cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 178 of 264
CVE-2023-1667P4MEDIUMCVSS 6.5v372023-05-26
CVE-2023-1667 [MEDIUM] CWE-476 CVE-2023-1667: A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.
nvd
CVE-2019-13738P4MEDIUMCVSS 6.5v30v312019-12-10
CVE-2019-13738 [MEDIUM] CWE-269 CVE-2019-13738: Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remot Insufficient policy enforcement in navigation in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2019-13743P4MEDIUMCVSS 6.5v30v312019-12-10
CVE-2019-13743 [MEDIUM] CVE-2019-13743: Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a Incorrect security UI in external protocol handling in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2019-5832P4MEDIUMCVSS 6.5v29v302019-06-27
CVE-2019-5832 [MEDIUM] CVE-2019-5832: Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a r Insufficient policy enforcement in XMLHttpRequest in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2010-4198P4HIGHCVSS 8.8v132010-11-06
CVE-2010-4198 [HIGH] CWE-20 CVE-2010-4198: WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, does not properly handle large text areas, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted HTML document.
nvd
CVE-2020-36150P4MEDIUMCVSS 6.5v322021-02-08
CVE-2020-36150 [MEDIUM] CWE-125 CVE-2020-36150: Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead t Incorrect handling of input data in loudness function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and access to unallocated memory block.
nvd
CVE-2019-19579P4MEDIUMCVSS 6.8v302019-12-04
CVE-2019-19579 [MEDIUM] CVE-2019-19579: An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the use of libxl's "assignable-add" feature to prepare devices to be assigned to untru
nvd
CVE-2019-5768P4MEDIUMCVSS 6.5v29v302019-02-19
CVE-2019-5768 [MEDIUM] CWE-269 CVE-2019-5768: DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0 DevTools API not correctly gating on extension capability in DevTools in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to read local files via a crafted Chrome Extension.
nvd
CVE-2021-21175P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21175 [MEDIUM] CWE-346 CVE-2021-21175: Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remo Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-0108P4MEDIUMCVSS 6.5v34v35+1 more2022-02-12
CVE-2022-0108 [MEDIUM] CWE-346 CVE-2022-0108: Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote a Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-27025P4MEDIUMCVSS 6.5v352021-11-18
CVE-2021-27025 [MEDIUM] CVE-2021-27025: A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be A flaw was discovered in Puppet Agent where the agent may silently ignore Augeas settings or may be vulnerable to a Denial of Service condition prior to the first 'pluginsync'.
nvd
CVE-2022-26691P4MEDIUMCVSS 6.7v35v362022-05-26
CVE-2022-26691 [MEDIUM] CWE-697 CVE-2022-26691: A logic issue was addressed with improved state management. This issue is fixed in Security Update 2 A logic issue was addressed with improved state management. This issue is fixed in Security Update 2022-003 Catalina, macOS Monterey 12.3, macOS Big Sur 11.6.5. An application may be able to gain elevated privileges.
nvd
CVE-2020-35884P4MEDIUMCVSS 6.5v34v352020-12-31
CVE-2020-35884 [MEDIUM] CWE-444 CVE-2020-35884: An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling c An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
nvd
CVE-2020-15973P4MEDIUMCVSS 6.5v31v32+1 more2020-11-03
CVE-2020-15973 [MEDIUM] CVE-2020-15973: Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an atta Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension.
nvd
CVE-2023-5171P4MEDIUMCVSS 6.5v392023-09-27
CVE-2023-5171 [MEDIUM] CWE-416 CVE-2023-5171: During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allo During Ion compilation, a Garbage Collection could have resulted in a use-after-free condition, allowing an attacker to write two NUL bytes, and cause a potentially exploitable crash. This vulnerability affects Firefox < 118, Firefox ESR < 115.3, and Thunderbird < 115.3.
nvd
CVE-2019-5778P4MEDIUMCVSS 6.5v29v302019-02-19
CVE-2019-5778 [MEDIUM] CWE-79 CVE-2019-5778: A missing case for handling special schemes in permission request checks in Extensions in Google Chr A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.
nvd
CVE-2021-21209P4MEDIUMCVSS 6.5v32v33+1 more2021-04-26
CVE-2021-21209 [MEDIUM] CWE-346 CVE-2021-21209: Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote atta Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2023-2459P4MEDIUMCVSS 6.5v36v37+1 more2023-05-03
CVE-2023-2459 [MEDIUM] CVE-2023-2459: Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote att Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-21163P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21163 [MEDIUM] CWE-346 CVE-2021-21163: Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server.
nvd
CVE-2016-0739P4MEDIUMCVSS 5.9v22v232016-04-13
CVE-2016-0739 [MEDIUM] CWE-200 CVE-2016-0739: libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-grou libssh before 0.7.3 improperly truncates ephemeral secrets generated for the (1) diffie-hellman-group1 and (2) diffie-hellman-group14 key exchange methods to 128 bits, which makes it easier for man-in-the-middle attackers to decrypt or intercept SSH sessions via unspecified vectors, aka a "bits/bytes confusion bug."
nvd
Fedoraproject Fedora vulnerabilities | cvebase