Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 208 of 264
CVE-2023-43789P4MEDIUMCVSS 5.5v382023-10-12
CVE-2023-43789 [MEDIUM] CWE-125 CVE-2023-43789: A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a loca
A vulnerability was found in libXpm where a vulnerability exists due to a boundary condition, a local user can trigger an out-of-bounds read error and read contents of memory on the system.
nvd
CVE-2021-35602P4MEDIUMCVSS 5.0v33v34+1 more2021-10-20
CVE-2021-35602 [MEDIUM] CVE-2021-35602: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abilit
nvd
CVE-2022-42824P4MEDIUMCVSS 5.5v35v36+1 more2022-11-01
CVE-2022-42824 [MEDIUM] CVE-2022-42824: A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS
A logic issue was addressed with improved state management. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose sensitive user information.
nvd
CVE-2023-1786P4MEDIUMCVSS 5.5v382023-04-26
CVE-2023-1786 [MEDIUM] CWE-532 CVE-2023-1786: Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use t
Sensitive data could be exposed in logs of cloud-init before version 23.1.2. An attacker could use this information to find hashed passwords and possibly escalate their privilege.
nvd
CVE-2023-2431P4MEDIUMCVSS 5.5v382023-06-16
CVE-2023-2431 [MEDIUM] CWE-1287 CVE-2023-2431: A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcemen
A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in unconfined (seccomp disabled) mode. This bug affects Kubelet.
nvd
CVE-2022-44020P4MEDIUMCVSS 5.5v35v36+1 more2022-10-30
CVE-2022-44020 [MEDIUM] CWE-281 CVE-2022-44020: An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changi
An issue was discovered in OpenStack Sushy-Tools through 0.21.0 and VirtualBMC through 2.2.2. Changing the boot device configuration with these packages removes password protection from the managed libvirt XML domain. NOTE: this only affects an "unsupported, production-like configuration."
nvd
CVE-2021-20266P4MEDIUMCVSS 4.9v33v342021-04-30
CVE-2021-20266 [MEDIUM] CWE-125 CVE-2021-20266: A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify
A flaw was found in RPM's hdrblobInit() in lib/header.c. This flaw allows an attacker who can modify the rpmdb to cause an out-of-bounds read. The highest threat from this vulnerability is to system availability.
nvd
CVE-2023-1055P4MEDIUMCVSS 5.5v36v37+1 more2023-02-27
CVE-2023-1055 [MEDIUM] CWE-200 CVE-2023-1055: A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPasswor
A flaw was found in RHDS 11 and RHDS 12. While browsing entries LDAP tries to decode the userPassword attribute instead of the userCertificate attribute which could lead into sensitive information leaked. An attacker with a local account where the cockpit-389-ds is running can list the processes and display the hashed passwords. The highest threat fro
nvd
CVE-2021-3446P4MEDIUMCVSS 5.5v332021-03-25
CVE-2021-3446 [MEDIUM] CWE-327 CVE-2021-3446: A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with
A flaw was found in libtpms in versions before 0.8.2. The commonly used integration of libtpms with OpenSSL contained a vulnerability related to the returned IV (initialization vector) when certain symmetric ciphers were used. Instead of returning the last IV it returned the initial IV to the caller, thus weakening the subsequent encryption and decrypt
nvd
CVE-2023-1672P4MEDIUMCVSS 5.3v382023-07-11
CVE-2023-1672 [MEDIUM] CWE-362 CVE-2023-1672: A race condition exists in the Tang server functionality for key generation and key rotation. This f
A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time window where Tang private keys become readable by other processes on the same host.
nvd
CVE-2023-5545P4MEDIUMCVSS 5.3v382023-11-09
CVE-2023-5545 [MEDIUM] CWE-200 CVE-2023-5545: H5P metadata automatically populated the author with the user's username, which could be sensitive i
H5P metadata automatically populated the author with the user's username, which could be sensitive information.
nvd
CVE-2021-42762P4MEDIUMCVSS 5.3v33v34+1 more2021-10-20
CVE-2021-42762 [MEDIUM] CVE-2021-42762: BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass tha
BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that Web
nvd
CVE-2021-24119P4MEDIUMCVSS 4.9v33v342021-07-14
CVE-2021-24119 [MEDIUM] CWE-203 CVE-2021-24119: In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows
In Trusted Firmware Mbed TLS 2.24.0, a side-channel vulnerability in base64 PEM file decoding allows system-level (administrator) attackers to obtain information about secret RSA keys via a controlled-channel and side-channel attack on software running in isolated environments that can be single stepped, especially Intel SGX.
nvd
CVE-2015-7217P4MEDIUMCVSS 4.3v22v232015-12-16
CVE-2015-7217 [MEDIUM] CWE-119 CVE-2015-7217: The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly ena
The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.
nvd
CVE-2021-28544P4MEDIUMCVSS 4.3v35v362022-04-12
CVE-2021-28544 [MEDIUM] CWE-200 CVE-2021-28544: Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom'
Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy can see the 'copyfrom' path of the original. This also reveals the fact t
nvd
CVE-2023-45129P4MEDIUMCVSS 4.9v37v382023-10-10
CVE-2023-45129 [MEDIUM] CWE-770 CVE-2023-45129: Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Pri
Synapse is an open-source Matrix homeserver written and maintained by the Matrix.org Foundation. Prior to version 1.94.0, a malicious server ACL event can impact performance temporarily or permanently leading to a persistent denial of service. Homeservers running on a closed federation (which presumably do not need to use server ACLs) are not affect
nvd
CVE-2024-31079P4MEDIUMCVSS 4.8v39v402024-05-29
CVE-2024-31079 [MEDIUM] CWE-121 CVE-2024-31079: When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 reques
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed HTTP/3 requests can cause NGINX worker processes to terminate or cause other potential impact. This attack requires that a request be specifically timed during the connection draining process, which the attacker has no visibility and limited influence over.
nvd
CVE-2010-2249P4MEDIUMCVSS 6.5v12v132010-06-30
CVE-2010-2249 [MEDIUM] CWE-401 CVE-2010-2249: Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers t
Memory leak in pngrutil.c in libpng before 1.2.44, and 1.4.x before 1.4.3, allows remote attackers to cause a denial of service (memory consumption and application crash) via a PNG image containing malformed Physical Scale (aka sCAL) chunks.
nvd
CVE-2008-3281P4MEDIUMCVSS 6.5v92008-08-27
CVE-2008-3281 [MEDIUM] CWE-776 CVE-2008-3281: libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribut
libxml2 2.6.32 and earlier does not properly detect recursion during entity expansion in an attribute value, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document.
nvd
CVE-2021-32672P4MEDIUMCVSS 4.3v33v34+1 more2021-10-04
CVE-2021-32672 [MEDIUM] CWE-125 CVE-2021-32672: Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger
Redis is an open source, in-memory database that persists on disk. When using the Redis Lua Debugger, users can send malformed requests that cause the debugger’s protocol parser to read data beyond the actual buffer. This issue affects all versions of Redis with Lua debugging support (3.2 or newer). The problem is fixed in versions 6.2.6, 6.0.16 and
nvd