cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 165 of 264
CVE-2020-6446P4MEDIUMCVSS 6.5v30v31+1 more2020-04-13
CVE-2020-6446 [MEDIUM] CWE-276 CVE-2020-6446: Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a re Insufficient policy enforcement in trusted types in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2021-21178P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21178 [MEDIUM] CVE-2021-21178: Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389 Inappropriate implementation in Compositing in Google Chrome on Linux and Windows prior to 89.0.4389.72 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2021-21170P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21170 [MEDIUM] CVE-2021-21170: Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who Incorrect security UI in Loader in Google Chrome prior to 89.0.4389.72 allowed a remote attacker who had compromised the renderer process to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2020-13401P4MEDIUMCVSS 6.0v31v322020-06-02
CVE-2020-13401 [MEDIUM] CWE-20 CVE-2020-13401: An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_N An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
nvd
CVE-2021-23414P4MEDIUMCVSS 6.1v35v36+1 more2021-07-28
CVE-2021-23414 [MEDIUM] CWE-79 CVE-2021-23414: This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTM This affects the package video.js before 7.14.3. The src attribute of track tag allows to bypass HTML escaping and execute arbitrary code.
nvd
CVE-2021-20291P4MEDIUMCVSS 6.5v33v342021-04-01
CVE-2021-20291 [MEDIUM] CWE-667 CVE-2021-20291: A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. Whe A deadlock vulnerability was found in 'github.com/containers/storage' in versions before 1.28.1. When a container image is processed, each layer is unpacked using `tar`. If one of those layers is not a valid `tar` archive this causes an error leading to an unexpected situation where the code indefinitely waits for the tar unpacked stream, which neve
nvd
CVE-2022-28796P4HIGHCVSS 7.0v352022-04-08
CVE-2022-28796 [HIGH] CWE-362 CVE-2022-28796: jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
nvd
CVE-2020-5238P4MEDIUMCVSS 6.5v31v32+1 more2020-07-01
CVE-2020-5238 [MEDIUM] CWE-20 CVE-2020-5238: The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to p The table extension in GitHub Flavored Markdown before version 0.29.0.gfm.1 takes O(n * n) time to parse certain inputs. An attacker could craft a markdown table which would take an unreasonably long time to process, causing a denial of service. This issue does not affect the upstream cmark project. The issue has been fixed in version 0.29.0.gfm.1.
nvd
CVE-2020-25599P4HIGHCVSS 7.0v31v32+1 more2020-09-23
CVE-2020-25599 [HIGH] CWE-119 CVE-2020-25599: An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVT An issue was discovered in Xen through 4.14.x. There are evtchn_reset() race conditions. Uses of EVTCHNOP_reset (potentially by a guest on itself) or XEN_DOMCTL_soft_reset (by itself covered by XSA-77) can lead to the violation of various internal assumptions. This may lead to out of bounds memory accesses or triggering of bug checks. In particular, x
nvd
CVE-2021-2011P4MEDIUMCVSS 5.9v32v332021-01-20
CVE-2021-2011 [MEDIUM] CVE-2021-2011: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2019-5188P4MEDIUMCVSS 6.7v30v312020-01-08
CVE-2019-5188 [MEDIUM] CWE-787 CVE-2019-5188: A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1 A code execution vulnerability exists in the directory rehashing functionality of E2fsprogs e2fsck 1.45.4. A specially crafted ext4 directory can cause an out-of-bounds write on the stack, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
nvd
CVE-2020-6561P4MEDIUMCVSS 6.5v332020-09-21
CVE-2020-6561 [MEDIUM] CVE-2020-6561: Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allow Inappropriate implementation in Content Security Policy in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-42320P4HIGHCVSS 7.0v35v36+1 more2022-11-01
CVE-2022-42320 [HIGH] CWE-459 CVE-2022-42320: Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. Ther
nvd
CVE-2021-20225P4MEDIUMCVSS 6.7v33v342021-03-03
CVE-2021-20225 [MEDIUM] CWE-787 CVE-2021-20225: A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write p A flaw was found in grub2 in versions prior to 2.06. The option parser allows an attacker to write past the end of a heap-allocated buffer by calling certain commands with a large number of specific short forms of options. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2022-1247P4HIGHCVSS 7.0v362022-08-31
CVE-2022-1247 [HIGH] CWE-362 CVE-2022-1247: An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver use An issue found in linux-kernel that leads to a race condition in rose_connect(). The rose driver uses rose_neigh->use to represent how many objects are using the rose_neigh. When a user wants to delete a rose_route via rose_ioctl(), the rose driver calls rose_del_node() and removes neighbours only if their “count” and “use” are zero.
nvd
CVE-2020-6484P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6484 [MEDIUM] CWE-276 CVE-2020-6484: Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote Insufficient data validation in ChromeDriver in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted request.
nvd
CVE-2021-32786P4MEDIUMCVSS 6.1v33v342021-07-22
CVE-2021-32786 [MEDIUM] CWE-601 CVE-2021-32786: mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that funct mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9, `oidc_validate_redirect_url()` does not parse URLs the same way as most browsers do. As a result, this function can be bypass
nvd
CVE-2021-20292P4MEDIUMCVSS 6.7v332021-05-28
CVE-2021-20292 [MEDIUM] CWE-416 CVE-2021-20292: There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouve There is a flaw reported in the Linux kernel in versions before 5.9 in drivers/gpu/drm/nouveau/nouveau_sgdma.c in nouveau_sgdma_create_ttm in Nouveau DRM subsystem. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker with a local account with a root privilege, can leverag
nvd
CVE-2019-9741P4MEDIUMCVSS 6.1v292019-03-13
CVE-2019-9741 [MEDIUM] CWE-93 CVE-2019-9741: An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker control An issue was discovered in net/http in Go 1.11.5. CRLF injection is possible if the attacker controls a url parameter, as demonstrated by the second argument to http.NewRequest with \r\n followed by an HTTP header or a Redis command.
nvd
CVE-2013-0294P4MEDIUMCVSS 5.9v18v19+1 more2020-01-28
CVE-2013-0294 [MEDIUM] CWE-330 CVE-2013-0294: packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash pa packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute force attack.
nvd
Fedoraproject Fedora vulnerabilities | cvebase