Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 188 of 264
CVE-2013-6673P4MEDIUMCVSS 5.9v18v19+1 more2013-12-11
CVE-2013-6673 [MEDIUM] CWE-310 CVE-2013-6673: Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey be
Mozilla Firefox before 26.0, Firefox ESR 24.x before 24.2, Thunderbird before 24.2, and SeaMonkey before 2.23 do not recognize a user's removal of trust from an EV X.509 certificate, which makes it easier for man-in-the-middle attackers to spoof SSL servers in opportunistic circumstances via a valid certificate that is unacceptable to the user.
nvd
CVE-2015-3196P4MEDIUMCVSS 4.3v222015-12-06
CVE-2015-3196 [MEDIUM] CWE-362 CVE-2015-3196: ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when use
ssl/s3_clnt.c in OpenSSL 1.0.0 before 1.0.0t, 1.0.1 before 1.0.1p, and 1.0.2 before 1.0.2d, when used for a multi-threaded client, writes the PSK identity hint to an incorrect data structure, which allows remote servers to cause a denial of service (race condition and double free) via a crafted ServerKeyExchange message.
nvd
CVE-2015-2316P4MEDIUMCVSS 5.0v222015-03-25
CVE-2015-2316 [MEDIUM] CWE-399 CVE-2015-2316: The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x befo
The utils.html.strip_tags function in Django 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1, when using certain versions of Python, allows remote attackers to cause a denial of service (infinite loop) by increasing the length of the input string.
nvd
CVE-2021-20205P4MEDIUMCVSS 6.5v342021-03-10
CVE-2021-20205 [MEDIUM] CWE-369 CVE-2021-20205: Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused b
Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.
nvd
CVE-2020-36148P4MEDIUMCVSS 6.5v322021-02-08
CVE-2020-36148 [MEDIUM] CWE-476 CVE-2020-36148: Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will
Incorrect handling of input data in verifyAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).
nvd
CVE-2020-36149P4MEDIUMCVSS 6.5v322021-02-08
CVE-2020-36149 [MEDIUM] CWE-476 CVE-2020-36149: Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will
Incorrect handling of input data in changeAttribute function in the libmysofa library 0.5 - 1.1 will lead to NULL pointer dereference and segmentation fault error in case of restrictive memory protection or near NULL pointer overwrite in case of no memory restrictions (e.g. in embedded environments).
nvd
CVE-2021-34342P4MEDIUMCVSS 6.5v352022-03-10
CVE-2021-34342 [MEDIUM] CWE-125 CVE-2021-34342: Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which c
Ming 0.4.8 has an out-of-bounds read vulnerability in the function newVar_N() in decompile.c which causes a huge information leak.
nvd
CVE-2020-12770P4MEDIUMCVSS 6.7v30v31+1 more2020-05-09
CVE-2020-12770 [MEDIUM] CVE-2020-12770: An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call
An issue was discovered in the Linux kernel through 5.6.11. sg_write lacks an sg_remove_request call in a certain failure case, aka CID-83c6f2390040.
nvd
CVE-2015-5146P4MEDIUMCVSS 5.3v21v22+1 more2017-08-24
CVE-2015-5146 [MEDIUM] CWE-20 CVE-2015-5146: ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with
ntpd in ntp before 4.2.8p3 with remote configuration enabled allows remote authenticated users with knowledge of the configuration password and access to a computer entrusted to perform remote configuration to cause a denial of service (service crash) via a NULL byte in a crafted configuration directive packet.
nvd
CVE-2019-5810P4MEDIUMCVSS 6.5v29v302019-06-27
CVE-2019-5810 [MEDIUM] CWE-312 CVE-2019-5810: Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to ob
Information leak in autofill in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-13748P4MEDIUMCVSS 6.5v30v312019-12-10
CVE-2019-13748 [MEDIUM] CWE-862 CVE-2019-13748: Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a
Insufficient policy enforcement in developer tools in Google Chrome prior to 79.0.3945.79 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2023-1994P4MEDIUMCVSS 6.5v36v37+1 more2023-04-12
CVE-2023-1994 [MEDIUM] CWE-400 CVE-2023-1994: GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via p
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-13776P4MEDIUMCVSS 6.7v322020-06-03
CVE-2020-13776 [MEDIUM] CVE-2020-13776: systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x fo
systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000082.
nvd
CVE-2021-31811P4MEDIUMCVSS 5.5v33v342021-06-12
CVE-2021-31811 [MEDIUM] CWE-789 CVE-2021-31811: In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading th
In Apache PDFBox, a carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
nvd
CVE-2020-16145P4MEDIUMCVSS 6.1v31v322020-08-12
CVE-2020-16145 [MEDIUM] CWE-79 CVE-2020-16145: Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display
Roundcube Webmail before 1.3.15 and 1.4.8 allows stored XSS in HTML messages during message display via a crafted SVG document. This issue has been fixed in 1.4.8 and 1.3.15.
nvd
CVE-2023-29659P4MEDIUMCVSS 6.5v36v372023-05-05
CVE-2023-29659 [MEDIUM] CWE-369 CVE-2023-29659: A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted hei
A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.
nvd
CVE-2022-30783P4MEDIUMCVSS 6.7v35v362022-05-26
CVE-2022-30783 [MEDIUM] CWE-252 CVE-2022-30783: An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic betw
An invalid return code in fuse_kern_mount enables intercepting of libfuse-lite protocol traffic between NTFS-3G and the kernel in NTFS-3G through 2021.8.22 when using libfuse-lite.
nvd
CVE-2020-10722P4MEDIUMCVSS 6.7v322020-05-19
CVE-2020-10722 [MEDIUM] CWE-190 CVE-2020-10722: A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow
A vulnerability was found in DPDK versions 18.05 and above. A missing check for an integer overflow in vhost_user_set_log_base() could result in a smaller memory map than requested, possibly allowing memory corruption.
nvd
CVE-2022-26363P4MEDIUMCVSS 6.7v35v362022-06-09
CVE-2022-26363 [MEDIUM] CVE-2022-26363: x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multipl
x86 pv: Insufficient care with non-coherent mappings T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests ma
nvd
CVE-2019-5834P4MEDIUMCVSS 6.5v29v302019-06-27
CVE-2019-5834 [MEDIUM] CWE-346 CVE-2019-5834: Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attack
Insufficient data validation in Blink in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd