Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 184 of 264
CVE-2023-29407P4MEDIUMCVSS 6.5v37v382023-08-02
CVE-2023-29407 [MEDIUM] CWE-834 CVE-2023-29407: A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a he
A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.
nvd
CVE-2021-21229P4MEDIUMCVSS 6.5v32v33+1 more2021-04-30
CVE-2021-21229 [MEDIUM] CWE-346 CVE-2021-21229: Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remot
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-13740P4MEDIUMCVSS 6.5v30v312019-12-10
CVE-2019-13740 [MEDIUM] CWE-346 CVE-2019-13740: Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2021-3543P4MEDIUMCVSS 6.7v342021-06-01
CVE-2021-3543 [MEDIUM] CWE-416 CVE-2021-3543: A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclav
A flaw null pointer dereference in the Nitro Enclaves kernel driver was found in the way that Enclaves VMs forces closures on the enclave file descriptor. A local user of a host machine could use this flaw to crash the system or escalate their privileges on the system.
nvd
CVE-2021-38021P4MEDIUMCVSS 6.5v342021-12-23
CVE-2021-38021 [MEDIUM] CVE-2021-38021: Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote att
Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-38018P4MEDIUMCVSS 6.5v342021-12-23
CVE-2021-38018 [MEDIUM] CVE-2021-38018: Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote a
Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2023-43279P4MEDIUMCVSS 6.5v38v39+1 more2024-03-12
CVE-2023-43279 [MEDIUM] CWE-476 CVE-2023-43279: Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to cr
Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.
nvd
CVE-2015-1840P4MEDIUMCVSS 5.0v21v222015-07-26
CVE-2015-1840 [MEDIUM] CWE-200 CVE-2015-1840: jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.
jquery_ujs.js in jquery-rails before 3.1.3 and 4.x before 4.0.4 and rails.js in jquery-ujs before 1.0.4, as used with Ruby on Rails 3.x and 4.x, allow remote attackers to bypass the Same Origin Policy, and trigger transmission of a CSRF token to a different-domain web server, via a leading space character in a URL within an attribute value.
nvd
CVE-2015-0407P4MEDIUMCVSS 5.0v202015-01-21
CVE-2015-0407 [MEDIUM] CVE-2015-0407: Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to
Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25 allows remote attackers to affect confidentiality via unknown vectors related to Swing.
nvd
CVE-2022-3057P4MEDIUMCVSS 6.5v372022-09-26
CVE-2022-3057 [MEDIUM] CWE-352 CVE-2022-3057: Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a rem
Inappropriate implementation in iframe Sandbox in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-13614P4MEDIUMCVSS 5.9v33v342020-05-26
CVE-2020-13614 [MEDIUM] CWE-295 CVE-2020-13614: An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verifi
An issue was discovered in ssl.c in Axel before 2.17.8. The TLS implementation lacks hostname verification.
nvd
CVE-2022-42799P4MEDIUMCVSS 6.1v35v36+1 more2022-11-01
CVE-2022-42799 [MEDIUM] CWE-1021 CVE-2022-42799: The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 1
The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.
nvd
CVE-2023-4813P4MEDIUMCVSS 5.9v382023-09-12
CVE-2023-4813 [MEDIUM] CWE-416 CVE-2023-4813: A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory
A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is configured with SUCCESS=continue or SUCCESS=merge.
nvd
CVE-2021-2021P4MEDIUMCVSS 4.9v32v332021-01-20
CVE-2021-2021 [MEDIUM] CVE-2021-2021: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-35937P4MEDIUMCVSS 6.4v342022-08-25
CVE-2021-35937 [MEDIUM] CVE-2021-35937: A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to by
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
nvd
CVE-2021-3700P4MEDIUMCVSS 6.4v342022-02-24
CVE-2021-3700 [MEDIUM] CWE-416 CVE-2021-3700: A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirpars
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
nvd
CVE-2022-35652P4MEDIUMCVSS 6.1v35v362022-07-25
CVE-2022-35652 [MEDIUM] CWE-601 CVE-2022-35652: An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mob
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform
nvd
CVE-2021-35604P4MEDIUMCVSS 5.5v33v34+1 more2021-10-20
CVE-2021-35604 [MEDIUM] CVE-2021-35604: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.35 and prior and 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2019-2991P4MEDIUMCVSS 5.5v29v30+1 more2019-10-16
CVE-2019-2991 [MEDIUM] CVE-2019-2991: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.017 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2023-4806P4MEDIUMCVSS 5.9v37v38+1 more2023-09-18
CVE-2023-4806 [MEDIUM] CWE-416 CVE-2023-4806: A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may ac
A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and _nss_*_getcanonname_r hooks without implementing the _nss_*_gethostbyname3_r hook. The r
nvd