cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 180 of 264
CVE-2021-30890P4MEDIUMCVSS 6.1v34v352021-08-24
CVE-2021-30890 [MEDIUM] CWE-79 CVE-2021-30890: A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.0.1, iOS 15.1 and iPadOS 15.1, watchOS 8.1, tvOS 15.1. Processing maliciously crafted web content may lead to universal cross site scripting.
nvd
CVE-2021-3573P4MEDIUMCVSS 6.4v342021-08-13
CVE-2021-3573 [MEDIUM] CWE-362 CVE-2021-3573: A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in t A use-after-free in function hci_sock_bound_ioctl() of the Linux kernel HCI subsystem was found in the way user calls ioct HCIUNBLOCKADDR or other way triggers race condition of the call hci_unregister_dev() together with one of the calls hci_sock_blacklist_add(), hci_sock_blacklist_del(), hci_get_conn_info(), hci_get_auth_info(). A privileged local u
nvd
CVE-2020-1730P4MEDIUMCVSS 5.3v31v322020-04-13
CVE-2020-1730 [MEDIUM] CWE-476 CVE-2020-1730: A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or A flaw was found in libssh versions before 0.8.9 and before 0.9.4 in the way it handled AES-CTR (or DES ciphers if enabled) ciphers. The server or client could crash when the connection hasn't been fully initialized and the system tries to cleanup the ciphers when closing the connection. The biggest threat from this vulnerability is system availability
nvd
CVE-2023-28447P4MEDIUMCVSS 6.1v36v37+1 more2023-03-28
CVE-2023-28447 [MEDIUM] CWE-79 CVE-2023-28447: Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript Smarty is a template engine for PHP. In affected versions smarty did not properly escape javascript code. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session. This may lead to unauthorized access to sensitive user data, manipulation of the web application's behavior, or unautho
nvd
CVE-2020-15257P4MEDIUMCVSS 5.2v332020-12-01
CVE-2020-15257 [MEDIUM] CWE-669 CVE-2020-15257: containerd is an industry-standard container runtime and is available as a daemon for Linux and Wind containerd is an industry-standard container runtime and is available as a daemon for Linux and Windows. In containerd before versions 1.3.9 and 1.4.3, the containerd-shim API is improperly exposed to host network containers. Access controls for the shim’s API socket verified that the connecting process had an effective UID of 0, but did not otherwi
nvd
CVE-2023-38633P4MEDIUMCVSS 5.5v37v382023-07-22
CVE-2023-38633 [MEDIUM] CWE-22 CVE-2023-38633: A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or A directory traversal problem in the URL decoder of librsvg before 2.56.3 could be used by local or remote attackers to disclose files (on the local filesystem outside of the expected area), as demonstrated by href=".?../../../../../../../../../../etc/passwd" in an xi:include element.
nvd
CVE-2019-11065P4MEDIUMCVSS 5.9v28v29+1 more2019-04-10
CVE-2019-11065 [MEDIUM] CVE-2019-11065: Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-i Gradle versions from 1.4 to 5.3.1 use an insecure HTTP URL to download dependencies when the built-in JavaScript or CoffeeScript Gradle plugins are used. Dependency artifacts could have been maliciously compromised by a MITM attack against the ajax.googleapis.com web site.
nvd
CVE-2021-39219P4MEDIUMCVSS 6.3v34v352021-09-17
CVE-2021-39219 [MEDIUM] CWE-843 CVE-2021-39219: Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affecte Wasmtime is an open source runtime for WebAssembly & WASI. Wasmtime before version 0.30.0 is affected by a type confusion vulnerability. As a Rust library the `wasmtime` crate clearly marks which functions are safe and which are `unsafe`, guaranteeing that if consumers never use `unsafe` then it should not be possible to have memory unsafety issues
nvd
CVE-2020-25653P4MEDIUMCVSS 6.3v32v332020-11-26
CVE-2020-25653 [MEDIUM] CWE-362 CVE-2020-25653: A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client con A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from the host. The highest threat from this vulnerability is to data confide
nvd
CVE-2023-5981P4MEDIUMCVSS 5.9v37v382023-11-28
CVE-2023-5981 [MEDIUM] CWE-208 CVE-2023-5981: A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExcha A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.
nvd
CVE-2023-1611P4MEDIUMCVSS 6.3v36v372023-04-03
CVE-2023-1611 [MEDIUM] CWE-416 CVE-2023-1611: A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kerne A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea
nvd
CVE-2020-14312P4MEDIUMCVSS 5.9fixed in 312021-02-06
CVE-2020-14312 [MEDIUM] CWE-284 CVE-2020-14312: A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 3 A flaw was found in the default configuration of dnsmasq, as shipped with Fedora versions prior to 31 and in all versions Red Hat Enterprise Linux, where it listens on any interface and accepts queries from addresses outside of its local subnet. In particular, the option `local-service` is not enabled. Running dnsmasq in this manner may inadvertentl
nvd
CVE-2023-28755P4MEDIUMCVSS 5.3v36v37+1 more2023-03-31
CVE-2023-28755 [MEDIUM] CWE-1333 CVE-2023-28755: A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI pars A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
nvd
CVE-2020-4046P4MEDIUMCVSS 5.4v31v322020-06-12
CVE-2020-4046 [MEDIUM] CWE-80 CVE-2020-4046: In affected versions of WordPress, users with low privileges (like contributors and authors) can use In affected versions of WordPress, users with low privileges (like contributors and authors) can use the embed block in a certain way to inject unfiltered HTML in the block editor. When affected posts are viewed by a higher privileged user, this could lead to script execution in the editor/wp-admin. This has been patched in version 5.4.2, along with al
nvd
CVE-2014-8119P4HIGHCVSS 7.5v20v21+1 more2017-12-29
CVE-2014-8119 [HIGH] CWE-20 CVE-2014-8119: The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of servic The find_ifcfg_path function in netcf before 0.2.7 might allow attackers to cause a denial of service (application crash) via vectors involving augeas path expressions.
nvd
CVE-2022-39264P4MEDIUMCVSS 5.9v36v372022-09-28
CVE-2022-39264 [MEDIUM] CWE-287 CVE-2022-39264: nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vu nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a workaround, one may apply the patch manually, avoid doing verifications of one's o
nvd
CVE-2020-12272P4MEDIUMCVSS 5.3v33v342020-04-27
CVE-2020-12272 [MEDIUM] CWE-290 CVE-2020-12272: OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false OpenDMARC through 1.3.2 and 1.4.x allows attacks that inject authentication results to provide false information about the domain that originated an e-mail message. This is caused by incorrect parsing and interpretation of SPF/DKIM authentication results, as demonstrated by the example.net(.example.com substring.
nvd
CVE-2022-21628P4MEDIUMCVSS 5.3v35v362022-10-18
CVE-2022-21628 [MEDIUM] CVE-2022-21628: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Easily exploitable vulnerability allows unauthenticated attac
nvd
CVE-2019-2778P4MEDIUMCVSS 5.4v29v302019-07-23
CVE-2019-2778 [MEDIUM] CVE-2019-2778: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability
nvd
CVE-2020-20739P4MEDIUMCVSS 5.3v322020-11-20
CVE-2020-20739 [MEDIUM] CWE-909 CVE-2020-20739: im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.
nvd
Fedoraproject Fedora vulnerabilities | cvebase