cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 170 of 264
CVE-2020-6563P4MEDIUMCVSS 6.5v332020-09-21
CVE-2020-6563 [MEDIUM] CVE-2020-6563: Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 Insufficient policy enforcement in intent handling in Google Chrome on Android prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
nvd
CVE-2020-6475P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6475 [MEDIUM] CVE-2020-6475: Incorrect implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote atta Incorrect implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6483P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6483 [MEDIUM] CWE-276 CVE-2020-6483: Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote Insufficient policy enforcement in payments in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-6486P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6486 [MEDIUM] CVE-2020-6486: Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remo Insufficient policy enforcement in navigations in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-11884P4HIGHCVSS 7.0v30v31+1 more2020-04-29
CVE-2020-11884 [HIGH] CWE-362 CVE-2020-11884: In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a r In the Linux kernel 4.19 through 5.6.7 on the s390 platform, code execution may occur because of a race condition, as demonstrated by code in enable_sacf_uaccess in arch/s390/lib/uaccess.c that fails to protect against a concurrent page table upgrade, aka CID-3f777e19d171. A crash could also occur.
nvd
CVE-2019-12817P4HIGHCVSS 7.0v29v302019-06-25
CVE-2019-12817 [HIGH] CWE-787 CVE-2019-12817: arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where arch/powerpc/mm/mmu_context_book3s64.c in the Linux kernel before 5.1.15 for powerpc has a bug where unrelated processes may be able to read/write to one another's virtual memory under certain conditions via an mmap above 512 TB. Only a subset of powerpc systems are affected.
nvd
CVE-2019-5766P4MEDIUMCVSS 6.5v29v302019-02-19
CVE-2019-5766 [MEDIUM] CVE-2019-5766: Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed Incorrect handling of origin taint checking in Canvas in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-28038P4MEDIUMCVSS 6.1v31v32+1 more2020-11-02
CVE-2020-28038 [MEDIUM] CWE-79 CVE-2020-28038: WordPress before 5.5.2 allows stored XSS via post slugs. WordPress before 5.5.2 allows stored XSS via post slugs.
nvd
CVE-2019-5094P4MEDIUMCVSS 6.7v30v312019-09-24
CVE-2019-5094 [MEDIUM] CWE-787 CVE-2019-5094: An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45 An exploitable code execution vulnerability exists in the quota file functionality of E2fsprogs 1.45.3. A specially crafted ext4 partition can cause an out-of-bounds write on the heap, resulting in code execution. An attacker can corrupt a partition to trigger this vulnerability.
nvd
CVE-2021-21181P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21181 [MEDIUM] CWE-203 CVE-2021-21181: Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote Side-channel information leakage in autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2021-21173P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21173 [MEDIUM] CWE-203 CVE-2021-21173: Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed Side-channel information leakage in Network Internals in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6487P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6487 [MEDIUM] CWE-276 CVE-2020-6487: Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote Insufficient policy enforcement in downloads in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-29470P4MEDIUMCVSS 6.5v33v342021-04-23
CVE-2021-29470 [MEDIUM] CWE-125 CVE-2021-29470: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability t
nvd
CVE-2020-6479P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6479 [MEDIUM] CVE-2020-6479: Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote atta Inappropriate implementation in sharing in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6478P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6478 [MEDIUM] CVE-2020-6478: Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote Inappropriate implementation in full screen in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2020-6566P4MEDIUMCVSS 6.5v332020-09-21
CVE-2020-6566 [MEDIUM] CVE-2020-6566: Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote att Insufficient policy enforcement in media in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-13749P4MEDIUMCVSS 6.5v30v312019-12-10
CVE-2019-13749 [MEDIUM] CVE-2019-13749: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote atta Incorrect security UI in Omnibox in Google Chrome on iOS prior to 79.0.3945.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2020-6481P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6481 [MEDIUM] CVE-2020-6481: Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a r Insufficient policy enforcement in URL formatting in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to perform domain spoofing via a crafted domain name.
nvd
CVE-2020-27672P4HIGHCVSS 7.0v312020-10-22
CVE-2020-27672 [HIGH] CWE-362 CVE-2020-27672: An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial An issue was discovered in Xen through 4.14.x allowing x86 guest OS users to cause a host OS denial of service, achieve data corruption, or possibly gain privileges by exploiting a race condition that leads to a use-after-free involving 2MiB and 1GiB superpages.
nvd
CVE-2019-13745P4MEDIUMCVSS 6.5v30v312019-12-10
CVE-2019-13745 [MEDIUM] CVE-2019-13745: Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote att Insufficient policy enforcement in audio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
Fedoraproject Fedora vulnerabilities | cvebase