] CWE-476 CVE-2019-8379: An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the functio
An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact when a victim opens a specially crafted
nvd
CVE-2014-3152P4HIGHCVSS 7.5v20v21+1 more2014-05-21
CVE-2014-3152 [HIGH] CWE-189 CVE-2014-3152: Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Goo
Integer underflow in the LCodeGen::PrepareKeyedOperand function in arm/lithium-codegen-arm.cc in Google V8 before 3.25.28.16, as used in Google Chrome before 35.0.1916.114, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that trigger a negative key value.
nvd
CVE-2020-5313P4HIGHCVSS 7.1v30v312020-01-03
CVE-2020-5313 [HIGH] CWE-125 CVE-2020-5313: libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
libImaging/FliDecode.c in Pillow before 6.2.2 has an FLI buffer overflow.
nvd
CVE-2022-1620P4HIGHCVSS 7.5v34v35+1 more2022-05-08
CVE-2022-1620 [HIGH] CWE-476 CVE-2022-1620: NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vi
NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 in GitHub repository vim/vim prior to 8.2.4901. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2729 allows attackers to cause a denial of service (application crash) via a crafted input.
nvd
CVE-2023-1993P4MEDIUMCVSS 6.5v36v37+1 more2023-04-12
CVE-2023-1993 [MEDIUM] CWE-834 CVE-2023-1993: LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service v
LISP dissector large loop in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2018-1000880P4MEDIUMCVSS 6.5v29v302018-12-20
CVE-2018-1000880 [MEDIUM] CWE-119 CVE-2018-1000880: libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards)
libarchive version commit 9693801580c0cf7c70e862d305270a16b52826a7 onwards (release v3.2.0 onwards) contains a CWE-20: Improper Input Validation vulnerability in WARC parser - libarchive/archive_read_support_format_warc.c, _warc_read() that can result in DoS - quasi-infinite run time and disk usage from tiny file. This attack appear to be exploit
nvd
CVE-2022-2963P4HIGHCVSS 7.5v362022-10-14
CVE-2022-2963 [HIGH] CWE-401 CVE-2022-2963: A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in
A vulnerability found in jasper. This security vulnerability happens because of a memory leak bug in function cmdopts_parse that can cause a crash or segmentation fault.
nvd
CVE-2022-2816P4HIGHCVSS 7.8v352022-08-15
CVE-2022-2816 [HIGH] CWE-125 CVE-2022-2816: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.
nvd
CVE-2022-2845P4HIGHCVSS 7.8v35v372022-08-17
CVE-2022-2845 [HIGH] CWE-1284 CVE-2022-2845: Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
nvd
CVE-2023-0049P4HIGHCVSS 7.8v36v372023-01-04
CVE-2023-0049 [HIGH] CWE-125 CVE-2023-0049: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.
nvd