Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 167 of 264
CVE-2023-51797P4MEDIUMCVSS 6.7v38v39+1 more2024-04-19
CVE-2023-51797 [MEDIUM] CWE-94 CVE-2023-51797: Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arb
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame
nvd
CVE-2023-1814P4MEDIUMCVSS 6.5v36v372023-04-04
CVE-2023-1814 [MEDIUM] CVE-2023-1814: Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2010-4158P4LOWCVSS 2.1PoCv132010-12-30
CVE-2010-4158 [LOW] CWE-200 CVE-2010-4158: The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check w
The sk_run_filter function in net/core/filter.c in the Linux kernel before 2.6.36.2 does not check whether a certain memory location has been initialized before executing a (1) BPF_S_LD_MEM or (2) BPF_S_LDX_MEM instruction, which allows local users to obtain potentially sensitive information from kernel stack memory via a crafted socket filter.
nvd
CVE-2022-1231P4MEDIUMCVSS 6.1v35v362022-04-15
CVE-2022-1231 [MEDIUM] CWE-79 CVE-2022-1231: XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4.
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example in desktop applications. Web based applications are the ones most affected.
nvd
CVE-2021-21273P4MEDIUMCVSS 6.1v342021-02-26
CVE-2021-21273 [MEDIUM] CWE-601 CVE-2021-21273: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.25.0, requests to user provided domains were not restricted to external IP addresses when calculating the key validity for third-party invite events and sending pus
nvd
CVE-2023-6238P4MEDIUMCVSS 6.7v382023-11-21
CVE-2023-6238 [MEDIUM] CWE-120 CVE-2023-6238: A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only
A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. Only privileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.
nvd
CVE-2022-21283P4MEDIUMCVSS 5.3v342022-01-19
CVE-2022-21283 [MEDIUM] CWE-693 CVE-2022-21283: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple prot
nvd
CVE-2021-39191P4MEDIUMCVSS 6.1v35v362021-09-03
CVE-2021-39191 [MEDIUM] CWE-601 CVE-2021-39191: mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that funct
mod_auth_openidc is an authentication/authorization module for the Apache 2.x HTTP server that functions as an OpenID Connect Relying Party, authenticating users against an OpenID Connect Provider. In versions prior to 2.4.9.4, the 3rd-party init SSO functionality of mod_auth_openidc was reported to be vulnerable to an open redirect attack by supply
nvd
CVE-2024-2630P4MEDIUMCVSS 6.5v38v39+1 more2024-03-20
CVE-2024-2630 [MEDIUM] CWE-79 CVE-2024-2630: Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacke
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-1813P4MEDIUMCVSS 6.5v36v372023-04-04
CVE-2023-1813 [MEDIUM] CVE-2023-1813: Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attack
Inappropriate implementation in Extensions in Google Chrome prior to 112.0.5615.49 allowed an attacker who convinced a user to install a malicious extension to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5487P4MEDIUMCVSS 6.5v37v382023-10-11
CVE-2023-5487 [MEDIUM] CVE-2023-5487: Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attack
Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
nvd
CVE-2022-2618P4MEDIUMCVSS 6.5v372022-08-12
CVE-2022-2618 [MEDIUM] CWE-20 CVE-2022-2618: Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allo
Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a malicious file .
nvd
CVE-2023-4367P4MEDIUMCVSS 6.5v382023-08-15
CVE-2023-4367 [MEDIUM] CVE-2023-4367: Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-2861P4MEDIUMCVSS 6.5v372022-09-26
CVE-2022-2861 [MEDIUM] CWE-79 CVE-2022-2861: Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an a
Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.101 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts into WebUI via a crafted HTML page.
nvd
CVE-2024-28176P4MEDIUMCVSS 5.9≥ 38, ≤ 402024-03-09
CVE-2024-28176 [MEDIUM] CWE-400 CVE-2024-28176: jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tok
jose is JavaScript module for JSON Object Signing and Encryption, providing support for JSON Web Tokens (JWT), JSON Web Signature (JWS), JSON Web Encryption (JWE), JSON Web Key (JWK), JSON Web Key Set (JWKS), and more. A vulnerability has
been identified in the JSON Web Encryption (JWE) decryption interfaces, specifically related to the support for
nvd
CVE-2022-24302P4MEDIUMCVSS 5.9v34v35+1 more2022-03-17
CVE-2022-24302 [MEDIUM] CWE-362 CVE-2022-24302: In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_fi
In Paramiko before 2.10.1, a race condition (between creation and chmod) in the write_private_key_file function could allow unauthorized information disclosure.
nvd
CVE-2019-7282P4MEDIUMCVSS 5.9v34v35+1 more2019-01-31
CVE-2019-7282 [MEDIUM] CVE-2019-7282: In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access
In NetKit through 0.17, rcp.c in the rcp client allows remote rsh servers to bypass intended access restrictions via the filename of . or an empty filename. The impact is modifying the permissions of the target directory on the client side. This is similar to CVE-2018-20685.
nvd
CVE-2021-2163P4MEDIUMCVSS 5.3v32v33+1 more2021-04-22
CVE-2021-2163 [MEDIUM] CVE-2021-2163: Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle
Vulnerability in the Java SE, Java SE Embedded, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u291, 8u281, 11.0.10, 16; Java SE Embedded: 8u281; Oracle GraalVM Enterprise Edition: 19.3.5, 20.3.1.2 and 21.0.0.2. Difficult to exploit vulnerability allows unauthenticated atta
nvd
CVE-2023-4135P4MEDIUMCVSS 6.5v382023-08-04
CVE-2023-4135 [MEDIUM] CWE-125 CVE-2023-4135: A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process
A heap out-of-bounds memory read flaw was found in the virtual nvme device in QEMU. The QEMU process does not validate an offset provided by the guest before computing a host heap pointer, which is used for copying data back to the guest. Arbitrary heap memory relative to an allocated buffer can be disclosed.
nvd
CVE-2024-5840P4MEDIUMCVSS 6.5v39v402024-06-11
CVE-2024-5840 [MEDIUM] CWE-284 CVE-2024-5840: Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass di
Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
nvd