cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 212 of 264
CVE-2019-19479P4MEDIUMCVSS 5.5v312019-12-01
CVE-2019-19479 [MEDIUM] CWE-125 CVE-2019-19479: An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setco An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
nvd
CVE-2021-34556P4MEDIUMCVSS 5.5v33v342021-08-02
CVE-2021-34556 [MEDIUM] CWE-203 CVE-2021-34556: In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information fro In the Linux kernel through 5.13.7, an unprivileged BPF program can obtain sensitive information from kernel memory via a Speculative Store Bypass side-channel attack because the protection mechanism neglects the possibility of uninitialized memory locations on the BPF stack.
nvd
CVE-2014-4978P4MEDIUMCVSS 5.5v222017-12-29
CVE-2014-4978 [MEDIUM] CWE-59 CVE-2014-4978: The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to tru The rs_filter_graph function in librawstudio/rs-filter.c in rawstudio might allow local users to truncate arbitrary files via a symlink attack on (1) /tmp/rs-filter-graph.png or (2) /tmp/rs-filter-graph.
nvd
CVE-2023-4155P4MEDIUMCVSS 5.6v37v382023-09-13
CVE-2023-4155 [MEDIUM] CWE-367 CVE-2023-4155: A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest u A flaw was found in KVM AMD Secure Encrypted Virtualization (SEV) in the Linux kernel. A KVM guest using SEV-ES or SEV-SNP with multiple vCPUs can trigger a double fetch race condition vulnerability and invoke the `VMGEXIT` handler recursively. If an attacker manages to call the handler multiple times, they can trigger a stack overflow and cause a den
nvd
CVE-2012-5644P4MEDIUMCVSS 5.5v182019-11-25
CVE-2012-5644 [MEDIUM] CWE-200 CVE-2012-5644: libuser has information disclosure when moving user's home directory libuser has information disclosure when moving user's home directory
nvd
CVE-2022-31030P4MEDIUMCVSS 5.5v35v362022-06-09
CVE-2022-31030 [MEDIUM] CWE-400 CVE-2022-31030: containerd is an open source container runtime. A bug was found in the containerd's CRI implementati containerd is an open source container runtime. A bug was found in the containerd's CRI implementation where programs inside a container can cause the containerd daemon to consume memory without bound during invocation of the `ExecSync` API. This can cause containerd to consume all available memory on the computer, denying service to other legitimat
nvd
CVE-2023-22909P4MEDIUMCVSS 5.3v372023-01-10
CVE-2023-22909 [MEDIUM] CVE-2023-22909: An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are slow.
nvd
CVE-2020-13867P4MEDIUMCVSS 5.5v322020-06-05
CVE-2020-13867 [MEDIUM] CWE-276 CVE-2020-13867: Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup dire Open-iSCSI targetcli-fb through 2.1.52 has weak permissions for /etc/target (and for the backup directory and backup files).
nvd
CVE-2021-26933P4MEDIUMCVSS 5.5v32v332021-02-17
CVE-2021-26933 [MEDIUM] CVE-2021-26933: An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether mem An issue was discovered in Xen 4.9 through 4.14.x. On Arm, a guest is allowed to control whether memory accesses are bypassing the cache. This means that Xen needs to ensure that all writes (such as the ones during scrubbing) have reached the memory before handing over the page to a guest. Unfortunately, the operation to clean the cache is happening before
nvd
CVE-2024-0690P4MEDIUMCVSS 5.5v38v392024-02-06
CVE-2024-0690 [MEDIUM] CWE-117 CVE-2024-0690: An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_ An information disclosure flaw was found in ansible-core due to a failure to respect the ANSIBLE_NO_LOG configuration in some scenarios. Information is still included in the output in certain tasks, such as loop items. Depending on the task, this issue may include sensitive information, such as decrypted secret values.
nvd
CVE-2022-4122P4MEDIUMCVSS 5.3v35v36+1 more2022-12-08
CVE-2022-4122 [MEDIUM] CWE-59 CVE-2022-4122: A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
nvd
CVE-2024-27017P4MEDIUMCVSS 5.5v38v39+1 more2024-05-01
CVE-2024-27017 [MEDIUM] CVE-2024-27017: In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_pipapo: walk over current view on netlink dump The generation mask can be updated while netlink dump is in progress. The pipapo set backend walk iterator cannot rely on it to infer what view of the datastructure is to be used. Add notation to specify if user wants to rea
nvd
CVE-2022-42322P4MEDIUMCVSS 5.5v35v36+1 more2022-11-01
CVE-2022-42322 [MEDIUM] CWE-401 CVE-2022-42322: Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record rela Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be modified to be owned by Dom0. This will allow two malicious guests working tog
nvd
CVE-2022-42323P4MEDIUMCVSS 5.5v35v36+1 more2022-11-01
CVE-2022-42323 [MEDIUM] CWE-401 CVE-2022-42323: Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record rela Xenstore: Cooperating guests can create arbitrary numbers of nodes T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] Since the fix of XSA-322 any Xenstore node owned by a removed domain will be modified to be owned by Dom0. This will allow two malicious guests working tog
nvd
CVE-2022-42331P4MEDIUMCVSS 5.5v37v382023-03-21
CVE-2022-42331 [MEDIUM] CVE-2022-42331: x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectr x86: speculative vulnerability in 32bit SYSCALL path Due to an oversight in the very original Spectre/Meltdown security work (XSA-254), one entrypath performs its speculation-safety actions too late. In some configurations, there is an unprotected RET instruction which can be attacked with a variety of speculative attacks.
nvd
CVE-2024-27013P4MEDIUMCVSS 5.5v38v39+1 more2024-05-01
CVE-2024-27013 [MEDIUM] CWE-770 CVE-2024-27013: In the Linux kernel, the following vulnerability has been resolved: tun: limit printing rate when i In the Linux kernel, the following vulnerability has been resolved: tun: limit printing rate when illegal packet received by tun dev vhost_worker will call tun call backs to receive packets. If too many illegal packets arrives, tun_do_read will keep dumping packet contents. When console is enabled, it will costs much more cpu time to dump packet an
nvd
CVE-2024-1151P4MEDIUMCVSS 5.5v38v392024-02-11
CVE-2024-1151 [MEDIUM] CWE-121 CVE-2024-1151: A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs A vulnerability was reported in the Open vSwitch sub-component in the Linux Kernel. The flaw occurs when a recursive operation of code push recursively calls into the code block. The OVS module does not validate the stack depth, pushing too many frames and causing a stack overflow. As a result, this can lead to a crash or other related issues.
nvd
CVE-2022-47927P4MEDIUMCVSS 5.5v372023-01-12
CVE-2022-47927 [MEDIUM] CWE-732 CVE-2022-47927: An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. When installing with a pre-existing data directory that has weak permissions, the SQLite files are created with file mode 0644, i.e., world readable to local users. These files include credentials data.
nvd
CVE-2020-2875P4MEDIUMCVSS 4.7v32v332020-04-15
CVE-2020-2875 [MEDIUM] CVE-2020-2875: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported ve Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.14 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a
nvd
CVE-2009-3767P4MEDIUMCVSS 4.3v112009-10-23
CVE-2009-3767 [MEDIUM] CVE-2009-3767: libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a '\0' character in a domain name in the subject's Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification
nvd
Fedoraproject Fedora vulnerabilities | cvebase