cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 202 of 264
CVE-2020-25813P4MEDIUMCVSS 5.3v332020-09-27
CVE-2020-25813 [MEDIUM] CVE-2020-25813: In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
nvd
CVE-2022-23133P4MEDIUMCVSS 5.4v34v352022-01-13
CVE-2022-23133 [MEDIUM] CWE-79 CVE-2022-23133: An authenticated user can create a hosts group from the configuration with XSS payload, which will b An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies and perform session hijacking to im
nvd
CVE-2021-20279P4MEDIUMCVSS 5.4v32v342021-03-15
CVE-2021-20279 [MEDIUM] CWE-79 CVE-2021-20279: The ID number user profile field required additional sanitizing to prevent a stored XSS risk in mood The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
nvd
CVE-2024-34064P4MEDIUMCVSS 5.4v39v402024-05-06
CVE-2024-34064 [MEDIUM] CVE-2024-34064: Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts Jinja is an extensible templating engine. The `xmlattr` filter in affected versions of Jinja accepts keys containing non-attribute characters. XML/HTML attributes cannot contain spaces, `/`, `>`, or `=`, as each would then be interpreted as starting a separate attribute. If an application accepts keys (as opposed to only values) as user input, and renders t
nvd
CVE-2024-1672P4MEDIUMCVSS 5.4v38v392024-02-21
CVE-2024-1672 [MEDIUM] CWE-474 CVE-2024-1672: Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allo Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-2385P4MEDIUMCVSS 5.0v33v342021-07-21
CVE-2021-2385 [MEDIUM] CVE-2021-2385: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supporte Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result
nvd
CVE-2021-26314P4MEDIUMCVSS 5.5v33v342021-06-09
CVE-2021-26314 [MEDIUM] CWE-208 CVE-2021-26314: Potential floating point value injection in all supported CPU products, in conjunction with software Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
nvd
CVE-2020-8619P4MEDIUMCVSS 4.9v31v322020-06-17
CVE-2020-8619 [MEDIUM] CWE-404 CVE-2020-8619: In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND S In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at least one zone contains an empty non-terminal entry containing an asterisk ("*") character, this defect cannot be enco
nvd
CVE-2022-30674P4MEDIUMCVSS 5.5v35v36+1 more2022-09-16
CVE-2022-30674 [MEDIUM] CWE-125 CVE-2022-30674: Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds Adobe InDesign versions 16.4.2 (and earlier) and 17.3 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
nvd
CVE-2023-39514P4MEDIUMCVSS 5.4v37v382023-09-05
CVE-2023-39514 [MEDIUM] CWE-79 CVE-2023-39514: Cacti is an open source operational monitoring and fault management framework. Affected versions are Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's b
nvd
CVE-2021-0561P4MEDIUMCVSS 5.5v35v362021-06-22
CVE-2021-0561 [MEDIUM] CWE-787 CVE-2021-0561: In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write d In append_to_verify_fifo_interleaved_ of stream_encoder.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-174302683
nvd
CVE-2024-35200P4MEDIUMCVSS 5.3v39v402024-05-29
CVE-2024-35200 [MEDIUM] CWE-476 CVE-2024-35200: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 reques When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate.
nvd
CVE-2019-3812P4MEDIUMCVSS 5.5v29v302019-02-19
CVE-2019-3812 [MEDIUM] CWE-119 CVE-2019-3812: QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up t QEMU, through version 2.10 and through version 3.1.0, is vulnerable to an out-of-bounds read of up to 128 bytes in the hw/i2c/i2c-ddc.c:i2c_ddc() function. A local attacker with permission to execute i2c commands could exploit this to read stack memory of the qemu process on the host.
nvd
CVE-2020-26571P4MEDIUMCVSS 5.5v332020-10-06
CVE-2020-26571 [MEDIUM] CWE-787 CVE-2020-26571: The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer over The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
nvd
CVE-2020-26572P4MEDIUMCVSS 5.5v332020-10-06
CVE-2020-26572 [MEDIUM] CWE-787 CVE-2020-26572: The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
nvd
CVE-2021-23351P4MEDIUMCVSS 4.9v33v342021-03-08
CVE-2021-23351 [MEDIUM] CVE-2021-23351: The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) vi The package github.com/pires/go-proxyproto before 0.5.0 are vulnerable to Denial of Service (DoS) via the parseVersion1() function. The reader in this package is a default bufio.Reader wrapping a net.Conn. It will read from the connection until it finds a newline. Since no limits are implemented in the code, a deliberately malformed V1 header could be used
nvd
CVE-2021-28700P4MEDIUMCVSS 4.9v33v34+1 more2021-08-27
CVE-2021-28700 [MEDIUM] CWE-770 CVE-2021-28700: xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create m xen/arm: No memory limit for dom0less domUs The dom0less feature allows an administrator to create multiple unprivileged domains directly from Xen. Unfortunately, the memory limit from them is not set. This allow a domain to allocate memory beyond what an administrator originally configured.
nvd
CVE-2024-0408P4MEDIUMCVSS 5.5v392024-01-18
CVE-2024-0408 [MEDIUM] CWE-158 CVE-2024-0408: A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX code will try to use an object tha
nvd
CVE-2021-31829P4MEDIUMCVSS 5.5v32v33+1 more2021-05-06
CVE-2021-31829 [MEDIUM] CWE-863 CVE-2021-31829: kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, lea kernel/bpf/verifier.c in the Linux kernel through 5.12.1 performs undesirable speculative loads, leading to disclosure of stack content via side-channel attacks, aka CID-801c6058d14a. The specific concern is not protecting the BPF stack area against speculative loads. Also, the BPF stack can contain uninitialized data that might represent sensitive
nvd
CVE-2023-43090P4MEDIUMCVSS 5.5v37v382023-09-22
CVE-2023-43090 [MEDIUM] CWE-862 CVE-2023-43090: A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local A vulnerability was found in GNOME Shell. GNOME Shell's lock screen allows an unauthenticated local user to view windows of the locked desktop session by using keyboard shortcuts to unlock the restricted functionality of the screenshot tool.
nvd
Fedoraproject Fedora vulnerabilities | cvebase