Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 183 of 264
CVE-2020-36151P4MEDIUMCVSS 6.5v322021-02-08
CVE-2020-36151 [MEDIUM] CWE-787 CVE-2020-36151: Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5
Incorrect handling of input data in mysofa_resampler_reset_mem function in the libmysofa library 0.5 - 1.1 will lead to heap buffer overflow and overwriting large memory block.
nvd
CVE-2015-7295P4MEDIUMCVSS 5.0v21v222015-11-09
CVE-2015-7295 [MEDIUM] CWE-119 CVE-2015-7295: hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable
hw/virtio/virtio.c in the Virtual Network Device (virtio-net) support in QEMU, when big or mergeable receive buffers are not supported, allows remote attackers to cause a denial of service (guest network consumption) via a flood of jumbo frames on the (1) tuntap or (2) macvtap interface.
nvd
CVE-2020-8551P4MEDIUMCVSS 6.5v322020-03-27
CVE-2020-8551 [MEDIUM] CWE-789 CVE-2020-8551: The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to
The Kubelet component in versions 1.15.0-1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via the kubelet API, including the unauthenticated HTTP read-only API typically served on port 10255, and the authenticated HTTPS API typically served on port 10250.
nvd
CVE-2020-7106P4MEDIUMCVSS 6.1v30v312020-01-16
CVE-2020-7106 [MEDIUM] CWE-79 CVE-2020-7106: Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.ph
Cacti 1.2.8 has stored XSS in data_sources.php, color_templates_item.php, graphs.php, graph_items.php, lib/api_automation.php, user_admin.php, and user_group_admin.php, as demonstrated by the description parameter in data_sources.php (a raw string from the database that is displayed by $header to trigger the XSS).
nvd
CVE-2019-3877P4MEDIUMCVSS 6.1v292019-03-27
CVE-2019-3877 [MEDIUM] CWE-601 CVE-2019-3877: A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allo
A vulnerability was found in mod_auth_mellon before v0.14.2. An open redirect in the logout URL allows requests with backslashes to pass through by assuming that it is a relative URL, while the browsers silently convert backslash characters into forward slashes treating them as an absolute URL. This mismatch allows an attacker to bypass the redirect U
nvd
CVE-2020-6547P4MEDIUMCVSS 6.5v332020-09-21
CVE-2020-6547 [MEDIUM] CWE-1021 CVE-2020-6547: Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to
Incorrect security UI in media in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially obtain sensitive information via a crafted HTML page.
nvd
CVE-2015-0886P4MEDIUMCVSS 5.0v20v21+1 more2015-02-28
CVE-2015-0886 [MEDIUM] CWE-190 CVE-2015-0886: Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4
Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum exponent.
nvd
CVE-2021-21211P4MEDIUMCVSS 6.5v32v33+1 more2021-04-26
CVE-2021-21211 [MEDIUM] CWE-346 CVE-2021-21211: Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a r
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6538P4MEDIUMCVSS 6.5v332020-09-21
CVE-2020-6538 [MEDIUM] CVE-2020-6538: Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a
Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-8296P4MEDIUMCVSS 6.7v342021-03-03
CVE-2020-8296 [MEDIUM] CWE-257 CVE-2020-8296: Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
nvd
CVE-2016-3320P4MEDIUMCVSS 4.9v252016-08-09
CVE-2016-3320 [MEDIUM] CWE-254 CVE-2016-3320: Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511
Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allow attackers to bypass the Secure Boot protection mechanism by leveraging (1) administrative or (2) physical access to install a crafted boot manager, aka "Secure Boot Security Feature Bypass."
nvd
CVE-2022-26364P4MEDIUMCVSS 6.7v35v362022-06-09
CVE-2022-26364 [MEDIUM] CVE-2022-26364: x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multipl
x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests ma
nvd
CVE-2020-14344P4MEDIUMCVSS 6.7v31v32+1 more2020-08-05
CVE-2020-14344 [MEDIUM] CWE-190 CVE-2020-14344: An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client w
An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No such programs are shipped with Red Hat Enterprise Linux.
nvd
CVE-2021-34339P4MEDIUMCVSS 6.5v352022-03-10
CVE-2021-34339 [MEDIUM] CWE-125 CVE-2021-34339: Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file
Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
nvd
CVE-2020-29668P4LOWCVSS 3.7v32v332020-12-10
CVE-2020-29668 [LOW] CWE-287 CVE-2020-29668: Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitra
Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.
nvd
CVE-2021-42739P4MEDIUMCVSS 6.7v33v34+1 more2021-10-20
CVE-2021-42739 [MEDIUM] CWE-787 CVE-2021-42739: The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/
The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.
nvd
CVE-2019-5814P4MEDIUMCVSS 6.5v29v302019-06-27
CVE-2019-5814 [MEDIUM] CWE-352 CVE-2019-5814: Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote at
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-38010P4MEDIUMCVSS 6.5v342021-12-23
CVE-2021-38010 [MEDIUM] CVE-2021-38010: Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a rem
Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2021-34340P4MEDIUMCVSS 6.5v352022-03-10
CVE-2021-34340 [MEDIUM] CWE-125 CVE-2021-34340: Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompil
Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
nvd
CVE-2020-26934P4MEDIUMCVSS 6.1v31v32+1 more2020-10-10
CVE-2020-26934 [MEDIUM] CWE-79 CVE-2020-26934: phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a cra
phpMyAdmin before 4.9.6 and 5.x before 5.0.3 allows XSS through the transformation feature via a crafted link.
nvd