cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 191 of 264
CVE-2019-14905P4MEDIUMCVSS 5.6v302020-03-31
CVE-2019-14905 [MEDIUM] CWE-20 CVE-2019-14905: A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x b A vulnerability was found in Ansible Engine versions 2.9.x before 2.9.3, 2.8.x before 2.8.8, 2.7.x before 2.7.16 and earlier, where in Ansible's nxos_file_copy module can be used to copy files to a flash or bootflash on NXOS devices. Malicious code could craft the filename parameter to perform OS command injections. This could result in a loss of con
nvd
CVE-2021-32808P4MEDIUMCVSS 5.4v33v34+1 more2021-08-12
CVE-2021-32808 [MEDIUM] CWE-79 CVE-2021-32808: ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been d ckeditor is an open source WYSIWYG HTML editor with rich content support. A vulnerability has been discovered in the clipboard Widget plugin if used alongside the undo feature. The vulnerability allows a user to abuse undo functionality using malformed widget HTML, which could result in executing JavaScript code. It affects all users using the CKEdit
nvd
CVE-2023-6918P4MEDIUMCVSS 5.3v38v392023-12-19
CVE-2023-6918 [MEDIUM] CWE-252 CVE-2023-6918: A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemen A flaw was found in the libssh implements abstract layer for message digest (MD) operations implemented by different supported crypto backends. The return values from these were not properly checked, which could cause low-memory situations failures, NULL dereferences, crashes, or usage of the uninitialized memory as an input for the KDF. In this case,
nvd
CVE-2021-41190P4MEDIUMCVSS 5.0v34v352021-11-17
CVE-2021-41190 [MEDIUM] CWE-843 CVE-2021-41190: The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribu The OCI Distribution Spec project defines an API protocol to facilitate and standardize the distribution of content. In the OCI Distribution Specification version 1.0.0 and prior, the Content-Type header alone was used to determine the type of document during push and pull operations. Documents that contain both “manifests” and “layers” fields could
nvd
CVE-2014-9527P4MEDIUMCVSS 5.0v202015-01-06
CVE-2014-9527 [MEDIUM] CWE-399 CVE-2014-9527: HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infini HSLFSlideShow in Apache POI before 3.11 allows remote attackers to cause a denial of service (infinite loop and deadlock) via a crafted PPT file.
nvd
CVE-2020-8624P4MEDIUMCVSS 4.3v31v322020-08-21
CVE-2020-8624 [MEDIUM] CWE-269 CVE-2020-8624: In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, a In BIND 9.9.12 -> 9.9.13, 9.10.7 -> 9.10.8, 9.11.3 -> 9.11.21, 9.12.1 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.12-S1 -> 9.9.13-S1, 9.11.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker who has been granted privileges to change a specific subset of the zone's content could abuse these unintended additional privileges to upda
nvd
CVE-2020-1753P4MEDIUMCVSS 5.5v30v31+1 more2020-03-16
CVE-2020-1753 [MEDIUM] CWE-200 CVE-2020-1753: A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible A security flaw was found in Ansible Engine, all Ansible 2.7.x versions prior to 2.7.17, all Ansible 2.8.x versions prior to 2.8.11 and all Ansible 2.9.x versions prior to 2.9.7, when managing kubernetes using the k8s module. Sensitive parameters such as passwords and tokens are passed to kubectl from the command line, not using an environment variabl
nvd
CVE-2021-43560P4MEDIUMCVSS 5.3v352021-11-22
CVE-2021-43560 [MEDIUM] CWE-863 CVE-2021-43560: A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier uns A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.
nvd
CVE-2023-43796P4MEDIUMCVSS 5.3v38v392023-10-31
CVE-2023-43796 [MEDIUM] CWE-200 CVE-2023-43796: Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device in Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to Synapse 1.95.1 or 1.96.0rc1 to receive a patch. As a workaround, the `feder
nvd
CVE-2024-34161P4MEDIUMCVSS 5.3v39v402024-05-29
CVE-2024-34161 [MEDIUM] CWE-416 CVE-2024-34161: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastruc When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module and the network infrastructure supports a Maximum Transmission Unit (MTU) of 4096 or greater without fragmentation, undisclosed QUIC packets can cause NGINX worker processes to leak previously freed memory.
nvd
CVE-2011-2691P4MEDIUMCVSS 6.5v142011-07-17
CVE-2011-2691 [MEDIUM] CWE-476 CVE-2011-2691: The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before The png_err function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 makes a function call using a NULL pointer argument instead of an empty-string argument, which allows remote attackers to cause a denial of service (application crash) via a crafted PNG image.
nvd
CVE-2021-20178P4MEDIUMCVSS 5.5v32v332021-05-26
CVE-2021-20178 [MEDIUM] CWE-532 CVE-2021-20178: A flaw was found in ansible module where credentials are disclosed in the console log by default and A flaw was found in ansible module where credentials are disclosed in the console log by default and not protected by the security feature when using the bitbucket_pipeline_variable module. This flaw allows an attacker to steal bitbucket_pipeline credentials. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2026-35094P4MEDIUMCVSS 5.5v43v442026-04-01
CVE-2026-35094 [MEDIUM] CWE-825 CVE-2026-35094: A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system logs. This could potentially expose sensitive data if the memory location i
nvd
CVE-2011-2192P4MEDIUMCVSS 4.3v14v152011-07-07
CVE-2011-2192 [MEDIUM] CWE-255 CVE-2011-2192: The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in c The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.
nvd
CVE-2014-9092P4MEDIUMCVSS 6.5v20v212017-10-10
CVE-2014-9092 [MEDIUM] CWE-119 CVE-2014-9092: libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafte libjpeg-turbo before 1.3.1 allows remote attackers to cause a denial of service (crash) via a crafted JPEG file, related to the Exif marker.
nvd
CVE-2007-3847P4MEDIUMCVSS 5.0v72007-08-23
CVE-2007-3847 [MEDIUM] CWE-125 CVE-2007-3847: The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threa The date handling code in modules/proxy/proxy_util.c (mod_proxy) in Apache 2.3.0, when using a threaded MPM, allows remote origin servers to cause a denial of service (caching forward proxy process crash) via crafted date headers that trigger a buffer over-read.
nvd
CVE-2019-0197P4MEDIUMCVSS 4.2v302019-06-11
CVE-2019-0197 [MEDIUM] CWE-444 CVE-2019-0197: A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http A vulnerability was found in Apache HTTP Server 2.4.34 to 2.4.38. When HTTP/2 was enabled for a http: host or H2Upgrade was enabled for h2 on a https: host, an Upgrade request from http/1.1 to http/2 that was not the first request on a connection could lead to a misconfiguration and crash. Server that never enabled the h2 protocol or that only enabled
nvd
CVE-2008-2364P4MEDIUMCVSS 5.0v8v92008-06-13
CVE-2008-2364 [MEDIUM] CWE-770 CVE-2008-2364: The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apach The ap_proxy_http_process_response function in mod_proxy_http.c in the mod_proxy module in the Apache HTTP Server 2.0.63 and 2.2.8 does not limit the number of forwarded interim responses, which allows remote HTTP servers to cause a denial of service (memory consumption) via a large number of interim responses.
nvd
CVE-2015-7216P4MEDIUMCVSS 6.8v22v232015-12-16
CVE-2015-7216 [MEDIUM] CWE-20 CVE-2015-7216: The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly ena The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 image.
nvd
CVE-2021-26926P4HIGHCVSS 7.1v32v33+1 more2021-02-23
CVE-2021-26926 [HIGH] CWE-125 CVE-2021-26926: A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode functi A flaw was found in jasper before 2.0.25. An out of bounds read issue was found in jp2_decode function whic may lead to disclosure of information or program crash.
nvd
Fedoraproject Fedora vulnerabilities | cvebase