cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 193 of 264
CVE-2021-34338P4MEDIUMCVSS 6.5v352022-03-10
CVE-2021-34338 [MEDIUM] CWE-125 CVE-2021-34338: Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c fil Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
nvd
CVE-2022-32325P4MEDIUMCVSS 6.5v372022-07-01
CVE-2022-32325 [MEDIUM] CWE-125 CVE-2022-32325: JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c.
nvd
CVE-2016-2228P4MEDIUMCVSS 6.1v22v232016-04-13
CVE-2016-2228 [MEDIUM] CWE-79 CVE-2016-2228: Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupw Cross-site scripting (XSS) vulnerability in horde/templates/topbar/_menubar.html.php in Horde Groupware before 5.2.12 and Horde Groupware Webmail Edition before 5.2.12 allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter, as demonstrated by a request to xplorer/gollem/manager.php.
nvd
CVE-2020-13231P4MEDIUMCVSS 6.5v31v322020-05-20
CVE-2020-13231 [MEDIUM] CWE-352 CVE-2020-13231: In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change. In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
nvd
CVE-2021-27906P4MEDIUMCVSS 5.5v32v33+1 more2021-03-19
CVE-2021-27906 [MEDIUM] CWE-789 CVE-2021-27906: A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2022-41804P4MEDIUMCVSS 6.7v382023-08-11
CVE-2022-41804 [MEDIUM] CWE-1334 CVE-2022-41804: Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors ma Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2015-2793P4MEDIUMCVSS 6.1v20v21+1 more2019-11-21
CVE-2015-2793 [MEDIUM] CWE-79 CVE-2015-2793: Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150 Cross-site scripting (XSS) vulnerability in templates/openid-selector.tmpl in ikiwiki before 3.20150329 allows remote attackers to inject arbitrary web script or HTML via the openid_identifier parameter in a verify action to ikiwiki.cgi.
nvd
CVE-2021-40403P4MEDIUMCVSS 6.3v362022-02-04
CVE-2021-40403 [MEDIUM] CWE-456 CVE-2021-40403: An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerabil
nvd
CVE-2012-1114P4MEDIUMCVSS 6.1v16v17+1 more2019-12-05
CVE-2012-1114 [MEDIUM] CWE-79 CVE-2012-1114: A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filte A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the filter parameter to cmd.php in an export and exporter_id action. and the filteruid parameter to list.php.
nvd
CVE-2012-1115P4MEDIUMCVSS 6.1v16v17+1 more2019-12-05
CVE-2012-1115 [MEDIUM] CWE-79 CVE-2012-1115: A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the expor A Cross-Site Scripting (XSS) vulnerability exists in LDAP Account Manager (LAM) Pro 3.6 in the export, add_value_form, and dn parameters to cmd.php.
nvd
CVE-2021-31812P4MEDIUMCVSS 5.5v33v342021-06-12
CVE-2021-31812 [MEDIUM] CWE-834 CVE-2021-31812: In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. In Apache PDFBox, a carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.23 and prior 2.0.x versions.
nvd
CVE-2024-0607P4MEDIUMCVSS 6.6v392024-01-18
CVE-2024-0607 [MEDIUM] CWE-229 CVE-2024-0607: A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_e A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each iteration, 8 bytes are written, but `dst` is an array of u32, so each element only has space for 4 bytes. That means every iteration overwrites part of the pre
nvd
CVE-2021-27807P4MEDIUMCVSS 5.5v32v33+1 more2021-03-19
CVE-2021-27807 [MEDIUM] CWE-834 CVE-2021-27807: A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
nvd
CVE-2020-13529P4MEDIUMCVSS 6.1v332021-05-10
CVE-2020-13529 [MEDIUM] CWE-290 CVE-2020-13529: An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCE An exploitable denial-of-service vulnerability exists in Systemd 245. A specially crafted DHCP FORCERENEW packet can cause a server running the DHCP client to be vulnerable to a DHCP ACK spoofing attack. An attacker can forge a pair of FORCERENEW and DCHP ACK packets to reconfigure the server.
nvd
CVE-2022-4172P4MEDIUMCVSS 6.5v372022-11-29
CVE-2022-4172 [MEDIUM] CWE-120 CVE-2022-4172: An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Tab An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory device. A malicious guest could use these flaws to crash the QEMU process on t
nvd
CVE-2019-19547P4MEDIUMCVSS 6.1v30v312020-01-13
CVE-2019-19547 [MEDIUM] CWE-79 CVE-2019-19547: Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site Symantec Endpoint Detection and Response (SEDR), prior to 4.3.0, may be susceptible to a cross site scripting (XSS) issue. XSS is a type of issue that can enable attackers to inject client-side scripts into web pages viewed by other users. An XSS vulnerability may be used by attackers to potentially bypass access controls such as the same-origin polic
nvd
CVE-2020-29483P4MEDIUMCVSS 6.5v32v332020-12-15
CVE-2020-29483 [MEDIUM] CWE-416 CVE-2020-29483: An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory An issue was discovered in Xen through 4.14.x. Xenstored and guests communicate via a shared memory page using a specific protocol. When a guest violates this protocol, xenstored will drop the connection to that guest. Unfortunately, this is done by just removing the guest from xenstored's internal management, resulting in the same actions as if the
nvd
CVE-2020-6535P4MEDIUMCVSS 6.1v31v322020-07-22
CVE-2020-6535 [MEDIUM] CWE-79 CVE-2020-6535: Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attack Insufficient data validation in WebUI in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had compromised the renderer process to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd
CVE-2020-25814P4MEDIUMCVSS 6.1v332020-09-27
CVE-2020-25814 [MEDIUM] CWE-79 CVE-2020-25814: In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an tag (or it does not have a href attribute, or it's empty, etc.
nvd
CVE-2021-28652P4MEDIUMCVSS 4.9v33v342021-05-27
CVE-2021-28652 [MEDIUM] CWE-401 CVE-2021-28652: An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validatio An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to incorrect parser validation, it allows a Denial of Service attack against the Cache Manager API. This allows a trusted client to trigger memory leaks that. over time, lead to a Denial of Service via an unspecified short query string. This attack is limited to clients with Cach
nvd
Fedoraproject Fedora vulnerabilities | cvebase