cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 189 of 264
CVE-2022-2928P4MEDIUMCVSS 6.5v35v36+1 more2022-10-07
CVE-2022-2928 [MEDIUM] CWE-476 CVE-2022-2928: In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_has In ISC DHCP 4.4.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1, when the function option_code_hash_lookup() is called from add_option(), it increases the option's refcount field. However, there is not a corresponding call to option_dereference() to decrement the refcount field. The function add_option() is only used in server responses to lease que
nvd
CVE-2022-2929P4MEDIUMCVSS 6.5v35v36+1 more2022-10-07
CVE-2022-2929 [MEDIUM] CWE-770 CVE-2022-2929: In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP serve In ISC DHCP 1.0 -> 4.4.3, ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16-P1 a system with access to a DHCP server, sending DHCP packets crafted to include fqdn labels longer than 63 bytes, could eventually cause the server to run out of memory.
nvd
CVE-2019-5754P4MEDIUMCVSS 6.5v29v302019-02-19
CVE-2019-5754 [MEDIUM] CWE-327 CVE-2019-5754: Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker r Implementation error in QUIC Networking in Google Chrome prior to 72.0.3626.81 allowed an attacker running or able to cause use of a proxy server to obtain cleartext of transport encryption via malicious network proxy.
nvd
CVE-2020-1760P4MEDIUMCVSS 6.1v312020-04-23
CVE-2020-1760 [MEDIUM] CWE-79 CVE-2020-1760: A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in A flaw was found in the Ceph Object Gateway, where it supports request sent by an anonymous user in Amazon S3. This flaw could lead to potential XSS attacks due to the lack of proper neutralization of untrusted input.
nvd
CVE-2013-6370P4MEDIUMCVSS 5.0v202014-04-22
CVE-2013-6370 [MEDIUM] CWE-119 CVE-2013-6370: Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial Buffer overflow in the printbuf APIs in json-c before 0.12 allows remote attackers to cause a denial of service via unspecified vectors.
nvd
CVE-2020-25702P4MEDIUMCVSS 6.1v32v332020-11-19
CVE-2020-25702 [MEDIUM] CWE-79 CVE-2020-25702: In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affecte In Moodle, it was possible to include JavaScript when re-naming content bank items. Versions affected: 3.9 to 3.9.2. This is fixed in moodle 3.9.3 and 3.10.
nvd
CVE-2023-31130P4MEDIUMCVSS 6.4v37v382023-05-25
CVE-2023-31130 [MEDIUM] CWE-124 CVE-2023-31130: c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses, in particular "0::00:00:00/2" was found to cause an issue. C-ares only uses this function internally for configuration purposes which would require an administrator to configure such an address via ares_set_sortlist(). How
nvd
CVE-2020-10941P4MEDIUMCVSS 5.9v31v322020-03-24
CVE-2020-10941 [MEDIUM] CVE-2020-10941: Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by Arm Mbed TLS before 2.16.5 allows attackers to obtain sensitive information (an RSA private key) by measuring cache usage during an import.
nvd
CVE-2022-26362P4MEDIUMCVSS 6.4v35v362022-06-09
CVE-2022-26362 [MEDIUM] CWE-362 CVE-2022-26362: x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in add x86 pv: Race condition in typeref acquisition Xen maintains a type reference count for pages, in addition to a regular reference count. This scheme is used to maintain invariants required for Xen's safety, e.g. PV guests may not have direct writeable access to pagetables; updates need auditing by Xen. Unfortunately, the logic for acquiring a type re
nvd
CVE-2021-22004P4MEDIUMCVSS 6.4v33v34+1 more2021-09-08
CVE-2021-22004 [MEDIUM] CWE-362 CVE-2021-22004: An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and u An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.
nvd
CVE-2022-35651P4MEDIUMCVSS 6.1v35v362022-07-25
CVE-2022-35651 [MEDIUM] CWE-79 CVE-2022-35651: A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitizati A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's browser in context of vulnerable website to steal potentially sensitive
nvd
CVE-2023-22298P4MEDIUMCVSS 6.1v362023-01-17
CVE-2023-22298 [MEDIUM] CWE-601 CVE-2023-22298: Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated att Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
nvd
CVE-2024-34403P4MEDIUMCVSS 5.9v38v39+1 more2024-05-03
CVE-2024-34403 [MEDIUM] CWE-190 CVE-2024-34403: An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an inte An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
nvd
CVE-2021-42781P4MEDIUMCVSS 5.3v332022-04-18
CVE-2021-42781 [MEDIUM] CWE-119 CVE-2021-42781: Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that cou Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
nvd
CVE-2024-3847P4MEDIUMCVSS 6.1v38v39+1 more2024-04-17
CVE-2024-3847 [MEDIUM] CWE-79 CVE-2024-3847: Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote at Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-40626P4MEDIUMCVSS 6.1v372022-09-14
CVE-2022-40626 [MEDIUM] CWE-79 CVE-2022-40626: An unauthenticated user can create a link with reflected Javascript code inside the backurl paramete An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend.
nvd
CVE-2021-42782P4MEDIUMCVSS 5.3v332022-04-18
CVE-2021-42782 [MEDIUM] CWE-119 CVE-2021-42782: Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could Stack buffer overflow issues were found in Opensc before version 0.22.0 in various places that could potentially crash programs using the library.
nvd
CVE-2019-3870P4MEDIUMCVSS 6.1v29v302019-04-09
CVE-2019-3870 [MEDIUM] CWE-276 CVE-2019-3870: A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permission
nvd
CVE-2015-4879P4MEDIUMCVSS 4.6v232015-10-21
CVE-2015-4879 [MEDIUM] CVE-2015-4879: Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.44 and earlier, and 5.6.25 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to DML.
nvd
CVE-2021-39360P4MEDIUMCVSS 5.9v33v34+1 more2021-08-22
CVE-2021-39360 [MEDIUM] CVE-2021-39360: In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on th In GNOME libzapojit through 0.0.3, zpj-skydrive.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
nvd
Fedoraproject Fedora vulnerabilities | cvebase