Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 211 of 264
CVE-2016-2040P4MEDIUMCVSS 5.4v22v232016-02-20
CVE-2016-2040 [MEDIUM] CWE-79 CVE-2016-2040: Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x befo
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search query, or (4) hostname in a Location header.
nvd
CVE-2021-21218P4MEDIUMCVSS 5.5v32v33+1 more2021-04-26
CVE-2021-21218 [MEDIUM] CWE-908 CVE-2021-21218: Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obt
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2020-2814P4MEDIUMCVSS 4.9v30v31+1 more2020-04-15
CVE-2020-2814 [MEDIUM] CVE-2020-2814: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.6.47 and prior, 5.7.28 and prior and 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can res
nvd
CVE-2016-2045P4MEDIUMCVSS 5.4v22v232016-02-20
CVE-2016-2045 [MEDIUM] CWE-79 CVE-2016-2045: Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows r
Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response.
nvd
CVE-2022-28506P4MEDIUMCVSS 5.5v35v362022-04-25
CVE-2022-28506 [MEDIUM] CWE-787 CVE-2022-28506: There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.
nvd
CVE-2021-21219P4MEDIUMCVSS 5.5v32v33+1 more2021-04-26
CVE-2021-21219 [MEDIUM] CWE-252 CVE-2021-21219: Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obt
Uninitialized data in PDFium in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2021-3409P4MEDIUMCVSS 5.7v332021-03-23
CVE-2021-3409 [MEDIUM] CVE-2021-3409: The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable
The patch for CVE-2020-17380/CVE-2020-25085 was found to be ineffective, thus making QEMU vulnerable to the out-of-bounds read/write access issues previously found in the SDHCI controller emulation code. This flaw allows a malicious privileged guest to crash the QEMU process on the host, resulting in a denial of service or potential code execution. QEMU up to
nvd
CVE-2019-11091P4MEDIUMCVSS 5.6v292019-05-30
CVE-2019-11091 [MEDIUM] CVE-2019-11091: Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocess
Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable memory on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/
nvd
CVE-2019-5823P4MEDIUMCVSS 5.4v29v302019-06-27
CVE-2019-5823 [MEDIUM] CWE-601 CVE-2019-5823: Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a
Insufficient policy enforcement in service workers in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2022-0157P4MEDIUMCVSS 5.4v34v352022-01-10
CVE-2022-0157 [MEDIUM] CWE-79 CVE-2022-0157: phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('C
phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
nvd
CVE-2021-37958P4MEDIUMCVSS 5.4v33v352021-10-08
CVE-2021-37958 [MEDIUM] CVE-2021-37958: Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed
Inappropriate implementation in Navigation in Google Chrome on Windows prior to 94.0.4606.54 allowed a remote attacker to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd
CVE-2019-7222P4MEDIUMCVSS 5.5v28v292019-03-21
CVE-2019-7222 [MEDIUM] CVE-2019-7222: The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
The KVM implementation in the Linux kernel through 4.20.5 has an Information Leak.
nvd
CVE-2019-11833P4MEDIUMCVSS 5.5v292019-05-15
CVE-2019-11833 [MEDIUM] CWE-908 CVE-2019-11833: fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in th
fs/ext4/extents.c in the Linux kernel through 5.1.2 does not zero out the unused memory region in the extent tree block, which might allow local users to obtain sensitive information by reading uninitialized data in the filesystem.
nvd
CVE-2023-43785P4MEDIUMCVSS 5.5v382023-10-10
CVE-2023-43785 [MEDIUM] CWE-787 CVE-2023-43785: A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() functio
A vulnerability was found in libX11 due to a boundary condition within the _XkbReadKeySyms() function. This flaw allows a local user to trigger an out-of-bounds read error and read the contents of memory on the system.
nvd
CVE-2020-13631P4MEDIUMCVSS 5.5v322020-05-27
CVE-2020-13631 [MEDIUM] CVE-2020-13631: SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, r
SQLite before 3.32.0 allows a virtual table to be renamed to the name of one of its shadow tables, related to alter.c and build.c.
nvd
CVE-2019-3887P4MEDIUMCVSS 5.6v292019-04-09
CVE-2019-3887 [MEDIUM] CWE-863 CVE-2019-3887: A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access wi
A flaw was found in the way KVM hypervisor handled x2APIC Machine Specific Rregister (MSR) access with nested(=1) virtualization enabled. In that, L1 guest could access L0's APIC register values via L2 guest, when 'virtualize x2APIC mode' is enabled. A guest could use this flaw to potentially crash the host kernel resulting in DoS issue. Kernel versio
nvd
CVE-2018-5729P4MEDIUMCVSS 4.7v26v272018-03-06
CVE-2018-5729 [MEDIUM] CWE-476 CVE-2018-5729: MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Ke
MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.
nvd
CVE-2020-25650P4MEDIUMCVSS 5.5v32v332020-11-25
CVE-2020-25650 [MEDIUM] CWE-770 CVE-2020-25650: A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to
A flaw was found in the way the spice-vdagentd daemon handled file transfers from the host system to the virtual machine. Any unprivileged local guest user with access to the UNIX domain socket path `/run/spice-vdagentd/spice-vdagent-sock` could use this flaw to perform a memory denial of service for spice-vdagentd or even other processes in the VM
nvd
CVE-2020-12458P4MEDIUMCVSS 5.5v31v322020-04-29
CVE-2020-12458 [MEDIUM] CWE-732 CVE-2020-12458: An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/g
An information-disclosure flaw was found in Grafana through 6.7.3. The database directory /var/lib/grafana and database file /var/lib/grafana/grafana.db are world readable. This can result in exposure of sensitive information (e.g., cleartext or encrypted datasource passwords).
nvd
CVE-2020-11740P4MEDIUMCVSS 5.5v30v31+1 more2020-04-14
CVE-2020-11740 [MEDIUM] CWE-212 CVE-2020-11740: An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active p
An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (without active profiling) to obtain sensitive information about other guests. Unprivileged guests can request to map xenoprof buffers, even if profiling has not been enabled for those guests. These buffers were not scrubbed.
nvd