Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 179 of 264
CVE-2022-30787P4MEDIUMCVSS 6.7v35v362022-05-26
CVE-2022-30787 [MEDIUM] CWE-191 CVE-2022-30787: An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through
An integer underflow in fuse_lib_readdir enables arbitrary memory read operations in NTFS-3G through 2021.8.22 when using libfuse-lite.
nvd
CVE-2020-10723P4MEDIUMCVSS 6.7v322020-05-19
CVE-2020-10723 [MEDIUM] CWE-190 CVE-2020-10723: A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an inte
A memory corruption issue was found in DPDK versions 17.05 and above. This flaw is caused by an integer truncation on the index of a payload. Under certain circumstances, the index (a UInt) is copied and truncated into a uint16, which can lead to out of bound indexing and possible memory corruption.
nvd
CVE-2022-3044P4MEDIUMCVSS 6.5v372022-09-26
CVE-2022-3044 [MEDIUM] CWE-693 CVE-2022-3044: Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a rem
Inappropriate implementation in Site Isolation in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2022-2860P4MEDIUMCVSS 6.5v372022-09-26
CVE-2022-2860 [MEDIUM] CVE-2022-2860: Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page.
nvd
CVE-2022-0113P4MEDIUMCVSS 6.5v34v35+1 more2022-02-12
CVE-2022-0113 [MEDIUM] CWE-346 CVE-2022-0113: Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attack
Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-38022P4MEDIUMCVSS 6.5v342021-12-23
CVE-2021-38022 [MEDIUM] CVE-2021-38022: Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a r
Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-24370P4MEDIUMCVSS 5.3v31v322020-08-17
CVE-2020-24370 [MEDIUM] CWE-191 CVE-2020-24370: ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as
ldebug.c in Lua 5.4.0 allows a negation overflow and segmentation fault in getlocal and setlocal, as demonstrated by getlocal(3,2^31).
nvd
CVE-2023-23589P4MEDIUMCVSS 6.5v36v372023-01-14
CVE-2023-23589 [MEDIUM] CWE-693 CVE-2023-23589: The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol ca
The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.
nvd
CVE-2021-38019P4MEDIUMCVSS 6.5v342021-12-23
CVE-2021-38019 [MEDIUM] CWE-670 CVE-2021-38019: Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote atta
Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-38009P4MEDIUMCVSS 6.5v342021-12-23
CVE-2021-38009 [MEDIUM] CWE-203 CVE-2021-38009: Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attack
Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-21164P4MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21164 [MEDIUM] CWE-346 CVE-2021-21164: Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed
Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-0111P4MEDIUMCVSS 6.5v34v35+1 more2022-02-12
CVE-2022-0111 [MEDIUM] CWE-346 CVE-2022-0111: Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote a
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.
nvd
CVE-2022-2610P4MEDIUMCVSS 6.5v372022-08-12
CVE-2022-2610 [MEDIUM] CWE-668 CVE-2022-2610: Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed
Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-2160P4MEDIUMCVSS 6.5v35v362022-07-28
CVE-2022-2160 [MEDIUM] CWE-362 CVE-2022-2160: Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allow
Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.
nvd
CVE-2022-2612P4MEDIUMCVSS 6.5v372022-08-12
CVE-2022-2612 [MEDIUM] CWE-203 CVE-2022-2612: Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a
Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2023-1073P4MEDIUMCVSS 6.6v372023-03-27
CVE-2023-1073 [MEDIUM] CWE-119 CVE-2023-1073: A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in h
A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.
nvd
CVE-2022-2615P4MEDIUMCVSS 6.5v372022-08-12
CVE-2022-2615 [MEDIUM] CWE-565 CVE-2022-2615: Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2022-4926P4MEDIUMCVSS 6.5v382023-07-29
CVE-2022-4926 [MEDIUM] CWE-522 CVE-2022-4926: Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allow
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2020-2760P4MEDIUMCVSS 5.5v30v31+1 more2020-04-15
CVE-2020-2760 [MEDIUM] CVE-2020-2760: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
nvd
CVE-2021-21333P4MEDIUMCVSS 6.1v342021-03-26
CVE-2021-21333 [MEDIUM] CWE-74 CVE-2021-21333: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.27.0, the notification emails sent for notifications for missed messages or for an expiring account are subject to HTML injection. In the case of the notification fo
nvd