cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 162 of 264
CVE-2023-27043P4MEDIUMCVSS 5.3v38v392023-04-19
CVE-2023-27043 [MEDIUM] CWE-20 CVE-2023-27043: The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special The email module of Python through 3.11.3 incorrectly parses e-mail addresses that contain a special character. The wrong portion of an RFC2822 header is identified as the value of the addr-spec. In some applications, an attacker can bypass a protection mechanism in which application access is granted only after verifying receipt of e-mail to a speci
nvd
CVE-2010-3702P4HIGHCVSS 7.5v12v13+1 more2010-11-05
CVE-2010-3702 [HIGH] CWE-476 CVE-2010-3702: The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other The Gfx::getPos function in the PDF parser in xpdf before 3.02pl5, poppler 0.8.7 and possibly other versions up to 0.15.1, CUPS, kdegraphics, and possibly other products allows context-dependent attackers to cause a denial of service (crash) via unknown vectors that trigger an uninitialized pointer dereference.
nvd
CVE-2020-36277P4HIGHCVSS 7.5v32v332021-03-11
CVE-2020-36277 [HIGH] CWE-670 CVE-2020-36277: Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift i Leptonica before 1.80.0 allows a denial of service (application crash) via an incorrect left shift in pixConvert2To8 in pixconv.c.
nvd
CVE-2019-12802P4HIGHCVSS 7.8v29v302019-06-13
CVE-2019-12802 [HIGH] CWE-416 CVE-2019-12802: In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing contex In radare2 through 3.5.1, the rcc_context function of libr/egg/egg_lang.c mishandles changing context. This allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact (invalid memory access in r_egg_lang_parsechar; invalid free in rcc_pusharg).
nvd
CVE-2015-7977P4MEDIUMCVSS 5.9v22v232017-01-30
CVE-2015-7977 [MEDIUM] CWE-476 CVE-2015-7977: ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of serv ntpd in NTP before 4.2.8p6 and 4.3.x before 4.3.90 allows remote attackers to cause a denial of service (NULL pointer dereference) via a ntpdc reslist command.
nvd
CVE-2015-8837P4HIGHCVSS 7.3v16v172016-03-30
CVE-2015-8837 [HIGH] CWE-119 CVE-2015-8837: Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows Stack-based buffer overflow in the isofs_real_readdir function in isofs.c in FuseISO 20070708 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long pathname in an ISO file.
nvd
CVE-2021-33203P4MEDIUMCVSS 4.9v352021-06-08
CVE-2021-33203 [MEDIUM] CWE-22 CVE-2021-33203: Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal Django before 2.2.24, 3.x before 3.1.12, and 3.2.x before 3.2.4 has a potential directory traversal via django.contrib.admindocs. Staff members could use the TemplateDetailView view to check the existence of arbitrary files. Additionally, if (and only if) the default admindocs templates have been customized by application developers to also show file
nvd
CVE-2015-6524P4MEDIUMCVSS 5.0v22v232015-08-24
CVE-2015-6524 [MEDIUM] CVE-2015-6524: The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Ap The LDAPLoginModule implementation in the Java Authentication and Authorization Service (JAAS) in Apache ActiveMQ 5.x before 5.10.1 allows wildcard operators in usernames, which allows remote attackers to obtain credentials via a brute force attack. NOTE: this identifier was SPLIT from CVE-2014-3612 per ADT2 due to different vulnerability types.
nvd
CVE-2016-10132P4HIGHCVSS 7.5v252017-03-24
CVE-2016-10132 [HIGH] CWE-476 CVE-2016-10132: regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer regexp.c in Artifex Software, Inc. MuJS allows attackers to cause a denial of service (NULL pointer dereference and crash) via vectors related to regular expression compilation.
nvd
CVE-2019-8377P4HIGHCVSS 7.8v28v29+3 more2019-02-17
CVE-2019-8377 [HIGH] CWE-476 CVE-2019-8377: An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ipv6_l4proto() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
nvd
CVE-2019-8376P4HIGHCVSS 7.8v28v29+1 more2019-02-17
CVE-2019-8376 [HIGH] CWE-476 CVE-2019-8376: An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_ An issue was discovered in Tcpreplay 4.3.1. A NULL pointer dereference occurred in the function get_layer4_v6() located at get.c. This can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
nvd
CVE-2019-8381P4HIGHCVSS 7.8v28v29+1 more2019-02-17
CVE-2019-8381 [HIGH] CWE-119 CVE-2019-8381: An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checks An issue was discovered in Tcpreplay 4.3.1. An invalid memory access occurs in do_checksum in checksum.c. It can be triggered by sending a crafted pcap file to the tcpreplay-edit binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or possibly have unspecified other impact.
nvd
CVE-2019-16168P4MEDIUMCVSS 6.5v302019-09-09
CVE-2019-16168 [MEDIUM] CWE-369 CVE-2019-16168: In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other applicati In SQLite through 3.29.0, whereLoopAddBtreeIndex in sqlite3.c can crash a browser or other application because of missing validation of a sqlite_stat1 sz field, aka a "severe division by zero in the query planner."
nvd
CVE-2021-45290P4HIGHCVSS 7.5v34v352021-12-21
CVE-2021-45290 [HIGH] CWE-617 CVE-2021-45290: A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_un A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.
nvd
CVE-2022-0714P4MEDIUMCVSS 5.5v34v352022-02-22
CVE-2022-0714 [MEDIUM] CWE-122 CVE-2022-0714: Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436. Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4436.
nvd
CVE-2015-8836P4HIGHCVSS 7.3v16v172016-03-30
CVE-2015-8836 [HIGH] CWE-119 CVE-2015-8836: Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remot Integer overflow in the isofs_real_read_zf function in isofs.c in FuseISO 20070708 might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a large ZF block size in an ISO file, leading to a heap-based buffer overflow.
nvd
CVE-2022-39831P4HIGHCVSS 7.8v36v372022-09-05
CVE-2022-39831 [HIGH] CVE-2022-39831: An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_by An issue was discovered in PSPP 1.6.2. There is a heap-based buffer overflow at the function read_bytes_internal in utilities/pspp-dump-sav.c, which allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact. This issue is different from CVE-2018-20230.
nvd
CVE-2024-27507P4HIGHCVSS 7.5v38v39+1 more2024-02-27
CVE-2024-27507 [HIGH] CWE-401 CVE-2024-27507: libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp. libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.
nvd
CVE-2022-47021P4HIGHCVSS 7.8v36v372023-01-20
CVE-2022-47021 [HIGH] CWE-476 CVE-2022-47021: A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.
nvd
CVE-2016-2316P4MEDIUMCVSS 5.9v22v232016-02-22
CVE-2016-2316 [MEDIUM] CWE-191 CVE-2016-2316: chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certif chan_sip in Asterisk Open Source 1.8.x, 11.x before 11.21.1, 12.x, and 13.x before 13.7.1 and Certified Asterisk 1.8.28, 11.6 before 11.6-cert12, and 13.1 before 13.1-cert3, when the timert1 sip.conf configuration is set to a value greater than 1245, allows remote attackers to cause a denial of service (file descriptor consumption) via vectors related
nvd
Fedoraproject Fedora vulnerabilities | cvebase