cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 210 of 264
CVE-2010-0751P4MEDIUMCVSS 5.0v11v12+1 more2010-04-06
CVE-2010-0751 [MEDIUM] CWE-476 CVE-2010-0751: The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly othe The ip_evictor function in ip_fragment.c in libnids before 1.24, as used in dsniff and possibly other products, allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via crafted fragmented packets.
nvd
CVE-2021-22570P4MEDIUMCVSS 5.5v34v35+1 more2022-01-26
CVE-2021-22570 [MEDIUM] CWE-476 CVE-2021-22570: Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, Nullptr dereference when a null char is present in a proto symbol. The symbol is parsed incorrectly, leading to an unchecked call into the proto file's name during generation of the resulting error message. Since the symbol is incorrectly parsed, the file is nullptr. We recommend upgrading to version 3.15.0 or greater.
nvd
CVE-2021-37746P4MEDIUMCVSS 6.1v33v342021-07-30
CVE-2021-37746 [MEDIUM] CWE-601 CVE-2021-37746: textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, d textview_uri_security_check in textview.c in Claws Mail before 3.18.0, and Sylpheed through 3.7.0, does not have sufficient link checks before accepting a click.
nvd
CVE-2013-4168P4MEDIUMCVSS 6.1v18v192019-11-01
CVE-2013-4168 [MEDIUM] CWE-79 CVE-2013-4168: Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields. Cross-site scripting (XSS) vulnerability in SmokePing 2.6.9 in the start and end time fields.
nvd
CVE-2014-9449P4MEDIUMCVSS 5.0v212015-01-02
CVE-2014-9449 [MEDIUM] CWE-119 CVE-2014-9449: Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows rem Buffer overflow in the RiffVideo::infoTagsHandler function in riffvideo.cpp in Exiv2 0.24 allows remote attackers to cause a denial of service (crash) via a long IKEY INFO tag value in an AVI file.
nvd
CVE-2020-35474P4MEDIUMCVSS 6.1v332020-12-18
CVE-2020-35474 [MEDIUM] CWE-79 CVE-2020-35474: In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS becau In MediaWiki before 1.35.1, the combination of Html::rawElement and Message::text leads to XSS because the definition of MediaWiki:recentchanges-legend-watchlistexpiry can be changed onwiki so that the output is raw HTML.
nvd
CVE-2022-25601P4MEDIUMCVSS 6.1v34v35+1 more2022-03-11
CVE-2022-25601 [MEDIUM] CWE-79 CVE-2022-25601: Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Fo Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
nvd
CVE-2015-3885P4MEDIUMCVSS 4.3v212015-05-19
CVE-2015-3885 [MEDIUM] CWE-189 CVE-2015-3885: Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to ca Integer overflow in the ljpeg_start function in dcraw 7.00 and earlier allows remote attackers to cause a denial of service (crash) via a crafted image, which triggers a buffer overflow, related to the len variable.
nvd
CVE-2010-0746P4MEDIUMCVSS 6.2v11v122014-01-13
CVE-2010-0746 [MEDIUM] CWE-22 CVE-2010-0746: Directory traversal vulnerability in DeviceKit-disks in DeviceKit, as used in Fedora 11 and 12 and p Directory traversal vulnerability in DeviceKit-disks in DeviceKit, as used in Fedora 11 and 12 and possibly other operating systems, allows local users to gain privileges via .. (dot dot) sequences in the label for a pluggable storage device.
nvd
CVE-2024-34500P4MEDIUMCVSS 6.1v402024-05-05
CVE-2024-34500 [MEDIUM] CWE-79 CVE-2024-34500: An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class.
nvd
CVE-2017-5849P4MEDIUMCVSS 5.5v24v252017-03-15
CVE-2017-5849 [MEDIUM] CWE-125 CVE-2017-5849: tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which all tiffttopnm in netpbm 10.47.63 does not properly use the libtiff TIFFRGBAImageGet function, which allows remote attackers to cause a denial of service (out-of-bounds read and write) via a crafted tiff image file, related to transposing width and height values.
nvd
CVE-2021-2478P4MEDIUMCVSS 4.9v33v34+1 more2021-10-20
CVE-2021-2478 [MEDIUM] CVE-2021-2478: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2020-11762P4MEDIUMCVSS 5.5v322020-04-14
CVE-2020-11762 [MEDIUM] CWE-125 CVE-2020-11762: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaComp An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read and write in DwaCompressor::uncompress in ImfDwaCompressor.cpp when handling the UNKNOWN compression case.
nvd
CVE-2020-11764P4MEDIUMCVSS 5.5v322020-04-14
CVE-2020-11764 [MEDIUM] CWE-787 CVE-2020-11764: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuf An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds write in copyIntoFrameBuffer in ImfMisc.cpp.
nvd
CVE-2021-29338P4MEDIUMCVSS 5.5v33v342021-04-14
CVE-2021-29338 [MEDIUM] CWE-190 CVE-2021-29338: Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Deni Integer Overflow in OpenJPEG v2.4.0 allows remote attackers to crash the application, causing a Denial of Service (DoS). This occurs when the attacker uses the command line option "-ImgDir" on a directory that contains 1048576 files.
nvd
CVE-2015-7207P4MEDIUMCVSS 5.0v22v232015-12-16
CVE-2015-7207 [MEDIUM] CWE-200 CVE-2015-7207: Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing AP Mozilla Firefox before 43.0 does not properly restrict the availability of IFRAME Resource Timing API times, which allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that leverages history.back and performance.getEntries calls, a related issue to CVE-2015-1300.
nvd
CVE-2021-3607P4MEDIUMCVSS 6.0v342022-02-24
CVE-2021-3607 [MEDIUM] CWE-190 CVE-2021-3607: An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in vers An integer overflow was found in the QEMU implementation of VMWare's paravirtual RDMA device in versions prior to 6.1.0. The issue occurs while handling a "PVRDMA_REG_DSRHIGH" write from the guest due to improper input validation. This flaw allows a privileged guest user to make QEMU allocate a large amount of memory, resulting in a denial of service.
nvd
CVE-2015-1609P4MEDIUMCVSS 5.0v212015-03-30
CVE-2015-1609 [MEDIUM] CWE-20 CVE-2015-1609: MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service vi MongoDB before 2.4.13 and 2.6.x before 2.6.8 allows remote attackers to cause a denial of service via a crafted UTF-8 string in a BSON request.
nvd
CVE-2021-45943P4MEDIUMCVSS 5.5v34v352022-01-01
CVE-2021-45943 [MEDIUM] CWE-787 CVE-2021-45943: GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (call GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
nvd
CVE-2020-2812P4MEDIUMCVSS 4.9v30v31+1 more2020-04-15
CVE-2020-2812 [MEDIUM] CVE-2020-2812: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Sup Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vul
nvd
Fedoraproject Fedora vulnerabilities | cvebase