cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 161 of 264
CVE-2020-6750P4MEDIUMCVSS 5.9v30v312020-01-09
CVE-2020-6750 [MEDIUM] CVE-2020-6750: GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address ins GSocketClient in GNOME GLib through 2.62.4 may occasionally connect directly to a target address instead of connecting via a proxy server when configured to do so, because the proxy_addr field is mishandled. This bug is timing-dependent and may occur only sporadically depending on network delays. The greatest security relevance is in use cases where a proxy i
nvd
CVE-2023-5475P4MEDIUMCVSS 6.5v37v382023-10-11
CVE-2023-5475 [MEDIUM] CVE-2023-5475: Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2019-3880P4MEDIUMCVSS 5.4v28v29+1 more2019-04-09
CVE-2019-3880 [MEDIUM] CWE-22 CVE-2019-3880: A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service A flaw was found in the way samba implemented an RPC endpoint emulating the Windows registry service API. An unprivileged attacker could use this flaw to create a new registry hive file anywhere they have unix permissions which could lead to creation of a new file in the Samba share. Versions before 4.8.11, 4.9.6 and 4.10.2 are vulnerable.
nvd
CVE-2024-5839P4MEDIUMCVSS 6.5v39v402024-06-11
CVE-2024-5839 [MEDIUM] CWE-474 CVE-2024-5839: Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a r Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-5843P4MEDIUMCVSS 6.5v39v402024-06-11
CVE-2024-5843 [MEDIUM] CWE-843 CVE-2024-5843: Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote a Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2021-21392P4MEDIUMCVSS 6.3v342021-04-12
CVE-2021-21392 [MEDIUM] CWE-601 CVE-2021-21392: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.28.0 requests to user provided domains were not restricted to external IP addresses when transitional IPv6 addresses were used. Outbound requests to federation, ide
nvd
CVE-2013-6629P4MEDIUMCVSS 5.0v18v19+1 more2013-11-19
CVE-2013-6629 [MEDIUM] CWE-200 CVE-2013-6629: The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in The get_sos function in jdmarker.c in (1) libjpeg 6b and (2) libjpeg-turbo through 1.3.0, as used in Google Chrome before 31.0.1650.48, Ghostscript, and other products, does not check for certain duplications of component data during the reading of segments that follow Start Of Scan (SOS) JPEG markers, which allows remote attackers to obtain sensitive
nvd
CVE-2021-3672P4MEDIUMCVSS 5.6v33v342021-11-23
CVE-2021-3672 [MEDIUM] CWE-79 CVE-2021-3672: A flaw was found in c-ares library, where a missing input validation check of host names returned by A flaw was found in c-ares library, where a missing input validation check of host names returned by DNS (Domain Name Servers) can lead to output of wrong hostnames which might potentially lead to Domain Hijacking. The highest threat from this vulnerability is to confidentiality and integrity as well as system availability.
nvd
CVE-2013-5619P4HIGHCVSS 7.5v19v202013-12-11
CVE-2013-5619 [HIGH] CWE-190 CVE-2013-5619: Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox be Multiple integer overflows in the binary-search implementation in SpiderMonkey in Mozilla Firefox before 26.0 and SeaMonkey before 2.23 might allow remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted JavaScript code.
nvd
CVE-2021-33910P4MEDIUMCVSS 5.5v33v342021-07-20
CVE-2021-33910 [MEDIUM] CWE-770 CVE-2021-33910: basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with a basic/unit-name.c in systemd prior to 246.15, 247.8, 248.5, and 249.1 has a Memory Allocation with an Excessive Size Value (involving strdupa and alloca for a pathname controlled by a local attacker) that results in an operating system crash.
nvd
CVE-2013-0334P4MEDIUMCVSS 5.0v19v20+1 more2014-10-31
CVE-2013-0334 [MEDIUM] CWE-20 CVE-2013-0334: Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to instal Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
nvd
CVE-2021-40529P4MEDIUMCVSS 5.9v34v352021-09-06
CVE-2021-40529 [MEDIUM] CWE-327 CVE-2021-40529: The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allow The ElGamal implementation in Botan through 2.18.1, as used in Thunderbird and other products, allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exp
nvd
CVE-2016-10027P4MEDIUMCVSS 5.9v252017-01-12
CVE-2016-10027 [MEDIUM] CWE-362 CVE-2016-10027: Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting Race condition in the XMPP library in Smack before 4.1.9, when the SecurityMode.required TLS setting has been set, allows man-in-the-middle attackers to bypass TLS protections and trigger use of cleartext for client authentication by stripping the "starttls" feature from a server response.
nvd
CVE-2020-4048P4MEDIUMCVSS 5.7v32v332020-06-12
CVE-2020-4048 [MEDIUM] CWE-601 CVE-2020-4048: In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, a In affected versions of WordPress, due to an issue in wp_validate_redirect() and URL sanitization, an arbitrary external link can be crafted leading to unintended/open redirect when clicked. This has been patched in version 5.4.2, along with all the previously affected versions via a minor release (5.3.4, 5.2.7, 5.1.6, 5.0.10, 4.9.15, 4.8.14, 4.7.18,
nvd
CVE-2020-28049P4MEDIUMCVSS 6.3v332020-11-04
CVE-2020-28049 [MEDIUM] CWE-362 CVE-2020-28049: An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - fo An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the cli
nvd
CVE-2021-3565P4MEDIUMCVSS 5.9v33v342021-06-04
CVE-2021-3565 [MEDIUM] CWE-665 CVE-2021-3565: A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed A A flaw was found in tpm2-tools in versions before 5.1.1 and before 4.3.2. tpm2_import used a fixed AES key for the inner wrapper, potentially allowing a MITM attacker to unwrap the inner portion and reveal the key being imported. The highest threat from this vulnerability is to data confidentiality.
nvd
CVE-2023-22053P4MEDIUMCVSS 5.9v37v38+1 more2023-07-18
CVE-2023-22053 [MEDIUM] CVE-2023-22053: Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported v Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.42 and prior and 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2023-51764P4MEDIUMCVSS 5.3v38v392023-12-24
CVE-2023-51764 [MEDIUM] CWE-345 CVE-2023-51764: Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_un Postfix through 3.8.5 allows SMTP smuggling unless configured with smtpd_data_restrictions=reject_unauth_pipelining and smtpd_discard_ehlo_keywords=chunking (or certain other options that exist in recent versions). Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass
nvd
CVE-2024-22420P4MEDIUMCVSS 6.1v392024-01-19
CVE-2024-22420 [MEDIUM] CWE-79 CVE-2024-22420: JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jup JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has access to as well as perform arbitrary
nvd
CVE-2017-5357P4HIGHCVSS 7.5v252017-02-17
CVE-2017-5357 [HIGH] CWE-416 CVE-2017-5357: regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malforme regex.c in GNU ed before 1.14.1 allows attackers to cause a denial of service (crash) via a malformed command, which triggers an invalid free.
nvd
Fedoraproject Fedora vulnerabilities | cvebase