cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 198 of 264
CVE-2019-13113P4MEDIUMCVSS 6.5v302019-06-30
CVE-2019-13113 [MEDIUM] CWE-617 CVE-2019-13113: Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to assertion failure) via an invalid data location in a CRW image file.
nvd
CVE-2019-9211P4MEDIUMCVSS 6.5v292019-02-27
CVE-2019-9211 [MEDIUM] CWE-617 CVE-2019-9211: There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys- There is a reachable assertion abort in the function write_long_string_missing_values() in data/sys-file-writer.c in libdata.a in GNU PSPP 1.2.0 that will lead to denial of service.
nvd
CVE-2022-48303P4MEDIUMCVSS 5.5v37v382023-01-30
CVE-2022-48303 [MEDIUM] CWE-125 CVE-2022-48303: GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory f GNU Tar through 1.34 has a one-byte out-of-bounds read that results in use of uninitialized memory for a conditional jump. Exploitation to change the flow of control has not been demonstrated. The issue occurs in from_header in list.c via a V7 archive in which mtime has approximately 11 whitespace characters.
nvd
CVE-2019-13112P4MEDIUMCVSS 6.5v302019-06-30
CVE-2019-13112 [MEDIUM] CWE-770 CVE-2019-13112: A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attac A PngChunk::parseChunkContent uncontrolled memory allocation in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (crash due to an std::bad_alloc exception) via a crafted PNG image file.
nvd
CVE-2019-16707P4MEDIUMCVSS 6.5v30v312019-09-23
CVE-2019-16707 [MEDIUM] CWE-119 CVE-2019-16707: Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx. Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx.
nvd
CVE-2022-27337P4MEDIUMCVSS 6.5v362022-05-05
CVE-2022-27337 [MEDIUM] CVE-2022-27337: A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of A logic error in the Hints::Hints function of Poppler v22.03.0 allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
nvd
CVE-2018-11797P4MEDIUMCVSS 5.5v29v302018-10-05
CVE-2018-11797 [MEDIUM] CVE-2018-11797: In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an In Apache PDFBox 1.8.0 to 1.8.15 and 2.0.0RC1 to 2.0.11, a carefully crafted PDF file can trigger an extremely long running computation when parsing the page tree.
nvd
CVE-2019-13108P4MEDIUMCVSS 6.5v302019-06-30
CVE-2019-13108 [MEDIUM] CWE-190 CVE-2019-13108: An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV An integer overflow in Exiv2 through 0.27.1 allows an attacker to cause a denial of service (SIGSEGV) via a crafted PNG image file, because PngImage::readMetadata mishandles a zero value for iccOffset.
nvd
CVE-2013-1931P4MEDIUMCVSS 6.1v17v182019-10-31
CVE-2013-1931 [MEDIUM] CWE-79 CVE-2013-1931: A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbi A cross-site scripting (XSS) vulnerability in MantisBT 1.2.14 allows remote attackers to inject arbitrary web script or HTML via a version, related to deleting a version.
nvd
CVE-2017-16876P4MEDIUMCVSS 6.1v262017-12-29
CVE-2017-16876 [MEDIUM] CWE-79 CVE-2017-16876: Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8 Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.
nvd
CVE-2008-3222P4MEDIUMCVSS 5.8v8v92008-07-18
CVE-2008-3222 [MEDIUM] CWE-384 CVE-2008-3222: Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors.
nvd
CVE-2021-28694P4MEDIUMCVSS 6.8v33v34+1 more2021-08-27
CVE-2021-28694 [MEDIUM] CVE-2021-28694: IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text exp IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these a
nvd
CVE-2021-28695P4MEDIUMCVSS 6.8v33v34+1 more2021-08-27
CVE-2021-28695 [MEDIUM] CVE-2021-28695: IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text exp IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these a
nvd
CVE-2022-3048P4MEDIUMCVSS 6.8v372022-09-26
CVE-2022-3048 [MEDIUM] CWE-863 CVE-2022-3048: Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.51 Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
nvd
CVE-2021-28696P4MEDIUMCVSS 6.8v33v34+1 more2021-08-27
CVE-2021-28696 [MEDIUM] CVE-2021-28696: IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text exp IOMMU page mapping issues on x86 T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Both AMD and Intel allow ACPI tables to specify regions of memory which should be left untranslated, which typically means these addresses should pass the translation phase unaltered. While these a
nvd
CVE-2021-3826P4MEDIUMCVSS 6.5v35v36+1 more2022-09-01
CVE-2021-3826 [MEDIUM] CWE-119 CVE-2021-3826: Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol.
nvd
CVE-2021-34341P4MEDIUMCVSS 6.5v352022-03-10
CVE-2021-34341 [MEDIUM] CWE-125 CVE-2021-34341: Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation fault and leads to denial of service.
nvd
CVE-2019-20479P4MEDIUMCVSS 6.1v31v322020-02-20
CVE-2019-20479 [MEDIUM] CWE-601 CVE-2019-20479: A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs wit A flaw was found in mod_auth_openidc before version 2.4.1. An open redirect issue exists in URLs with a slash and backslash at the beginning.
nvd
CVE-2022-23825P4MEDIUMCVSS 6.5v35v362022-07-14
CVE-2022-23825 [MEDIUM] CWE-668 CVE-2022-23825: Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type poten Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
nvd
CVE-2022-46329P4MEDIUMCVSS 6.7v37v38+1 more2023-08-11
CVE-2022-46329 [MEDIUM] CWE-693 CVE-2022-46329: Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
Fedoraproject Fedora vulnerabilities | cvebase