Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 164 of 264
CVE-2020-6393P4MEDIUMCVSS 6.5v30v312020-02-11
CVE-2020-6393 [MEDIUM] CWE-862 CVE-2020-6393: Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-5773P4MEDIUMCVSS 6.5v29v302019-02-19
CVE-2019-5773 [MEDIUM] CWE-346 CVE-2019-5773: Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote
Insufficient origin validation in IndexedDB in Google Chrome prior to 72.0.3626.81 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page.
nvd
CVE-2023-6277P4MEDIUMCVSS 6.5v382023-11-24
CVE-2023-6277 [MEDIUM] CWE-400 CVE-2023-6277: An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow
An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.
nvd
CVE-2020-2804P4MEDIUMCVSS 5.9v30v31+1 more2020-04-15
CVE-2020-2804 [MEDIUM] CVE-2020-2804: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabi
nvd
CVE-2024-27401P4HIGHCVSS 7.1v39v402024-05-14
CVE-2024-27401 [HIGH] CVE-2024-27401: In the Linux kernel, the following vulnerability has been resolved: firewire: nosy: ensure user_len
In the Linux kernel, the following vulnerability has been resolved:
firewire: nosy: ensure user_length is taken into account when fetching packet contents
Ensure that packet_buffer_get respects the user_length provided. If
the length of the head packet exceeds the user_length, packet_buffer_get
will now return 0 to signify to the user that no data were read
nvd
CVE-2010-3439P4MEDIUMCVSS 6.5v11v12+1 more2019-11-12
CVE-2010-3439 [MEDIUM] CWE-20 CVE-2010-3439: It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supply
It is possible to cause a DoS condition by causing the server to crash in alien-arena 7.33 by supplying various invalid parameters to the download command.
nvd
CVE-2021-30583P4MEDIUMCVSS 6.5v33v34+1 more2021-08-03
CVE-2021-30583 [MEDIUM] CVE-2021-30583: Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.
Insufficient policy enforcement in image handling in iOS in Google Chrome on iOS prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-21168P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21168 [MEDIUM] CVE-2021-21168: Insufficient policy enforcement in appcache in Google Chrome prior to 89.0.4389.72 allowed a remote
Insufficient policy enforcement in appcache in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2022-28614P4MEDIUMCVSS 5.3v35v362022-06-09
CVE-2022-28614 [MEDIUM] CWE-190 CVE-2022-28614: The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an a
The ap_rwrite() function in Apache HTTP Server 2.4.53 and earlier may read unintended memory if an attacker can cause the server to reflect very large input using ap_rwrite() or ap_rputs(), such as with mod_luas r:puts() function. Modules compiled and distributed separately from Apache HTTP Server that use the 'ap_rputs' function and may pass it a v
nvd
CVE-2010-1772P4HIGHCVSS 8.8v12v132010-09-24
CVE-2010-1772 [HIGH] CWE-416 CVE-2010-1772: Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in
Use-after-free vulnerability in page/Geolocation.cpp in WebCore in WebKit before r59859, as used in Google Chrome before 5.0.375.70, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted web site, related to failure to stop timers associated with geolocation upon deletion of a document.
nvd
CVE-2019-13752P4MEDIUMCVSS 6.5v30v312019-12-10
CVE-2019-13752 [MEDIUM] CWE-125 CVE-2019-13752: Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-13753P4MEDIUMCVSS 6.5v30v312019-12-10
CVE-2019-13753 [MEDIUM] CWE-125 CVE-2019-13753: Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obt
Out of bounds read in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2021-21176P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21176 [MEDIUM] CVE-2021-21176: Inappropriate implementation in full screen mode in Google Chrome prior to 89.0.4389.72 allowed a re
Inappropriate implementation in full screen mode in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2023-23916P4MEDIUMCVSS 6.5v362023-02-23
CVE-2023-23916 [MEDIUM] CWE-770 CVE-2023-23916: An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based
An allocation of resources without limits or throttling vulnerability exists in curl <v7.88.0 based on the "chained" HTTP compression algorithms, meaning that a server response can be compressed multiple times and potentially with differentalgorithms. The number of acceptable "links" in this "decompression chain" wascapped, but the cap was implemente
nvd
CVE-2020-6511P4MEDIUMCVSS 6.5v31v322020-07-22
CVE-2020-6511 [MEDIUM] CWE-209 CVE-2020-6511: Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote
Information leak in content security policy in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6485P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6485 [MEDIUM] CWE-20 CVE-2020-6485: Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote
Insufficient data validation in media router in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-21171P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21171 [MEDIUM] CVE-2021-21171: Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 a
Incorrect security UI in TabStrip and Navigation in Google Chrome on Android prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2020-6560P4MEDIUMCVSS 6.5v332020-09-21
CVE-2020-6560 [MEDIUM] CVE-2020-6560: Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote
Insufficient policy enforcement in autofill in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-15985P4MEDIUMCVSS 6.5v31v32+1 more2020-11-03
CVE-2020-15985 [MEDIUM] CVE-2020-15985: Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attack
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2021-36221P4MEDIUMCVSS 5.9v33v34+1 more2021-08-08
CVE-2021-36221 [MEDIUM] CWE-362 CVE-2021-36221: Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil
Go before 1.15.15 and 1.16.x before 1.16.7 has a race condition that can lead to a net/http/httputil ReverseProxy panic upon an ErrAbortHandler abort.
nvd