Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 190 of 264
CVE-2019-2993P4MEDIUMCVSS 5.3v29v30+1 more2019-10-16
CVE-2019-2993 [MEDIUM] CVE-2019-2993: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported vers
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: C API). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in una
nvd
CVE-2021-39358P4MEDIUMCVSS 5.9v33v34+1 more2021-08-22
CVE-2021-39358 [MEDIUM] CVE-2021-39358: In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on
In GNOME libgfbgraph through 0.2.4, gfbgraph-photo.c does not enable TLS certificate verification on the SoupSessionSync objects it creates, leaving users vulnerable to network MITM attacks. NOTE: this is similar to CVE-2016-20011.
nvd
CVE-2021-3504P4MEDIUMCVSS 5.4v342021-05-11
CVE-2021-3504 [MEDIUM] CWE-125 CVE-2021-3504: A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bound
A flaw was found in the hivex library in versions before 1.3.20. It is caused due to a lack of bounds check within the hivex_open function. An attacker could input a specially crafted Windows Registry (hive) file which would cause hivex to read memory beyond its normal bounds or cause the program to crash. The highest threat from this vulnerability is
nvd
CVE-2021-35608P4MEDIUMCVSS 5.3v33v34+1 more2021-10-20
CVE-2021-35608 [MEDIUM] CVE-2021-35608: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in una
nvd
CVE-2022-21301P4MEDIUMCVSS 5.5v34v352022-01-19
CVE-2022-21301 [MEDIUM] CVE-2022-21301: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2021-42779P4MEDIUMCVSS 5.3v332022-04-18
CVE-2021-42779 [MEDIUM] CWE-416 CVE-2021-42779: A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
nvd
CVE-2022-21528P4MEDIUMCVSS 5.5v35v362022-07-19
CVE-2022-21528 [MEDIUM] CVE-2022-21528: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2014-1685P4MEDIUMCVSS 5.5v19v202014-05-08
CVE-2014-1685 [MEDIUM] CVE-2014-1685: The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows re
The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
nvd
CVE-2020-6394P4MEDIUMCVSS 5.4v30v312020-02-11
CVE-2020-6394 [MEDIUM] CVE-2020-6394: Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote att
Insufficient policy enforcement in Blink in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2020-35655P4MEDIUMCVSS 5.4v32v332021-01-12
CVE-2020-35655 [MEDIUM] CWE-125 CVE-2020-35655: In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE ima
In Pillow before 8.1.0, SGIRleDecode has a 4-byte buffer over-read when decoding crafted SGI RLE image files because offsets and length tables are mishandled.
nvd
CVE-2013-6456P4MEDIUMCVSS 5.8v202014-04-15
CVE-2013-6456 [MEDIUM] CWE-59 CVE-2013-6456: The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete ar
The LXC driver (lxc/lxc_driver.c) in libvirt 1.0.1 through 1.2.1 allows local users to (1) delete arbitrary host devices via the virDomainDeviceDettach API and a symlink attack on /dev in the container; (2) create arbitrary nodes (mknod) via the virDomainDeviceAttach API and a symlink attack on /dev in the container; and cause a denial of service (shut
nvd
CVE-2020-14556P4MEDIUMCVSS 4.8v31v322020-07-15
CVE-2020-14556 [MEDIUM] CVE-2020-14556: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-7041P4MEDIUMCVSS 5.3v30v31+1 more2020-02-27
CVE-2020-7041 [MEDIUM] CWE-295 CVE-2020-7041: An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c misha
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because an X509_check_host negative error code is interpreted as a successful return value.
nvd
CVE-2023-26116P4MEDIUMCVSS 5.3v382023-03-30
CVE-2023-26116 [MEDIUM] CWE-1333 CVE-2023-26116: Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (
Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
nvd
CVE-2023-26117P4MEDIUMCVSS 5.3v382023-03-30
CVE-2023-26117 [MEDIUM] CWE-1333 CVE-2023-26117: Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (R
Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is possible by a large carefully-crafted input, which can result in catastrophic backtracking.
nvd
CVE-2022-21254P4MEDIUMCVSS 5.3v34v352022-01-19
CVE-2022-21254 [MEDIUM] CVE-2022-21254: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abilit
nvd
CVE-2012-5656P4MEDIUMCVSS 5.5v16v17+1 more2013-01-18
CVE-2012-5656 [MEDIUM] CWE-611 CVE-2012-5656: The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via a
The rasterization process in Inkscape before 0.48.4 allows local users to read arbitrary files via an external entity in a SVG file, aka an XML external entity (XXE) injection attack.
nvd
CVE-2020-2800P4MEDIUMCVSS 4.8v30v31+1 more2020-04-15
CVE-2020-2800 [MEDIUM] CVE-2020-2800: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTT
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Lightweight HTTP Server). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embed
nvd
CVE-2021-33515P4MEDIUMCVSS 4.8v33v342021-06-28
CVE-2021-33515 [MEDIUM] CWE-77 CVE-2021-33515: The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensi
The submission service in Dovecot before 2.3.15 allows STARTTLS command injection in lib-smtp. Sensitive information can be redirected to an attacker-controlled address.
nvd
CVE-2020-35480P4MEDIUMCVSS 5.3v332020-12-18
CVE-2020-35480 [MEDIUM] CWE-203 CVE-2020-35480: An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hi
An issue was discovered in MediaWiki before 1.35.1. Missing users (accounts that don't exist) and hidden users (accounts that have been explicitly hidden due to being abusive, or similar) that the viewer cannot see are handled differently, exposing sensitive information about the hidden status to unprivileged viewers. This exists on various code pat
nvd