Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 176 of 264
CVE-2020-13630P4HIGHCVSS 7.0v322020-05-27
CVE-2020-13630 [HIGH] CWE-416 CVE-2020-13630: ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snip
ext/fts3/fts3.c in SQLite before 3.32.0 has a use-after-free in fts3EvalNextRow, related to the snippet feature.
nvd
CVE-2021-29390P4HIGHCVSS 7.1v37v38+1 more2023-08-22
CVE-2021-29390 [HIGH] CWE-787 CVE-2021-29390: libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data i
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
nvd
CVE-2021-31525P4MEDIUMCVSS 5.9v342021-05-27
CVE-2021-31525 [MEDIUM] CWE-674 CVE-2021-31525: net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of
net/http in Go before 1.15.12 and 1.16.x before 1.16.4 allows remote attackers to cause a denial of service (panic) via a large header to ReadRequest or ReadResponse. Server, Transport, and Client can each be affected in some configurations.
nvd
CVE-2020-8185P4MEDIUMCVSS 6.5v332020-07-02
CVE-2020-8185 [MEDIUM] CWE-400 CVE-2020-8185: A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any
A denial of service vulnerability exists in Rails <6.0.3.2 that allowed an untrusted user to run any pending migrations on a Rails app running in production.
nvd
CVE-2021-32052P4MEDIUMCVSS 6.1v342021-05-06
CVE-2021-32052 [MEDIUM] CWE-79 CVE-2021-32052: In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValida
In Django 2.2 before 2.2.22, 3.1 before 3.1.10, and 3.2 before 3.2.2 (with Python 3.9.5+), URLValidator does not prohibit newlines and tabs (unless the URLField form field is used). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because HttpResponse prohibits newlines in HTTP h
nvd
CVE-2021-3739P4HIGHCVSS 7.1v342022-03-10
CVE-2021-3739 [HIGH] CWE-476 CVE-2021-3739: A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in t
A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/btrfs/volumes.c in the Linux Kernel, where triggering the bug requires ‘CAP_SYS_ADMIN’. This flaw allows a local attacker to crash the system or leak kernel internal information. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-20271P4HIGHCVSS 7.0v32v33+1 more2021-03-26
CVE-2021-20271 [HIGH] CWE-345 CVE-2021-20271: A flaw was found in RPM's signature check functionality when reading a package file. This flaw allow
A flaw was found in RPM's signature check functionality when reading a package file. This flaw allows an attacker who can convince a victim to install a seemingly verifiable package, whose signature header was modified, to cause RPM database corruption and execute code. The highest threat from this vulnerability is to data integrity, confidentiality,
nvd
CVE-2014-9636P4MEDIUMCVSS 5.0v20v212015-02-06
CVE-2014-9636 [MEDIUM] CWE-119 CVE-2014-9636: unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and cras
unzip 6.0 allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) via an extra field with an uncompressed size smaller than the compressed field size in a zip archive that advertises STORED method compression.
nvd
CVE-2019-25013P4MEDIUMCVSS 5.9v32v332021-01-04
CVE-2019-25013 [MEDIUM] CWE-125 CVE-2019-25013: The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid mu
The iconv feature in the GNU C Library (aka glibc or libc6) through 2.32, when processing invalid multi-byte input sequences in the EUC-KR encoding, may have a buffer over-read.
nvd
CVE-2021-30597P4MEDIUMCVSS 6.8v33v34+1 more2021-08-26
CVE-2021-30597 [MEDIUM] CWE-416 CVE-2021-30597: Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote atta
Use after free in Browser UI in Google Chrome on Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
nvd
CVE-2020-13596P4MEDIUMCVSS 6.1v322020-06-03
CVE-2020-13596 [MEDIUM] CWE-79 CVE-2020-13596: An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated
An issue was discovered in Django 2.2 before 2.2.13 and 3.0 before 3.0.7. Query parameters generated by the Django admin ForeignKeyRawIdWidget were not properly URL encoded, leading to a possibility of an XSS attack.
nvd
CVE-2020-13775P4MEDIUMCVSS 6.5v31v322020-06-02
CVE-2020-13775 [MEDIUM] CWE-476 CVE-2020-13775: ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL po
ZNC 1.8.0 up to 1.8.1-rc1 allows authenticated users to trigger an application crash (with a NULL pointer dereference) if echo-message is not enabled and there is no network.
nvd
CVE-2022-33742P4HIGHCVSS 7.1v35v362022-07-05
CVE-2022-33742 [HIGH] CVE-2022-33742: Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't
nvd
CVE-2022-26365P4HIGHCVSS 7.1v35v362022-07-05
CVE-2022-26365 [HIGH] CWE-401 CVE-2022-26365: Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table
nvd
CVE-2022-33740P4HIGHCVSS 7.1v35v362022-07-05
CVE-2022-33740 [HIGH] CVE-2022-33740: Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't
nvd
CVE-2022-33741P4HIGHCVSS 7.1v35v362022-07-05
CVE-2022-33741 [HIGH] CVE-2022-33741: Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text
Linux disk/nic frontends data leaks T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Linux Block and Network PV device frontends don't zero memory regions before sharing them with the backend (CVE-2022-26365, CVE-2022-33740). Additionally the granularity of the grant table doesn't
nvd
CVE-2019-13626P4MEDIUMCVSS 6.5v312019-07-17
CVE-2019-13626 [MEDIUM] CWE-125 CVE-2019-13626: SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM
SDL (Simple DirectMedia Layer) 2.x through 2.0.9 has a heap-based buffer over-read in Fill_IMA_ADPCM_block, caused by an integer overflow in IMA_ADPCM_decode() in audio/SDL_wave.c.
nvd
CVE-2021-45931P4MEDIUMCVSS 6.5v34v352022-01-01
CVE-2021-45931 [MEDIUM] CWE-787 CVE-2021-45931: HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_
HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t::set and hb_set_copy).
nvd
CVE-2022-42327P4HIGHCVSS 7.1v36v372022-11-01
CVE-2022-42327 [HIGH] CWE-284 CVE-2022-42327: x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC acc
x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the global shared xAPIC page by moving the local APIC out of xAPIC mode. Access to this shared page bypasses the expected isolation that should exist between two guests.
nvd
CVE-2020-6408P4MEDIUMCVSS 6.5v30v312020-02-11
CVE-2020-6408 [MEDIUM] CVE-2020-6408: Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attac
Insufficient policy enforcement in CORS in Google Chrome prior to 80.0.3987.87 allowed a local attacker to obtain potentially sensitive information via a crafted HTML page.
nvd