Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 186 of 264
CVE-2019-16910P4MEDIUMCVSS 5.3v29v30+1 more2019-09-26
CVE-2019-16910 [MEDIUM] CVE-2019-16910: Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, us
Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times. (For Mbed TLS, the fix is also available in versions 2.7.12 and 2.16.3.)
nvd
CVE-2021-41800P4MEDIUMCVSS 5.3v33v34+1 more2021-10-11
CVE-2021-41800 [MEDIUM] CWE-770 CVE-2021-41800: MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query pr
MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.
nvd
CVE-2021-30158P4MEDIUMCVSS 5.3v33v342021-04-06
CVE-2021-30158 [MEDIUM] CWE-287 CVE-2021-30158: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Blocked users are unable to use Special:ResetTokens. This has security relevance because a blocked user might have accidentally shared a token, or might know that a token has been compromised, and yet is not able to block any potential future use of the toke
nvd
CVE-2020-13977P4MEDIUMCVSS 4.9v32v33+1 more2020-06-09
CVE-2020-13977 [MEDIUM] CWE-829 CVE-2020-13977: Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON C
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.
nvd
CVE-2021-21424P4MEDIUMCVSS 5.3v33v342021-05-13
CVE-2021-21424 [MEDIUM] CWE-200 CVE-2021-21424: Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Th
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. The ability to enumerate users was possible without relevant permissions due to different handling depending on whether the user existed or not when attempting to use the switch users functionality. We now ensure that 403s are returned whether the user
nvd
CVE-2022-1328P4MEDIUMCVSS 5.3v362022-04-14
CVE-2022-1328 [MEDIUM] CWE-120 CVE-2022-1328: Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allow
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
nvd
CVE-2023-26118P4MEDIUMCVSS 5.3v382023-03-30
CVE-2023-26118 [MEDIUM] CWE-1333 CVE-2023-26118: Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (R
Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the element due to the usage of an insecure regular expression in the input[url] functionality. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
nvd
CVE-2021-29471P4MEDIUMCVSS 5.3v342021-05-11
CVE-2021-29471 [MEDIUM] CWE-400 CVE-2021-29471: Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is
Synapse is a Matrix reference homeserver written in python (pypi package matrix-synapse). Matrix is an ecosystem for open federated Instant Messaging and VoIP. In Synapse before version 1.33.2 "Push rules" can specify conditions under which they will match, including `event_match`, which matches event content against a pattern including wildcards. Ce
nvd
CVE-2021-32062P4MEDIUMCVSS 5.3v33v342021-05-06
CVE-2021-32062 [MEDIUM] CWE-22 CVE-2021-32062: MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.
MapServer before 7.0.8, 7.1.x and 7.2.x before 7.2.3, 7.3.x and 7.4.x before 7.4.5, and 7.5.x and 7.6.x before 7.6.3 does not properly enforce the MS_MAP_NO_PATH and MS_MAP_PATTERN restrictions that are intended to control the locations from which a mapfile may be loaded (with MapServer CGI).
nvd
CVE-2021-32809P4MEDIUMCVSS 5.4v33v34+1 more2021-08-12
CVE-2021-32809 [MEDIUM] CWE-94 CVE-2021-32809: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste functionality using malformed HTML, which could result in injecting arbitrary HTML into the editor. It affects all
nvd
CVE-2021-34434P4MEDIUMCVSS 5.3v34v352021-08-30
CVE-2021-34434 [MEDIUM] CWE-285 CVE-2021-34434: In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
nvd
CVE-2021-44225P4MEDIUMCVSS 5.4v34v352021-11-26
CVE-2021-44225 [MEDIUM] CVE-2021-44225: In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable (writable) property
nvd
CVE-2023-51766P4MEDIUMCVSS 5.3v38v392023-12-24
CVE-2023-51766 [MEDIUM] CWE-345 CVE-2023-51766: Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attac
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports . but some other popular e-mail servers do not.
nvd
CVE-2022-24806P4MEDIUMCVSS 5.3v35v362024-04-16
CVE-2022-24806 [MEDIUM] CWE-20 CVE-2022-24806: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can exploit an Improper Input Validation vulnerability when SETing malformed OIDs in master agent and subagent simultaneously. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avo
nvd
CVE-2010-4180P4MEDIUMCVSS 4.3v13v142010-12-06
CVE-2010-4180 [MEDIUM] CVE-2010-4180: OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enab
OpenSSL before 0.9.8q, and 1.0.x before 1.0.0c, when SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG is enabled, does not properly prevent modification of the ciphersuite in the session cache, which allows remote attackers to force the downgrade to an unintended cipher via vectors involving sniffing network traffic to discover a session identifier.
nvd
CVE-2023-2455P4MEDIUMCVSS 5.4v382023-06-09
CVE-2023-2455 [MEDIUM] CWE-20 CVE-2023-2455: Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect po
Row security policies disregard user ID changes after inlining; PostgreSQL could permit incorrect policies to be applied in certain cases where role-specific policies are used and a given query is planned under one role and then executed under other roles. This scenario can happen under security definer functions or when a common user and query is plan
nvd
CVE-2011-2924P4MEDIUMCVSS 5.5v14v152019-11-19
CVE-2011-2924 [MEDIUM] CWE-59 CVE-2011-2924: foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScr
foomatic-rip filter v4.0.12 and prior used insecurely creates temporary files for storage of PostScript data by rendering the data when the debug mode was enabled. This flaw may be exploited by a local attacker to conduct symlink attacks by overwriting arbitrary files accessible with the privileges of the user running the foomatic-rip universal print f
nvd
CVE-2023-39364P4MEDIUMCVSS 5.4v37v382023-09-05
CVE-2023-39364 [MEDIUM] CWE-601 CVE-2023-39364: Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, user
Cacti is an open source operational monitoring and fault management framework. In Cacti 1.2.24, users with console access can be redirected to an arbitrary website after a change password performed via a specifically crafted URL. The `auth_changepassword.php` file accepts `ref` as a URL parameter and reflects it in the form used to perform the chang
nvd
CVE-2023-46839P4MEDIUMCVSS 5.3v392024-03-20
CVE-2023-46839 [MEDIUM] CVE-2023-46839: PCI devices can make use of a functionality called phantom functions, that when enabled allows the d
PCI devices can make use of a functionality called phantom functions,
that when enabled allows the device to generate requests using the IDs
of functions that are otherwise unpopulated. This allows a device to
extend the number of outstanding requests.
Such phantom functions need an IOMMU context setup, but failure to
setup the context is not fatal when th
nvd
CVE-2024-23301P4MEDIUMCVSS 5.5v392024-01-12
CVE-2024-23301 [MEDIUM] CWE-276 CVE-2024-23301: Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. T
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
nvd