cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 187 of 264
CVE-2015-2751P4HIGHCVSS 7.1v20v212015-04-01
CVE-2015-2751 [HIGH] CWE-17 CVE-2015-2751: Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial Xen 4.3.x, 4.4.x, and 4.5.x, when using toolstack disaggregation, allows remote domains with partial management control to cause a denial of service (host lock) via unspecified domctl operations.
nvd
CVE-2024-38273P4MEDIUMCVSS 5.4v39v402024-06-18
CVE-2024-38273 [MEDIUM] CWE-284 CVE-2024-38273: Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access.
nvd
CVE-2024-24568P4MEDIUMCVSS 5.3v38v392024-02-26
CVE-2024-24568 [MEDIUM] CWE-284 CVE-2024-24568: Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security M Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3.
nvd
CVE-2023-6693P4MEDIUMCVSS 5.3v392024-01-02
CVE-2023-6693 [MEDIUM] CWE-121 CVE-2023-6693: A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flu A stack based buffer overflow was found in the virtio-net device of QEMU. This issue occurs when flushing TX in the virtio_net_flush_tx function if guest features VIRTIO_NET_F_HASH_REPORT, VIRTIO_F_VERSION_1 and VIRTIO_NET_F_MRG_RXBUF are enabled. This could allow a malicious user to overwrite local variables allocated on the stack. Specifically, the
nvd
CVE-2018-14498P4MEDIUMCVSS 6.5v282019-03-07
CVE-2018-14498 [MEDIUM] CWE-125 CVE-2018-14498: get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers t get_8bit_row in rdbmp.c in libjpeg-turbo through 1.5.90 and MozJPEG through 3.3.1 allows attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted 8-bit BMP in which one or more of the color indices is out of range for the number of palette entries.
nvd
CVE-2019-9917P4MEDIUMCVSS 6.5v28v29+1 more2019-03-27
CVE-2019-9917 [MEDIUM] CWE-20 CVE-2019-9917: ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid ZNC before 1.7.3-rc1 allows an existing remote user to cause a Denial of Service (crash) via invalid encoding.
nvd
CVE-2020-17498P4MEDIUMCVSS 6.5v31v322020-08-13
CVE-2020-17498 [MEDIUM] CWE-415 CVE-2020-17498: In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/di In Wireshark 3.2.0 to 3.2.5, the Kafka protocol dissector could crash. This was addressed in epan/dissectors/packet-kafka.c by avoiding a double free during LZ4 decompression.
nvd
CVE-2022-0856P4MEDIUMCVSS 6.5v37v382022-03-10
CVE-2022-0856 [MEDIUM] CWE-369 CVE-2022-0856: libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to c libcaca is affected by a Divide By Zero issue via img2txt, which allows a remote malicious user to cause a Denial of Service
nvd
CVE-2019-11372P4MEDIUMCVSS 6.5v28v29+1 more2019-04-20
CVE-2019-11372 [MEDIUM] CWE-125 CVE-2019-11372: An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in Medi An out-of-bounds read in MediaInfoLib::File__Tags_Helper::Synched_Test in Tag/File__Tags.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
nvd
CVE-2019-11373P4MEDIUMCVSS 6.5v28v29+1 more2019-04-20
CVE-2019-11373 [MEDIUM] CWE-125 CVE-2019-11373: An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaA An out-of-bounds read in File__Analyze::Get_L8 in File__Analyze_Buffer.cpp in MediaInfoLib in MediaArea MediaInfo 18.12 leads to a crash.
nvd
CVE-2019-9903P4MEDIUMCVSS 6.5v28v29+1 more2019-03-21
CVE-2019-9903 [MEDIUM] CWE-787 CVE-2019-9903: PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumpt PDFDoc::markObject in PDFDoc.cc in Poppler 0.74.0 mishandles dict marking, leading to stack consumption in the function Dict::find() located at Dict.cc, which can (for example) be triggered by passing a crafted pdf file to the pdfunite binary.
nvd
CVE-2020-1983P4MEDIUMCVSS 6.5v31v322020-04-22
CVE-2020-1983 [MEDIUM] CWE-416 CVE-2020-1983: A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allo A use after free vulnerability in ip_reass() in ip_input.c of libslirp 4.2.0 and prior releases allows crafted packets to cause a denial of service.
nvd
CVE-2018-20097P4MEDIUMCVSS 6.5v302018-12-12
CVE-2018-20097 [MEDIUM] CWE-119 CVE-2018-20097: There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv There is a SEGV in Exiv2::Internal::TiffParserWorker::findPrimaryGroups of tiffimage_int.cpp in Exiv2 0.27-RC3. A crafted input will lead to a remote denial of service attack.
nvd
CVE-2023-20569P4MEDIUMCVSS 4.7v37v382023-08-08
CVE-2023-20569 [MEDIUM] CWE-203 CVE-2023-20569: A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the retur A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
nvd
CVE-2021-30594P4MEDIUMCVSS 6.8v33v34+1 more2021-08-26
CVE-2021-30594 [MEDIUM] CWE-416 CVE-2021-30594: Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to Use after free in Page Info UI in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via physical access to the device.
nvd
CVE-2013-0159P4HIGHCVSS 7.1v17v182018-05-01
CVE-2013-0159 [HIGH] CWE-59 CVE-2013-0159: The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 o The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-buffer.svg.
nvd
CVE-2022-34526P4MEDIUMCVSS 6.5v362022-07-29
CVE-2022-34526 [MEDIUM] CWE-787 CVE-2022-34526: A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerabili A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.
nvd
CVE-2018-19497P4MEDIUMCVSS 6.5v29v302018-11-29
CVE-2018-19497 [MEDIUM] CWE-125 CVE-2018-19497: In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to cause a denial of service (SEGV on unknown address with READ memory access in a tsk_getu16 call in hfs_dir_open_meta_cb in tsk/fs/hfs_dent.c).
nvd
CVE-2022-31160P4MEDIUMCVSS 6.1v35v36+1 more2022-07-20
CVE-2022-31160 [MEDIUM] CWE-79 CVE-2022-31160: jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "r
nvd
CVE-2014-8132P4MEDIUMCVSS 5.0v19v20+1 more2014-12-29
CVE-2014-8132 [MEDIUM] CVE-2014-8132: Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x befo Double free vulnerability in the ssh_packet_kexinit function in kex.c in libssh 0.5.x and 0.6.x before 0.6.4 allows remote attackers to cause a denial of service via a crafted kexinit packet.
nvd
Fedoraproject Fedora vulnerabilities | cvebase