Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 201 of 264
CVE-2022-1355P4MEDIUMCVSS 6.1v34v35+1 more2022-08-31
CVE-2022-1355 [MEDIUM] CWE-121 CVE-2022-1355: A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
nvd
CVE-2023-5547P4MEDIUMCVSS 6.1v37v38+1 more2023-11-09
CVE-2023-5547 [MEDIUM] CWE-79 CVE-2023-5547: The course upload preview contained an XSS risk for users uploading unsafe data.
The course upload preview contained an XSS risk for users uploading unsafe data.
nvd
CVE-2024-38274P4MEDIUMCVSS 6.1v39v402024-06-18
CVE-2024-38274 [MEDIUM] CWE-79 CVE-2024-38274: Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion p
Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt.
nvd
CVE-2018-12127P4MEDIUMCVSS 5.6v292019-05-30
CVE-2018-12127 [MEDIUM] CWE-200 CVE-2018-12127: Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing spe
Microarchitectural Load Port Data Sampling (MLPDS): Load ports on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate
nvd
CVE-2018-12126P4MEDIUMCVSS 5.6v292019-05-30
CVE-2018-12126 [MEDIUM] CWE-200 CVE-2018-12126: Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizi
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/cor
nvd
CVE-2020-27843P4MEDIUMCVSS 5.5v32v332021-01-05
CVE-2020-27843 [MEDIUM] CWE-125 CVE-2020-27843: A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide spe
A flaw was found in OpenJPEG in versions prior to 2.4.0. This flaw allows an attacker to provide specially crafted input to the conversion or encoding functionality, causing an out-of-bounds read. The highest threat from this vulnerability is system availability.
nvd
CVE-2014-1491P4MEDIUMCVSS 4.3v19v202014-02-06
CVE-2014-1491 [MEDIUM] CWE-326 CVE-2014-1491: Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firef
Mozilla Network Security Services (NSS) before 3.15.4, as used in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, SeaMonkey before 2.24, and other products, does not properly restrict public values in Diffie-Hellman key exchanges, which makes it easier for remote attackers to bypass cryptographic protection mechanis
nvd
CVE-2022-24736P4MEDIUMCVSS 5.5v34v35+1 more2022-04-27
CVE-2022-24736 [MEDIUM] CWE-476 CVE-2022-24736: Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker
Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis versions 7.0.0 and 6.2.7. An additional workaround to mitigate this problem
nvd
CVE-2020-7957P4MEDIUMCVSS 5.3v30v312020-02-12
CVE-2020-7957 [MEDIUM] CWE-20 CVE-2020-7957: The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many
The IMAP and LMTP components in Dovecot 2.3.9 before 2.3.9.3 mishandle snippet generation when many characters must be read to compute the snippet and a trailing > character exists. This causes a denial of service in which the recipient cannot read all of their messages.
nvd
CVE-2012-1169P4MEDIUMCVSS 5.3v15v16+1 more2019-11-14
CVE-2012-1169 [MEDIUM] CWE-200 CVE-2012-1169: Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name disp
Moodle before 2.2.2 has Personal information disclosure, when administrative setting users name display is set to first name only full names are shown in page breadcrumbs.
nvd
CVE-2019-16738P4MEDIUMCVSS 5.3v30v312019-09-26
CVE-2019-16738 [MEDIUM] CWE-862 CVE-2019-16738: In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames
In MediaWiki through 1.33.0, Special:Redirect allows information disclosure of suppressed usernames via a User ID Lookup.
nvd
CVE-2020-11095P4MEDIUMCVSS 5.4v31v322020-06-22
CVE-2020-11095 [MEDIUM] CWE-125 CVE-2020-11095: In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory locati
In FreeRDP before version 2.1.2, an out of bound reads occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
nvd
CVE-2020-11097P4MEDIUMCVSS 5.4v31v322020-06-22
CVE-2020-11097 [MEDIUM] CWE-125 CVE-2020-11097: In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory locati
In FreeRDP before version 2.1.2, an out of bounds read occurs resulting in accessing a memory location that is outside of the boundaries of the static array PRIMARY_DRAWING_ORDER_FIELD_BYTES. This is fixed in version 2.1.2.
nvd
CVE-2020-35477P4MEDIUMCVSS 5.3v332020-12-18
CVE-2020-35477 [MEDIUM] CWE-670 CVE-2020-35477: MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one se
MediaWiki before 1.35.1 blocks legitimate attempts to hide log entries in some situations. If one sets MediaWiki:Mainpage to Special:MyLanguage/Main Page, visits a log entry on Special:Log, and toggles the "Change visibility of selected log entries" checkbox (or a tags checkbox) next to it, there is a redirection to the main page's action=historysub
nvd
CVE-2020-35132P4MEDIUMCVSS 5.4v32v332020-12-11
CVE-2020-35132 [MEDIUM] CWE-79 CVE-2020-35132: An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious
An XSS issue has been discovered in phpLDAPadmin before 1.2.6.2 that allows users to store malicious values that may be executed by other users at a later time via get_request in lib/function.php.
nvd
CVE-2020-0499P4MEDIUMCVSS 4.3v32v332020-12-15
CVE-2020-0499 [MEDIUM] CWE-125 CVE-2020-0499: In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due
In FLAC__bitreader_read_rice_signed_block of bitreader.c, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-156076070
nvd
CVE-2020-6425P4MEDIUMCVSS 5.4v30v31+1 more2020-03-23
CVE-2020-6425 [MEDIUM] CWE-20 CVE-2020-6425: Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an att
Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.149 allowed an attacker who convinced a user to install a malicious extension to bypass site isolation via a crafted Chrome Extension.
nvd
CVE-2015-1165P4MEDIUMCVSS 5.0v21v222015-03-09
CVE-2015-1165 [MEDIUM] CWE-200 CVE-2015-1165: RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attac
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
nvd
CVE-2022-3435P4MEDIUMCVSS 4.3v35v36+1 more2022-10-08
CVE-2022-3435 [MEDIUM] CWE-119 CVE-2022-3435: A vulnerability classified as problematic has been found in Linux Kernel. This affects the function
A vulnerability classified as problematic has been found in Linux Kernel. This affects the function fib_nh_match of the file net/ipv4/fib_semantics.c of the component IPv4 Handler. The manipulation leads to out-of-bounds read. It is possible to initiate the attack remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-210357
nvd
CVE-2021-20281P4MEDIUMCVSS 5.3v32v342021-03-15
CVE-2021-20281 [MEDIUM] CWE-200 CVE-2021-20281: It was possible for some users without permission to view other users' full names to do so via the o
It was possible for some users without permission to view other users' full names to do so via the online users block in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
nvd