Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 192 of 264
CVE-2015-0295P4MEDIUMCVSS 5.0v20v21+1 more2015-03-25
CVE-2015-0295 [MEDIUM] CWE-189 CVE-2015-0295: The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the
The BMP decoder in QtGui in QT before 5.5 does not properly calculate the masks used to extract the color components, which allows remote attackers to cause a denial of service (divide-by-zero and crash) via a crafted BMP file.
nvd
CVE-2022-0518P4HIGHCVSS 7.1v35v362022-02-08
CVE-2022-0518 [HIGH] CWE-122 CVE-2022-0518: Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.
nvd
CVE-2022-21673P4MEDIUMCVSS 4.3v34v35+1 more2022-01-18
CVE-2022-21673 [MEDIUM] CWE-200 CVE-2022-21673: Grafana is an open-source platform for monitoring and observability. In affected versions when a dat
Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of the most recently logged-in user. This can allow API token holders to retr
nvd
CVE-2022-0713P4HIGHCVSS 7.1v35v362022-02-22
CVE-2022-0713 [HIGH] CWE-122 CVE-2022-0713: Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.
nvd
CVE-2022-0522P4HIGHCVSS 7.1v35v362022-02-08
CVE-2022-0522 [HIGH] CWE-786 CVE-2022-0522: Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.
Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.
nvd
CVE-2022-0519P4HIGHCVSS 7.1v35v362022-02-08
CVE-2022-0519 [HIGH] CWE-805 CVE-2022-0519: Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.
nvd
CVE-2007-5191P4HIGHCVSS 7.2v72007-10-04
CVE-2007-5191 [HIGH] CWE-252 CVE-2007-5191: mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong
mount and umount in util-linux and loop-aes-utils call the setuid and setgid functions in the wrong order and do not check the return values, which might allow attackers to gain privileges via helpers such as mount.nfs.
nvd
CVE-2022-28041P4MEDIUMCVSS 6.5v34v35+1 more2022-04-15
CVE-2022-28041 [MEDIUM] CWE-190 CVE-2022-28041: stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_b
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
nvd
CVE-2022-40313P4HIGHCVSS 7.1v35v362022-09-30
CVE-2022-40313 [HIGH] CWE-79 CVE-2022-40313: Recursive rendering of Mustache template helpers containing user input could, in some cases, result
Recursive rendering of Mustache template helpers containing user input could, in some cases, result in an XSS risk or a page failing to load.
nvd
CVE-2019-13110P4MEDIUMCVSS 6.5v302019-06-30
CVE-2019-13110 [MEDIUM] CWE-125 CVE-2019-13110: A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allow
A CiffDirectory::readDirectory integer overflow and out-of-bounds read in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted CRW image file.
nvd
CVE-2021-0002P4HIGHCVSS 7.1v33v34+1 more2021-08-11
CVE-2021-0002 [HIGH] CWE-754 CVE-2021-0002: Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before vers
Improper conditions check in some Intel(R) Ethernet Controllers 800 series Linux drivers before version 1.4.11 may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
nvd
CVE-2019-15531P4MEDIUMCVSS 6.5v29v30+1 more2019-08-23
CVE-2019-15531 [MEDIUM] CWE-125 CVE-2019-15531: GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract
GNU Libextractor through 1.9 has a heap-based buffer over-read in the function EXTRACTOR_dvi_extract_method in plugins/dvi_extractor.c.
nvd
CVE-2021-32436P4MEDIUMCVSS 6.5v34v35+1 more2022-03-10
CVE-2021-32436 [MEDIUM] CWE-125 CVE-2021-32436: An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote atta
An out-of-bounds read in the function write_title() in subs.c of abcm2ps v8.14.11 allows remote attackers to cause a Denial of Service (DoS) via unspecified vectors.
nvd
CVE-2019-13109P4MEDIUMCVSS 6.5v302019-06-30
CVE-2019-13109 [MEDIUM] CWE-190 CVE-2019-13109: An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV
An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a chunkLength - iccOffset subtraction.
nvd
CVE-2014-8738P4MEDIUMCVSS 5.0v20v212015-01-15
CVE-2014-8738 [MEDIUM] CWE-119 CVE-2014-8738: The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows
The _bfd_slurp_extended_name_table function in bfd/archive.c in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (invalid write, segmentation fault, and crash) via a crafted extended name table in an archive.
nvd
CVE-2024-25081P4MEDIUMCVSS 4.2v402024-02-26
CVE-2024-25081 [MEDIUM] CWE-77 CVE-2024-25081: Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
nvd
CVE-2014-8484P4MEDIUMCVSS 5.0v19v20+1 more2014-12-09
CVE-2014-8484 [MEDIUM] CWE-119 CVE-2014-8484: The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers
The srec_scan function in bfd/srec.c in libdbfd in GNU binutils before 2.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a small S-record.
nvd
CVE-2020-24455P4MEDIUMCVSS 6.7v342021-02-26
CVE-2020-24455 [MEDIUM] CWE-909 CVE-2020-24455: Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially e
Missing initialization of a variable in the TPM2 source may allow a privileged user to potentially enable an escalation of privilege via local access. This affects tpm2-tss before 3.0.1 and before 2.4.3.
nvd
CVE-2015-8807P4MEDIUMCVSS 6.1v22v232016-04-13
CVE-2015-8807 [MEDIUM] CWE-79 CVE-2015-8807: Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/C
Cross-site scripting (XSS) vulnerability in the _renderVarInput_number function in horde/framework/Core/lib/Horde/Core/Ui/VarRenderer/Html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via vectors involving numeric form fields.
nvd
CVE-2016-4796P4MEDIUMCVSS 5.5v23v242017-02-03
CVE-2016-4796 [MEDIUM] CWE-119 CVE-2016-4796: Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allow
Heap-based buffer overflow in the color_cmyk_to_rgb in common/color.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (crash) via a crafted .j2k file.
nvd