Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 195 of 264
CVE-2023-39189P4MEDIUMCVSS 6.0v382023-10-09
CVE-2023-39189 [MEDIUM] CWE-125 CVE-2023-39189: A flaw was found in the Netfilter subsystem in the Linux kernel. The nfnl_osf_add_callback function
A flaw was found in the Netfilter subsystem in the Linux kernel. The nfnl_osf_add_callback function did not validate the user mode controlled opt_num field. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, leading to a crash or information disclosure.
nvd
CVE-2023-39192P4MEDIUMCVSS 6.0v382023-10-09
CVE-2023-39192 [MEDIUM] CWE-125 CVE-2023-39192: A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate
A flaw was found in the Netfilter subsystem in the Linux kernel. The xt_u32 module did not validate the fields in the xt_u32 structure. This flaw allows a local privileged attacker to trigger an out-of-bounds read by setting the size fields with a value beyond the array boundaries, leading to a crash or information disclosure.
nvd
CVE-2021-42780P4MEDIUMCVSS 5.3v332022-04-18
CVE-2021-42780 [MEDIUM] CWE-252 CVE-2021-42780: A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could
A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
nvd
CVE-2021-42778P4MEDIUMCVSS 5.3v332022-04-18
CVE-2021-42778 [MEDIUM] CWE-672 CVE-2021-42778: A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
nvd
CVE-2021-45958P4MEDIUMCVSS 5.5v35v36+1 more2022-01-01
CVE-2021-45958 [MEDIUM] CWE-787 CVE-2021-45958: UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecke
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
nvd
CVE-2022-21509P4MEDIUMCVSS 5.5v352022-07-19
CVE-2022-21509 [MEDIUM] CVE-2022-21509: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2022-24769P4MEDIUMCVSS 5.9v34v35+1 more2022-03-24
CVE-2022-24769 [MEDIUM] CWE-732 CVE-2022-24769: Moby is an open-source project created by Docker to enable and accelerate software containerization.
Moby is an open-source project created by Docker to enable and accelerate software containerization. A bug was found in Moby (Docker Engine) prior to version 20.10.14 where containers were incorrectly started with non-empty inheritable Linux process capabilities, creating an atypical Linux environment and enabling programs with inheritable file capa
nvd
CVE-2020-10700P4MEDIUMCVSS 5.3v30v31+1 more2020-05-04
CVE-2020-10700 [MEDIUM] CWE-416 CVE-2020-10700: A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control
A use-after-free flaw was found in the way samba AD DC LDAP servers, handled 'Paged Results' control is combined with the 'ASQ' control. A malicious user in a samba AD could use this flaw to cause denial of service. This issue affects all samba versions before 4.10.15, before 4.11.8 and before 4.12.2.
nvd
CVE-2022-21527P4MEDIUMCVSS 5.5v352022-07-19
CVE-2022-21527 [MEDIUM] CVE-2022-21527: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2020-14410P4MEDIUMCVSS 5.4v332021-01-19
CVE-2020-14410 [MEDIUM] CWE-125 CVE-2020-14410: SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4
SDL (Simple DirectMedia Layer) through 2.0.12 has a heap-based buffer over-read in Blit_3or4_to_3or4__inversed_rgb in video/SDL_blit_N.c via a crafted .BMP file.
nvd
CVE-2022-29869P4MEDIUMCVSS 5.3v34v35+1 more2022-04-28
CVE-2022-29869 [MEDIUM] CWE-532 CVE-2022-29869: cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains =
cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.
nvd
CVE-2021-2006P4MEDIUMCVSS 5.3v32v332021-01-20
CVE-2021-2006 [MEDIUM] CVE-2021-2006: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2015-7215P4MEDIUMCVSS 5.0v22v232015-12-16
CVE-2015-7215 [MEDIUM] CWE-200 CVE-2015-7215: The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allo
The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to information disclosure after a rethrow.
nvd
CVE-2023-21929P4MEDIUMCVSS 5.5v37v38+1 more2023-04-18
CVE-2023-21929 [MEDIUM] CVE-2023-21929: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versi
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to ca
nvd
CVE-2013-4550P4MEDIUMCVSS 5.1v18v19+1 more2013-12-24
CVE-2013-4550 [MEDIUM] CVE-2013-4550: Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descri
Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed, which allows remote attackers to write to other sockets and have an unspecified impact via a failed SSL handshake, a different vulnerability than CVE-2011-5268. NOTE: some sources or
nvd
CVE-2020-7042P4MEDIUMCVSS 5.3v30v31+1 more2020-02-27
CVE-2020-7042 [MEDIUM] CWE-295 CVE-2020-7042: An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c misha
An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL 1.0.2 or later. tunnel.c mishandles certificate validation because the hostname check operates on uninitialized memory. The outcome is that a valid certificate is never accepted (only a malformed certificate may be accepted).
nvd
CVE-2021-37695P4MEDIUMCVSS 5.4v33v34+1 more2021-08-13
CVE-2021-37695 [MEDIUM] CWE-79 CVE-2021-37695: ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could result in executing JavaScript code. It affects all users using the CKEdi
nvd
CVE-2021-29155P4MEDIUMCVSS 5.5v32v33+1 more2021-04-20
CVE-2021-29155 [MEDIUM] CWE-125 CVE-2021-29155: An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirab
An issue was discovered in the Linux kernel through 5.11.x. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory. Specifically, for sequences of pointer arithmetic operations, the pointer modifica
nvd
CVE-2021-28876P4MEDIUMCVSS 5.3v32v33+1 more2021-04-11
CVE-2021-28876 [MEDIUM] CWE-755 CVE-2021-28876: In the standard library in Rust before 1.52.0, the Zip implementation has a panic safety issue. It c
In the standard library in Rust before 1.52.0, the Zip implementation has a panic safety issue. It calls __iterator_get_unchecked() more than once for the same index when the underlying iterator panics (in certain conditions). This bug could lead to a memory safety violation due to an unmet safety requirement for the TrustedRandomAccess trait.
nvd
CVE-2022-21302P4MEDIUMCVSS 5.3v34v352022-01-19
CVE-2022-21302 [MEDIUM] CVE-2022-21302: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause
nvd