cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 171 of 264
CVE-2020-6567P4MEDIUMCVSS 6.5v332020-09-21
CVE-2020-6567 [MEDIUM] CWE-20 CVE-2020-6567: Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prio Insufficient validation of untrusted input in command line handling in Google Chrome on Windows prior to 85.0.4183.83 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2022-26357P4HIGHCVSS 7.0v34v352022-04-05
CVE-2022-26357 [HIGH] CWE-362 CVE-2022-26357: race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for on race in VT-d domain ID cleanup Xen domain IDs are up to 15 bits wide. VT-d hardware may allow for only less than 15 bits to hold a domain ID associating a physical device with a particular domain. Therefore internally Xen domain IDs are mapped to the smaller value range. The cleaning up of the housekeeping structures has a race, allowing for VT-d doma
nvd
CVE-2020-15977P4MEDIUMCVSS 6.5v31v32+1 more2020-11-03
CVE-2020-15977 [MEDIUM] CWE-20 CVE-2020-15977: Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a rem Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
nvd
CVE-2022-0117P4MEDIUMCVSS 6.5v34v35+1 more2022-02-12
CVE-2022-0117 [MEDIUM] CWE-863 CVE-2022-0117: Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cros Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2009-2813P4MEDIUMCVSS 6.0v112009-09-14
CVE-2009-2813 [MEDIUM] CWE-264 CVE-2009-2813: Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in t Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictio
nvd
CVE-2020-8223P4MEDIUMCVSS 6.5v32v332020-10-05
CVE-2020-8223 [MEDIUM] CWE-269 CVE-2020-8223: A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to r A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.
nvd
CVE-2020-6491P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6491 [MEDIUM] CVE-2020-6491: Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a re Insufficient data validation in site information in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to spoof security UI via a crafted domain name.
nvd
CVE-2021-30540P4MEDIUMCVSS 6.5v33v342021-06-07
CVE-2021-30540 [MEDIUM] CWE-74 CVE-2021-30540: Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2013-4345P4MEDIUMCVSS 5.8v18v192013-10-10
CVE-2013-4345 [MEDIUM] CWE-189 CVE-2013-4345: Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3 Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to improper management of the state of the consumed data.
nvd
CVE-2020-15981P4MEDIUMCVSS 6.5v31v32+1 more2020-11-03
CVE-2020-15981 [MEDIUM] CWE-125 CVE-2020-15981: Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obta Out of bounds read in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2020-6456P4MEDIUMCVSS 6.5v30v31+1 more2020-04-13
CVE-2020-6456 [MEDIUM] CWE-276 CVE-2020-6456: Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allow Insufficient validation of untrusted input in clipboard in Google Chrome prior to 81.0.4044.92 allowed a local attacker to bypass site isolation via crafted clipboard contents.
nvd
CVE-2020-6476P4MEDIUMCVSS 6.5v31v322020-05-21
CVE-2020-6476 [MEDIUM] CWE-276 CVE-2020-6476: Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attac Insufficient policy enforcement in tab strip in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2021-4068P4MEDIUMCVSS 6.5v342021-12-23
CVE-2021-4068 [MEDIUM] CWE-116 CVE-2021-4068: Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-15984P4MEDIUMCVSS 6.5v31v32+1 more2020-11-03
CVE-2020-15984 [MEDIUM] CVE-2020-15984: Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a r Insufficient policy enforcement in Omnibox in Google Chrome on iOS prior to 86.0.4240.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted URL.
nvd
CVE-2019-13739P4MEDIUMCVSS 6.5v30v312019-12-10
CVE-2019-13739 [MEDIUM] CVE-2019-13739: Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote a Insufficient policy enforcement in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2019-5767P4MEDIUMCVSS 6.5v29v302019-02-19
CVE-2019-5767 [MEDIUM] CWE-1021 CVE-2019-5767: Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.8 Insufficient protection of permission UI in WebAPKs in Google Chrome on Android prior to 72.0.3626.81 allowed an attacker who convinced the user to install a malicious application to access privacy/security sensitive web APIs via a crafted APK.
nvd
CVE-2019-18424P4MEDIUMCVSS 6.8v29v30+1 more2019-10-31
CVE-2019-18424 [MEDIUM] CWE-78 CVE-2019-18424: An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI device is assigned to an untrusted domain, it is possible for that domain to
nvd
CVE-2021-30534P4MEDIUMCVSS 6.5v33v342021-06-07
CVE-2021-30534 [MEDIUM] CWE-863 CVE-2021-30534: Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a re Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-4054P4MEDIUMCVSS 6.5v342021-12-23
CVE-2021-4054 [MEDIUM] CVE-2021-4054: Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker t Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2016-0787P4MEDIUMCVSS 5.9v22v232016-04-13
CVE-2016-0787 [MEDIUM] CWE-200 CVE-2016-0787: The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to The diffie_hellman_sha256 function in kex.c in libssh2 before 1.7.0 improperly truncates secrets to 128 or 256 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
nvd
Fedoraproject Fedora vulnerabilities | cvebase