cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 194 of 264
CVE-2022-0571P4MEDIUMCVSS 6.1v34v35+1 more2022-02-14
CVE-2022-0571 [MEDIUM] CWE-79 CVE-2022-0571: Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.
nvd
CVE-2023-46841P4MEDIUMCVSS 6.5v402024-03-20
CVE-2023-46841 [MEDIUM] CVE-2023-46841: Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature Recent x86 CPUs offer functionality named Control-flow Enforcement Technology (CET). A sub-feature of this are Shadow Stacks (CET-SS). CET-SS is a hardware feature designed to protect against Return Oriented Programming attacks. When enabled, traditional stacks holding both data and return addresses are accompanied by so called "shadow stacks", holding little
nvd
CVE-2015-5295P4MEDIUMCVSS 5.4v232016-01-20
CVE-2015-5295 [MEDIUM] CWE-119 CVE-2015-5295: The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
nvd
CVE-2013-0211P4MEDIUMCVSS 5.0v17v182013-09-30
CVE-2013-0211 [MEDIUM] CWE-189 CVE-2013-0211: Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in Integer signedness error in the archive_write_zip_data function in archive_write_set_format_zip.c in libarchive 3.1.2 and earlier, when running on 64-bit machines, allows context-dependent attackers to cause a denial of service (crash) via unspecified vectors, which triggers an improper conversion between unsigned and signed types, leading to a buffer
nvd
CVE-2023-5480P4MEDIUMCVSS 6.1v37v38+1 more2023-11-01
CVE-2023-5480 [MEDIUM] CWE-79 CVE-2023-5480: Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote a Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)
nvd
CVE-2018-12130P4MEDIUMCVSS 5.9v292019-05-30
CVE-2018-12130 [MEDIUM] CWE-200 CVE-2018-12130: Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corpo
nvd
CVE-2015-0381P4MEDIUMCVSS 4.3v202015-01-21
CVE-2015-0381 [MEDIUM] CVE-2015-0381: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote attackers to affect availability via unknown vectors related to Server : Replication, a different vulnerability than CVE-2015-0382.
nvd
CVE-2022-27920P4MEDIUMCVSS 6.1v352022-03-25
CVE-2022-27920 [MEDIUM] CWE-79 CVE-2022-27920: libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggest libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.
nvd
CVE-2012-5630P4MEDIUMCVSS 6.3v182019-11-25
CVE-2012-5630 [MEDIUM] CWE-367 CVE-2012-5630: libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and remov libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
nvd
CVE-2024-3841P4MEDIUMCVSS 6.1v38v39+1 more2024-04-17
CVE-2024-3841 [MEDIUM] CWE-79 CVE-2024-3841: Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a r Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)
nvd
CVE-2020-26421P4MEDIUMCVSS 5.3v32v332020-12-11
CVE-2020-26421 [MEDIUM] CWE-125 CVE-2020-26421: Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3. Crash in USB HID protocol dissector and possibly other dissectors in Wireshark 3.4.0 and 3.2.0 to 3.2.8 allows denial of service via packet injection or crafted capture file.
nvd
CVE-2019-19722P4MEDIUMCVSS 5.3v30v312019-12-13
CVE-2019-19722 [MEDIUM] CWE-476 CVE-2019-19722: In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email whe In Dovecot before 2.3.9.2, an attacker can crash a push-notification driver with a crafted email when push notifications are used, because of a NULL Pointer Dereference. The email must use a group address as either the sender or the recipient.
nvd
CVE-2021-39272P4MEDIUMCVSS 5.9v33v34+1 more2021-08-30
CVE-2021-39272 [MEDIUM] CWE-319 CVE-2021-39272: Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as Fetchmail before 6.4.22 fails to enforce STARTTLS session encryption in some circumstances, such as a certain situation with IMAP and PREAUTH.
nvd
CVE-2021-3623P4MEDIUMCVSS 6.1v342022-03-02
CVE-2021-3623 [MEDIUM] CWE-787 CVE-2021-3623: A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets co A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this vulnerability is to system availability.
nvd
CVE-2020-2752P4MEDIUMCVSS 5.3v31v322020-04-15
CVE-2020-2752 [MEDIUM] CVE-2020-2752: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can res
nvd
CVE-2021-3622P4MEDIUMCVSS 4.3v33v342021-12-23
CVE-2021-3622 [MEDIUM] CWE-400 CVE-2021-3622: A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Win A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to system availability.
nvd
CVE-2021-45942P4MEDIUMCVSS 5.5v34v35+1 more2022-01-01
CVE-2021-45942 [MEDIUM] CWE-787 CVE-2021-45942: OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute ( OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
nvd
CVE-2020-14367P4MEDIUMCVSS 6.0v322020-08-24
CVE-2020-14367 [MEDIUM] CWE-59 CVE-2020-14367: A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chron A flaw was found in chrony versions before 3.5.1 when creating the PID file under the /var/run/chrony folder. The file is created during chronyd startup while still running as the root user, and when it's opened for writing, chronyd does not check for an existing symbolic link with the same file name. This flaw allows an attacker with privileged acce
nvd
CVE-2020-14550P4MEDIUMCVSS 5.3v31v32+1 more2020-07-15
CVE-2020-14550 [MEDIUM] CVE-2020-14550: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can r
nvd
CVE-2023-39193P4MEDIUMCVSS 6.0v382023-10-09
CVE-2023-39193 [MEDIUM] CWE-125 CVE-2023-39193: A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate A flaw was found in the Netfilter subsystem in the Linux kernel. The sctp_mt_check did not validate the flag_count field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure.
nvd
Fedoraproject Fedora vulnerabilities | cvebase