Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 199 of 264
CVE-2022-27635P4MEDIUMCVSS 6.7v37v38+1 more2023-08-11
CVE-2022-27635 [MEDIUM] CWE-284 CVE-2022-27635: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allo
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2022-40964P4MEDIUMCVSS 6.7v37v38+1 more2023-08-11
CVE-2022-40964 [MEDIUM] CWE-284 CVE-2022-40964: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allo
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2020-6802P4MEDIUMCVSS 6.1v30v31+1 more2020-03-24
CVE-2020-6802 [MEDIUM] CWE-79 CVE-2020-6802: In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a
In Mozilla Bleach before 3.11, a mutation XSS affects users calling bleach.clean with noscript and a raw tag in the allowed/whitelisted tags option.
nvd
CVE-2015-4645P4MEDIUMCVSS 5.5v21v222017-03-17
CVE-2015-4645 [MEDIUM] CWE-190 CVE-2015-4645: Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch all
Integer overflow in the read_fragment_table_4 function in unsquash-4.c in Squashfs and sasquatch allows remote attackers to cause a denial of service (application crash) via a crafted input, which triggers a stack-based buffer overflow.
nvd
CVE-2021-2166P4MEDIUMCVSS 4.9v32v33+1 more2021-04-22
CVE-2021-2166 [MEDIUM] CVE-2021-2166: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2016-1926P4MEDIUMCVSS 6.1v22v232016-01-26
CVE-2016-1926 [MEDIUM] CWE-79 CVE-2016-1926: Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA)
Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a get_aggregate command to omp.
nvd
CVE-2022-36351P4MEDIUMCVSS 6.5v37v38+1 more2023-08-11
CVE-2022-36351 [MEDIUM] CWE-20 CVE-2022-36351: Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may all
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access.
nvd
CVE-2016-0725P4MEDIUMCVSS 6.1v22v232016-02-22
CVE-2016-0725 [MEDIUM] CWE-79 CVE-2016-0725: Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/managem
Cross-site scripting (XSS) vulnerability in the search_pagination function in course/classes/management_renderer.php in Moodle 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted search string.
nvd
CVE-2020-35479P4MEDIUMCVSS 6.1v332020-12-18
CVE-2020-35479 [MEDIUM] CWE-79 CVE-2020-35479: MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself
MediaWiki before 1.35.1 allows XSS via BlockLogFormatter.php. Language::translateBlockExpiry itself does not escape in all code paths. For example, the return of Language::userTimeAndDate is is always unsafe for HTML in a month value. This affects MediaWiki 1.12.0 and later.
nvd
CVE-2021-3638P4MEDIUMCVSS 6.5v36v372022-03-03
CVE-2021-3638 [MEDIUM] CWE-787 CVE-2021-3638: An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occ
An out-of-bounds memory access flaw was found in the ATI VGA device emulation of QEMU. This flaw occurs in the ati_2d_blt() routine while handling MMIO write operations when the guest provides invalid values for the destination display parameters. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of ser
nvd
CVE-2021-23648P4MEDIUMCVSS 6.1v34v35+1 more2022-03-16
CVE-2021-23648 [MEDIUM] CWE-79 CVE-2021-23648: The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to
The package @braintree/sanitize-url before 6.0.0 are vulnerable to Cross-site Scripting (XSS) due to improper sanitization in sanitizeUrl function.
nvd
CVE-2020-15563P4MEDIUMCVSS 6.5v31v322020-07-07
CVE-2020-15563 [MEDIUM] CWE-119 CVE-2020-15563: An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor
An issue was discovered in Xen through 4.13.x, allowing x86 HVM guest OS users to cause a hypervisor crash. An inverted conditional in x86 HVM guests' dirty video RAM tracking code allows such guests to make Xen de-reference a pointer guaranteed to point at unmapped space. A malicious or buggy HVM guest may cause the hypervisor to crash, resulting i
nvd
CVE-2021-30157P4MEDIUMCVSS 6.1v33v342021-04-06
CVE-2021-30157 [MEDIUM] CWE-79 CVE-2021-30157: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Chan
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On ChangesList special pages such as Special:RecentChanges and Special:Watchlist, some of the rcfilters-filter-* label messages are output in HTML unescaped, leading to XSS.
nvd
CVE-2021-20257P4MEDIUMCVSS 6.5v332022-03-16
CVE-2021-20257 [MEDIUM] CWE-835 CVE-2021-20257: An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while proce
An infinite loop flaw was found in the e1000 NIC emulator of the QEMU. This issue occurs while processing transmits (tx) descriptors in process_tx_desc if various descriptor fields are initialized with invalid values. This flaw allows a guest to consume CPU cycles on the host, resulting in a denial of service. The highest threat from this vulnerabil
nvd
CVE-2021-30154P4MEDIUMCVSS 6.1v33v342021-04-06
CVE-2021-30154 [MEDIUM] CWE-79 CVE-2021-30154: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Spec
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. On Special:NewFiles, all the mediastatistics-header-* messages are output in HTML unescaped, leading to XSS.
nvd
CVE-2021-3941P4MEDIUMCVSS 6.5v34v35+1 more2022-03-25
CVE-2021-3941 [MEDIUM] CWE-369 CVE-2021-3941: In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (
In ImfChromaticities.cpp routine RGBtoXYZ(), there are some division operations such as `float Z = (1 - chroma.white.x - chroma.white.y) * Y / chroma.white.y;` and `chroma.green.y * (X + Z))) / d;` but the divisor is not checked for a 0 value. A specially crafted file could trigger a divide-by-zero condition which could affect the availability of prog
nvd
CVE-2022-42321P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42321 [MEDIUM] CWE-674 CVE-2022-42321: Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some
Xenstore: Guests can crash xenstored via exhausting the stack Xenstored is using recursion for some Xenstore operations (e.g. for deleting a sub-tree of Xenstore nodes). With sufficiently deep nesting levels this can result in stack exhaustion on xenstored, leading to a crash of xenstored.
nvd
CVE-2022-42319P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42319 [MEDIUM] CWE-401 CVE-2022-42319: Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a gues
Xenstore: Guests can cause Xenstore to not free temporary memory When working on a request of a guest, xenstored might need to allocate quite large amounts of memory temporarily. This memory is freed only after the request has been finished completely. A request is regarded to be finished only after the guest has read the response message of the req
nvd
CVE-2023-3180P4MEDIUMCVSS 6.5v382023-08-03
CVE-2023-3180 [MEDIUM] CWE-122 CVE-2023-3180: A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption request
A flaw was found in the QEMU virtual crypto device while handling data encryption/decryption requests in virtio_crypto_handle_sym_req. There is no check for the value of `src_len` and `dst_len` in virtio_crypto_sym_op_helper, potentially leading to a heap buffer overflow when the two values differ.
nvd
CVE-2020-25815P4MEDIUMCVSS 6.1v332020-09-27
CVE-2020-25815 [MEDIUM] CWE-79 CVE-2020-25815: An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDe
An issue was discovered in MediaWiki 1.32.x through 1.34.x before 1.34.4. LogEventList::getFiltersDesc is insecurely using message text to build options names for an HTML multi-select field. The relevant code should use escaped() instead of text().
nvd