cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 209 of 264
CVE-2016-1523P4MEDIUMCVSS 6.5v22v232016-02-13
CVE-2016-1523 [MEDIUM] CVE-2016-1523: The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozi The SillMap::readFace function in FeatureMap.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, mishandles a return value, which allows remote attackers to cause a denial of service (missing initialization, NULL pointer dereference, and application crash) via a crafted Graphite smart font.
nvd
CVE-2018-20662P4MEDIUMCVSS 6.5v28v29+1 more2019-01-03
CVE-2018-20662 [MEDIUM] CWE-20 CVE-2018-20662: In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (applica In Poppler 0.72.0, PDFDoc::setup in PDFDoc.cc allows attackers to cause a denial-of-service (application crash caused by Object.h SIGABRT, because of a wrong return value from PDFDoc::setup) by crafting a PDF file in which an xref data structure is mishandled during extractPDFSubtype processing.
nvd
CVE-2016-2270P4MEDIUMCVSS 6.8v22v232016-02-19
CVE-2016-2270 [MEDIUM] CWE-20 CVE-2016-2270: Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) v Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.
nvd
CVE-2009-3611P4HIGHCVSS 7.1v10v112009-10-26
CVE-2009-3611 [HIGH] CWE-732 CVE-2009-3611: common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 befo common/snapshots.py in Back In Time (aka backintime) 0.9.26 changes certain permissions to 0777 before deleting the files in an old backup snapshot, which allows local users to obtain sensitive information by reading these files, or interfere with backup integrity by modifying files that are shared across snapshots.
nvd
CVE-2014-9529P4MEDIUMCVSS 6.9v20v212015-01-09
CVE-2014-9529 [MEDIUM] CWE-362 CVE-2014-9529: Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through Race condition in the key_gc_unused_keys function in security/keys/gc.c in the Linux kernel through 3.18.2 allows local users to cause a denial of service (memory corruption or panic) or possibly have unspecified other impact via keyctl commands that trigger access to a key structure member during garbage collection of a key.
nvd
CVE-2014-1530P4MEDIUMCVSS 6.1v19v202014-04-30
CVE-2014-1530 [MEDIUM] CWE-79 CVE-2014-1530: The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbir The docshell implementation in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to trigger the loading of a URL with a spoofed baseURI property, and conduct cross-site scripting (XSS) attacks, via a crafted web site that performs history navigation.
nvd
CVE-2013-5611P4MEDIUMCVSS 5.8v19v202013-12-11
CVE-2013-5611 [MEDIUM] CVE-2013-5611: Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which Mozilla Firefox before 26.0 does not properly remove the Application Installation doorhanger, which makes it easier for remote attackers to spoof a Web App installation site by controlling the timing of page navigation.
nvd
CVE-2019-19582P4MEDIUMCVSS 6.5v312019-12-11
CVE-2019-19582 [MEDIUM] CWE-835 CVE-2019-19582: An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of servi An issue was discovered in Xen through 4.12.x allowing x86 guest OS users to cause a denial of service (infinite loop) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over all bits involves functions which may misbehave in certain corner cases: On x86 acces
nvd
CVE-2019-19581P4MEDIUMCVSS 6.5v312019-12-11
CVE-2019-19581 [MEDIUM] CWE-119 CVE-2019-19581: An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial o An issue was discovered in Xen through 4.12.x allowing 32-bit Arm guest OS users to cause a denial of service (out-of-bounds access) because certain bit iteration is mishandled. In a number of places bitmaps are being used by the hypervisor to track certain state. Iteration over all bits involves functions which may misbehave in certain corner cases
nvd
CVE-2020-6816P4MEDIUMCVSS 6.1v332020-03-24
CVE-2020-6816 [MEDIUM] CWE-79 CVE-2020-6816: In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tag In Mozilla Bleach before 3.12, a mutation XSS in bleach.clean when RCDATA and either svg or math tags are whitelisted and the keyword argument strip=False.
nvd
CVE-2022-4144P4MEDIUMCVSS 6.5v372022-11-29
CVE-2022-4144 [MEDIUM] CWE-125 CVE-2022-4144: An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt( An out-of-bounds read flaw was found in the QXL display device emulation in QEMU. The qxl_phys2virt() function does not check the size of the structure pointed to by the guest physical address, potentially reading past the end of the bar space into adjacent pages. A malicious guest user could use this flaw to crash the QEMU process on the host causing
nvd
CVE-2019-9844P4MEDIUMCVSS 6.1v302019-04-09
CVE-2019-9844 [MEDIUM] CWE-79 CVE-2019-9844: simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: simple-markdown.js in Khan Academy simple-markdown before 0.4.4 allows XSS via a data: or vbscript: URI.
nvd
CVE-2022-42316P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42316 [MEDIUM] CWE-770 CVE-2022-42316: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42317P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42317 [MEDIUM] CWE-770 CVE-2022-42317: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42312P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42312 [MEDIUM] CWE-770 CVE-2022-42312: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42311P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42311 [MEDIUM] CWE-770 CVE-2022-42311: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42315P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42315 [MEDIUM] CWE-770 CVE-2022-42315: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42313P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42313 [MEDIUM] CWE-770 CVE-2022-42313: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42318P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42318 [MEDIUM] CWE-770 CVE-2022-42318: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
CVE-2022-42314P4MEDIUMCVSS 6.5v35v36+1 more2022-11-01
CVE-2022-42314 [MEDIUM] CWE-770 CVE-2022-42314: Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multipl Xenstore: guests can let run xenstored out of memory T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Malicious guests can cause xenstored to allocate vast amounts of memory, eventually resulting in a Denial of Service (DoS) of xenstored. There are multiple ways how gues
nvd
Fedoraproject Fedora vulnerabilities | cvebase