cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 18 of 264
CVE-2020-8277P3HIGHCVSS 7.5v32v332020-11-19
CVE-2020-8277 [HIGH] CWE-400 CVE-2020-8277: A Node.js application that allows an attacker to trigger a DNS request for a host of their choice co A Node.js application that allows an attacker to trigger a DNS request for a host of their choice could trigger a Denial of Service in versions < 15.2.1, < 14.15.1, and < 12.19.1 by getting the application to resolve a DNS record with a larger number of responses. This is fixed in 15.2.1, 14.15.1, and 12.19.1.
nvd
CVE-2020-13576P2CRITICALCVSS 9.8v33v342021-02-10
CVE-2020-13576 [CRITICAL] CWE-680 CVE-2020-13576: A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8 A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
nvd
CVE-2012-4528P3MEDIUMCVSS 5.0PoCv182012-12-28
CVE-2012-4528 [MEDIUM] CVE-2012-4528: The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass r The mod_security2 module before 2.7.0 for the Apache HTTP Server allows remote attackers to bypass rules, and deliver arbitrary POST data to a PHP application, via a multipart request in which an invalid part precedes the crafted data.
nvd
CVE-2021-25283P2CRITICALCVSS 9.8v32v33+1 more2021-02-27
CVE-2021-25283 [CRITICAL] CWE-94 CVE-2021-25283: An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
nvd
CVE-2022-24065P2CRITICALCVSS 9.8v35v362022-06-08
CVE-2022-24065 [CRITICAL] CWE-78 CVE-2022-24065: The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. The package cookiecutter before 2.1.1 are vulnerable to Command Injection via hg argument injection. When calling the cookiecutter function from Python code with the checkout parameter, it is passed to the hg checkout command in a way that additional flags can be set. The additional flags can be used to perform a command injection.
nvd
CVE-2020-11987P2HIGHCVSS 8.2v33v342021-02-24
CVE-2020-11987 [HIGH] CWE-20 CVE-2020-11987: Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
nvd
CVE-2021-31618P3HIGHCVSS 7.5v33v342021-06-15
CVE-2021-31618 [HIGH] CWE-476 CVE-2021-31618: Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against Apache HTTP Server protocol handler for the HTTP/2 protocol checks received request headers against the size limitations as configured for the server and used for the HTTP/1 protocol as well. On violation of these restrictions and HTTP response is sent to the client with a status code indicating why the request was rejected. This rejection response was
nvd
CVE-2022-36944P2CRITICALCVSS 9.8v35v362022-09-23
CVE-2022-36944 [CRITICAL] CWE-502 CVE-2022-36944: Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot b Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specific
nvd
CVE-2020-6541P3HIGHCVSS 8.8v332020-09-21
CVE-2020-6541 [HIGH] CWE-416 CVE-2020-6541: Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potent Use after free in WebUSB in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-24883P2CRITICALCVSS 9.8v34v35+1 more2022-04-26
CVE-2022-24883 [CRITICAL] CWE-287 CVE-2022-24883: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, serve FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not affected. RDP server implementations using FreeRDP to authenticate against
nvd
CVE-2023-29404P2CRITICALCVSS 9.8v382023-06-08
CVE-2023-29404 [CRITICAL] CWE-94 CVE-2023-29404: The go command may execute arbitrary code at build time when using cgo. This may occur when running The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. The arguments for a number of flags which are non-optional are incorrect
nvd
CVE-2023-29405P2CRITICALCVSS 9.8v382023-06-08
CVE-2023-29405 [CRITICAL] CWE-74 CVE-2023-29405: The go command may execute arbitrary code at build time when using cgo. This may occur when running The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive. Flags containing embedded spaces are mishandled, allowing disallowed fla
nvd
CVE-2019-11356P2CRITICALCVSS 9.8v29v302019-06-03
CVE-2019-11356 [CRITICAL] CWE-787 CVE-2019-11356: The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote The CalDAV feature in httpd in Cyrus IMAP 2.5.x through 2.5.12 and 3.0.x through 3.0.9 allows remote attackers to execute arbitrary code via a crafted HTTP PUT operation for an event with a long iCalendar property name.
nvd
CVE-2023-6395P2CRITICALCVSS 9.8v38v392024-01-16
CVE-2023-6395 [CRITICAL] CWE-20 CVE-2023-6395: The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege e The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of Jinja2 templates, which may be included in certain configuration parameters.
nvd
CVE-2024-3209P2CRITICALCVSS 9.8v38v39+1 more2024-04-02
CVE-2024-3209 [CRITICAL] CWE-122 CVE-2024-3209: A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055. NOTE: The vendor was contacted earl
nvd
CVE-2023-24805P2HIGHCVSS 8.8v37v382023-05-17
CVE-2023-24805 [HIGH] CWE-78 CVE-2023-24805: cups-filters contains backends, filters, and other software required to get the cups printing servic cups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. If you use the Backend Error Handler (beh) to create an accessible network printer, this security vulnerability can cause remote code execution. `beh.c` contains the line `retval = system(cmdline) >> 8;` w
nvd
CVE-2016-10243P2CRITICALCVSS 9.8v25v262017-05-02
CVE-2016-10243 [CRITICAL] CWE-20 CVE-2016-10243: TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in s TeX Live allows remote attackers to execute arbitrary commands by leveraging inclusion of mpost in shell_escape_commands in the texmf.cnf config file.
nvd
CVE-2021-45079P2CRITICALCVSS 9.1v34v352022-01-31
CVE-2021-45079 [CRITICAL] CWE-476 CVE-2021-45079: In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.
nvd
CVE-2015-8980P2CRITICALCVSS 9.8v242019-11-04
CVE-2015-8980 [CRITICAL] CWE-20 CVE-2015-8980: The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attac The plural form formula in ngettext family of calls in php-gettext before 1.0.12 allows remote attackers to execute arbitrary code.
nvd
CVE-2021-32610P3HIGHCVSS 7.1v33v34+1 more2021-07-30
CVE-2021-32610 [HIGH] CVE-2021-32610: In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a diff In Archive_Tar before 1.4.14, symlinks can refer to targets outside of the extracted archive, a different vulnerability than CVE-2020-36193.
nvd
Fedoraproject Fedora vulnerabilities | cvebase