Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 203 of 264
CVE-2022-46392P4MEDIUMCVSS 5.3v36v372022-12-15
CVE-2022-46392 [MEDIUM] CWE-203 CVE-2022-46392: An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_
nvd
CVE-2023-42811P4MEDIUMCVSS 5.5v37v38+1 more2023-09-22
CVE-2023-42811 [MEDIUM] CWE-347 CVE-2023-42811: aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to versio
aes-gcm is a pure Rust implementation of the AES-GCM. Starting in version 0.10.0 and prior to version 0.10.3, in the AES GCM implementation of decrypt_in_place_detached, the decrypted ciphertext (i.e. the correct plaintext) is exposed even if tag verification fails. If a program using the `aes-gcm` crate's `decrypt_in_place*` APIs accesses the buffe
nvd
CVE-2023-4361P4MEDIUMCVSS 5.3v382023-08-15
CVE-2023-4361 [MEDIUM] CVE-2023-4361: Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed
Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-5544P4MEDIUMCVSS 5.4v37v38+1 more2023-11-09
CVE-2023-5544 [MEDIUM] CWE-79 CVE-2023-5544: Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk an
Wiki comments required additional sanitizing and access restrictions to prevent a stored XSS risk and potential IDOR risk.
nvd
CVE-2021-20320P4MEDIUMCVSS 5.5v342022-02-18
CVE-2021-20320 [MEDIUM] CWE-200 CVE-2021-20320: A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kerne
A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.
nvd
CVE-2024-4216P4MEDIUMCVSS 5.4v402024-05-02
CVE-2024-4216 [MEDIUM] CWE-79 CVE-2024-4216: pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This v
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
nvd
CVE-2019-9849P4MEDIUMCVSS 4.3v29v302019-07-17
CVE-2019-9849 [MEDIUM] CVE-2019-9849: LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed
LibreOffice has a 'stealth mode' in which only documents from locations deemed 'trusted' are allowed to retrieve remote resources. This mode is not the default mode, but can be enabled by users who want to disable LibreOffice's ability to include remote resources within a document. A flaw existed where bullet graphics were omitted from this protection prior t
nvd
CVE-2019-19269P4MEDIUMCVSS 4.9v30v312019-11-30
CVE-2019-19269 [MEDIUM] CWE-476 CVE-2019-19269: An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. A dereference of a NULL pointer may occur. This pointer is returned by the OpenSSL sk_X509_REVOKED_value() function when encountering an empty CRL installed by a system administrator. The dereference occurs when validating the certificate of a client connecting to the server in a T
nvd
CVE-2024-25983P4MEDIUMCVSS 5.3v382024-02-19
CVE-2024-25983 [MEDIUM] CWE-639 CVE-2024-25983: Insufficient checks in a web service made it possible to add comments to the comments block on anoth
Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).
nvd
CVE-2023-5549P4MEDIUMCVSS 5.3v382023-11-09
CVE-2023-5549 [MEDIUM] CWE-284 CVE-2023-5549: Insufficient web service capability checks made it possible to move categories a user had permission
Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.
nvd
CVE-2023-32732P4MEDIUMCVSS 5.3v37v382023-06-09
CVE-2023-32732 [MEDIUM] CWE-440 CVE-2023-32732: gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2
gRPC contains a vulnerability whereby a client can cause a termination of connection between a HTTP2 proxy and a gRPC server: a base64 encoding error for `-bin` suffixed headers will result in a disconnection by the gRPC server, but is typically allowed by HTTP2 proxies. We recommend upgrading beyond the commit in https://github.com/grpc/grpc/pull/3
nvd
CVE-2011-2501P4MEDIUMCVSS 6.5v142011-07-17
CVE-2011-2501 [MEDIUM] CVE-2011-2501: The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4
The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a C
nvd
CVE-2024-0333P4MEDIUMCVSS 5.3v38v392024-01-10
CVE-2024-0333 [MEDIUM] CVE-2024-0333: Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attac
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2014-4341P4MEDIUMCVSS 5.0v202014-07-20
CVE-2014-4341 [MEDIUM] CWE-125 CVE-2014-4341: MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer
MIT Kerberos 5 (aka krb5) before 1.12.2 allows remote attackers to cause a denial of service (buffer over-read and application crash) by injecting invalid tokens into a GSSAPI application session.
nvd
CVE-2022-0393P4HIGHCVSS 7.1v34v352022-01-28
CVE-2022-0393 [HIGH] CWE-125 CVE-2022-0393: Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2022-2287P4HIGHCVSS 7.1v35v362022-07-02
CVE-2022-2287 [HIGH] CWE-125 CVE-2022-2287: Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.
nvd
CVE-2022-30184P4MEDIUMCVSS 5.5v35v362022-06-15
CVE-2022-30184 [MEDIUM] CWE-200 CVE-2022-30184: .NET and Visual Studio Information Disclosure Vulnerability
.NET and Visual Studio Information Disclosure Vulnerability
nvd
CVE-2009-2816P4MEDIUMCVSS 6.8v11v122009-11-13
CVE-2009-2816 [MEDIUM] CWE-352 CVE-2009-2816: The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before
The implementation of Cross-Origin Resource Sharing (CORS) in WebKit, as used in Apple Safari before 4.0.4 and Google Chrome before 3.0.195.33, includes certain custom HTTP headers in the OPTIONS request during cross-origin operations with preflight, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a
nvd
CVE-2023-4156P4HIGHCVSS 7.1v382023-09-25
CVE-2023-4156 [HIGH] CWE-125 CVE-2023-4156: A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a
A heap out-of-bounds read flaw was found in builtin.c in the gawk package. This issue may lead to a crash and could be used to read sensitive information.
nvd
CVE-2019-11026P4MEDIUMCVSS 6.5v28v29+1 more2019-04-08
CVE-2019-11026 [MEDIUM] CWE-674 CVE-2019-11026: FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a cal
FontInfoScanner::scanFonts in FontInfo.cc in Poppler 0.75.0 has infinite recursion, leading to a call to the error function in Error.cc.
nvd