cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 163 of 264
CVE-2024-28084P4HIGHCVSS 7.5v39v402024-03-03
CVE-2024-28084 [HIGH] CWE-665 CVE-2024-28084: p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service ( p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.
nvd
CVE-2013-2064P4MEDIUMCVSS 6.8v192013-06-15
CVE-2013-2064 [MEDIUM] CWE-189 CVE-2013-2064: Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insuffici Integer overflow in X.org libxcb 1.9 and earlier allows X servers to trigger allocation of insufficient memory and a buffer overflow via vectors related to the read_packet function.
nvd
CVE-2019-1000020P4MEDIUMCVSS 6.5v292019-02-04
CVE-2019-1000020 [MEDIUM] CWE-835 CVE-2019-1000020: libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) libarchive version commit 5a98dcf8a86364b3c2c469c85b93647dfb139961 onwards (version v2.8.0 onwards) contains a CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in ISO9660 parser, archive_read_support_format_iso9660.c, read_CE()/parse_rockridge() that can result in DoS by infinite loop. This attack appears to be exploi
nvd
CVE-2022-0891P4HIGHCVSS 7.1v35v362022-03-10
CVE-2022-0891 [HIGH] CWE-787 CVE-2022-0891: A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3. A heap buffer overflow in ExtractImageSection function in tiffcrop.c in libtiff library Version 4.3.0 allows attacker to trigger unsafe or out of bounds memory access via crafted TIFF image file which could result into application crash, potential information disclosure or any other context-dependent impact
nvd
CVE-2015-5745P4MEDIUMCVSS 6.5v21v22+1 more2020-01-23
CVE-2015-5745 [MEDIUM] CWE-120 CVE-2015-5745: Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 Buffer overflow in the send_control_msg function in hw/char/virtio-serial-bus.c in QEMU before 2.4.0 allows guest users to cause a denial of service (QEMU process crash) via a crafted virtio control message.
nvd
CVE-2021-42716P4HIGHCVSS 7.1v33v34+1 more2021-10-21
CVE-2021-42716 [HIGH] CWE-120 CVE-2021-42716: An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM f An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service using stb_image, or read up to 1024 bytes of non-consecutive heap data with
nvd
CVE-2014-8964P4MEDIUMCVSS 5.0v19v20+1 more2014-12-16
CVE-2014-8964 [MEDIUM] CWE-119 CVE-2014-8964: Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of ser Heap-based buffer overflow in PCRE 8.36 and earlier allows remote attackers to cause a denial of service (crash) or have other unspecified impact via a crafted regular expression, related to an assertion that allows zero repeats.
nvd
CVE-2022-41742P4HIGHCVSS 7.1v35v36+1 more2022-10-19
CVE-2022-41742 [HIGH] CWE-787 CVE-2022-41742: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a spe
nvd
CVE-2014-1526P4MEDIUMCVSS 6.8v192014-04-30
CVE-2014-1526 [MEDIUM] CWE-269 CVE-2014-1526: The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user- The XrayWrapper implementation in Mozilla Firefox before 29.0 and SeaMonkey before 2.26 allows user-assisted remote attackers to bypass intended access restrictions via a crafted web site that is visited in the debugger, leading to unwrapping operations and calls to DOM methods on the unwrapped objects.
nvd
CVE-2017-16818P4MEDIUMCVSS 6.5v272017-12-20
CVE-2017-16818 [MEDIUM] CWE-617 CVE-2017-16818: RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of s RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, related to rgw/rgw_iam_policy.cc, rgw/rgw_basic_types.h, and rgw/rgw_iam_types.h.
nvd
CVE-2015-5225P4HIGHCVSS 7.2v21v22+1 more2015-11-06
CVE-2015-5225 [HIGH] CWE-119 CVE-2015-5225: Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before Buffer overflow in the vnc_refresh_server_surface function in the VNC display driver in QEMU before 2.4.0.1 allows guest users to cause a denial of service (heap memory corruption and process crash) or possibly execute arbitrary code on the host via unspecified vectors, related to refreshing the server display surface.
nvd
CVE-2023-28686P4HIGHCVSS 7.1v36v37+1 more2023-03-24
CVE-2023-28686 [HIGH] CWE-639 CVE-2023-28686: Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the persona Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
nvd
CVE-2020-8156P4HIGHCVSS 7.0v322020-05-12
CVE-2020-8156 [HIGH] CWE-295 CVE-2020-8156: A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack. A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
nvd
CVE-2015-5166P4HIGHCVSS 7.2v21v222015-08-12
CVE-2015-5166 [HIGH] CWE-264 CVE-2015-5166: Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated bl Use-after-free vulnerability in QEMU in Xen 4.5.x and earlier does not completely unplug emulated block devices, which allows local HVM guest users to gain privileges by unplugging a block device twice.
nvd
CVE-2021-37750P4MEDIUMCVSS 6.5v332021-08-23
CVE-2021-37750 [MEDIUM] CWE-476 CVE-2021-37750: The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19. The Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.18.5 and 1.19.x before 1.19.3 has a NULL pointer dereference in kdc/do_tgs_req.c via a FAST inner body that lacks a server field.
nvd
CVE-2020-6400P4MEDIUMCVSS 6.5v30v312020-02-11
CVE-2020-6400 [MEDIUM] CWE-203 CVE-2020-6400: Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacke Inappropriate implementation in CORS in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-2830P4MEDIUMCVSS 5.3v30v31+1 more2020-04-15
CVE-2020-2830 [MEDIUM] CVE-2020-2830: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). S Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successfu
nvd
CVE-2020-2781P4MEDIUMCVSS 5.3v30v31+1 more2020-04-15
CVE-2020-2781 [MEDIUM] CVE-2020-2781: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supporte Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Java SE, Java SE Embedded. Successful attacks of this vu
nvd
CVE-2021-30584P4MEDIUMCVSS 6.5v33v34+1 more2021-08-03
CVE-2021-30584 [MEDIUM] CVE-2021-30584: Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remo Incorrect security UI in Downloads in Google Chrome on Android prior to 92.0.4515.107 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2020-6445P4MEDIUMCVSS 6.5v30v31+1 more2020-04-13
CVE-2020-6445 [MEDIUM] CWE-276 CVE-2020-6445: Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a re Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
Fedoraproject Fedora vulnerabilities | cvebase