cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 174 of 264
CVE-2021-40530P4MEDIUMCVSS 5.9v33v34+1 more2021-09-06
CVE-2021-40530 [MEDIUM] CWE-327 CVE-2021-40530: The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interac The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key, and the sender's ephemeral exponents can lead to a cross-configuration att
nvd
CVE-2021-28153P4MEDIUMCVSS 5.3v332021-03-11
CVE-2021-28153 [MEDIUM] CWE-59 CVE-2021-28153: An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREAT An issue was discovered in GNOME GLib before 2.66.8. When g_file_replace() is used with G_FILE_CREATE_REPLACE_DESTINATION to replace a path that is a dangling symlink, it incorrectly also creates the target of the symlink as an empty file, which could conceivably have security relevance if the symlink is attacker-controlled. (If the path is a symlink
nvd
CVE-2022-29526P4MEDIUMCVSS 5.3v35v362022-06-23
CVE-2022-29526 [MEDIUM] CWE-269 CVE-2022-29526: Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a no Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.
nvd
CVE-2022-21702P4MEDIUMCVSS 5.4v34v35+1 more2022-02-08
CVE-2022-21702 [MEDIUM] CWE-79 CVE-2022-21702: Grafana is an open-source platform for monitoring and observability. In affected versions an attacke Grafana is an open-source platform for monitoring and observability. In affected versions an attacker could serve HTML content thru the Grafana datasource or plugin proxy and trick a user to visit this HTML page using a specially crafted link and execute a Cross-site Scripting (XSS) attack. The attacker could either compromise an existing datasource
nvd
CVE-2016-9108P4HIGHCVSS 7.5v23v24+1 more2017-02-03
CVE-2016-9108 [HIGH] CWE-190 CVE-2016-9108: Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit Integer overflow in the js_regcomp function in regexp.c in Artifex Software, Inc. MuJS before commit b6de34ac6d8bb7dd5461c57940acfbd3ee7fd93e allows attackers to cause a denial of service (application crash) via a crafted regular expression.
nvd
CVE-2022-21549P4MEDIUMCVSS 5.3v35v362022-07-19
CVE-2022-21549 [MEDIUM] CWE-502 CVE-2022-21549: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 17.0.3.1; Oracle GraalVM Enterprise Edition: 21.3.2 and 22.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols t
nvd
CVE-2021-32917P4MEDIUMCVSS 5.3v32v33+1 more2021-05-13
CVE-2021-32917 [MEDIUM] CWE-862 CVE-2021-32917: An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by defaul An issue was discovered in Prosody before 0.11.9. The proxy65 component allows open access by default, even if neither of the users has an XMPP account on the local server, allowing unrestricted use of the server's bandwidth.
nvd
CVE-2022-21618P4MEDIUMCVSS 5.3v35v362022-10-18
CVE-2022-21618 [MEDIUM] CWE-287 CVE-2022-21618: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JGSS). Supported versions that are affected are Oracle Java SE: 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via Kerberos to compromis
nvd
CVE-2021-28090P4MEDIUMCVSS 5.3v332021-03-19
CVE-2021-28090 [MEDIUM] CWE-617 CVE-2021-28090: Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an asser Tor before 0.4.5.7 allows a remote attacker to cause Tor directory authorities to exit with an assertion failure, aka TROVE-2021-002.
nvd
CVE-2009-1721P4MEDIUMCVSS 6.8v10v112009-07-31
CVE-2009-1721 [MEDIUM] CWE-824 CVE-2009-1721: The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allow The decompression implementation in the Imf::hufUncompress function in OpenEXR 1.2.2 and 1.6.1 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via vectors that trigger a free of an uninitialized pointer.
nvd
CVE-2020-12802P4MEDIUMCVSS 5.3v312020-06-08
CVE-2020-12802 [MEDIUM] CWE-200 CVE-2020-12802: LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where remote graphic links loaded from docx documents
nvd
CVE-2021-22923P4MEDIUMCVSS 5.3v332021-08-05
CVE-2021-22923 [MEDIUM] CWE-319 CVE-2021-22923: When curl is instructed to get content using the metalink feature, and a user name and password are When curl is instructed to get content using the metalink feature, and a user name and password are used to download the metalink XML file, those same credentials are then subsequently passed on to each of the servers from which curl will download or try to download the contents from. Often contrary to the user's expectations and intentions and witho
nvd
CVE-2021-39241P4MEDIUMCVSS 5.3v33v342021-08-17
CVE-2021-39241 [MEDIUM] CVE-2021-39241: An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 An issue was discovered in HAProxy 2.0 before 2.0.24, 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. An HTTP method name may contain a space followed by the name of a protected resource. It is possible that a server would interpret this as a request for that protected resource, such as in the "GET /admin? HTTP/1.1 /static/images HTTP/1.1" exampl
nvd
CVE-2021-33896P4MEDIUMCVSS 5.3v33v342021-06-07
CVE-2021-33896 [MEDIUM] CWE-22 CVE-2021-33896: Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) Dino before 0.1.2 and 0.2.x before 0.2.1 allows Directory Traversal (only for creation of new files) via URI-encoded path separators.
nvd
CVE-2013-2032P4MEDIUMCVSS 5.0v17v18+1 more2013-11-18
CVE-2013-2032 [MEDIUM] CWE-264 CVE-2013-2032: MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password chang MediaWiki before 1.19.6 and 1.20.x before 1.20.5 does not allow extensions to prevent password changes without using both Special:PasswordReset and Special:ChangePassword, which allows remote attackers to bypass the intended restrictions of an extension that only implements one of these blocks.
nvd
CVE-2020-10803P4MEDIUMCVSS 5.4v30v31+1 more2020-03-22
CVE-2020-10803 [MEDIUM] CWE-79 CVE-2020-10803: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered wh In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was discovered where malicious code could be used to trigger an XSS attack through retrieving and displaying results (in tbl_get_field.php and libraries/classes/Display/Results.php). The attacker must be able to insert crafted data into certain database tables, which w
nvd
CVE-2014-9669P4MEDIUMCVSS 6.8v20v212015-02-08
CVE-2014-9669 [MEDIUM] CWE-125 CVE-2014-9669: Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause Multiple integer overflows in sfnt/ttcmap.c in FreeType before 2.5.4 allow remote attackers to cause a denial of service (out-of-bounds read or memory corruption) or possibly have unspecified other impact via a crafted cmap SFNT table.
nvd
CVE-2020-14370P4MEDIUMCVSS 5.3v31v32+1 more2020-09-23
CVE-2020-14370 [MEDIUM] CWE-212 CVE-2020-14370: An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. Whe An information disclosure vulnerability was found in containers/podman in versions before 2.0.5. When using the deprecated Varlink API or the Docker-compatible REST API, if multiple containers are created in a short duration, the environment variables from the first container will get leaked into subsequent containers. An attacker who has control ov
nvd
CVE-2023-34968P4MEDIUMCVSS 5.3v37v382023-07-20
CVE-2023-34968 [MEDIUM] CWE-201 CVE-2023-34968: A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba disclos A path disclosure vulnerability was found in Samba. As part of the Spotlight protocol, Samba discloses the server-side absolute path of shares, files, and directories in the results for search queries. This flaw allows a malicious client or an attacker with a targeted RPC request to view the information that is part of the disclosed path.
nvd
CVE-2022-45866P4MEDIUMCVSS 5.3v35v36+1 more2022-11-23
CVE-2022-45866 [MEDIUM] CWE-22 CVE-2022-45866: qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and o qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file.
nvd
Fedoraproject Fedora vulnerabilities | cvebase