Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 214 of 264
CVE-2020-26558P4MEDIUMCVSS 4.2v342021-05-24
CVE-2020-26558 [MEDIUM] CWE-287 CVE-2020-26558: Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a
Bluetooth LE and BR/EDR secure pairing in Bluetooth Core Specification 2.1 through 5.2 may permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing (in the Passkey authentication procedure) by reflection of the public key and the authentication evidence of the initiating device, potentially permitting this attacker to co
nvd
CVE-2020-13696P4MEDIUMCVSS 4.4v31v322020-06-08
CVE-2020-13696 [MEDIUM] CWE-863 CVE-2020-13696: An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does no
An issue was discovered in LinuxTV xawtv before 3.107. The function dev_open() in v4l-conf.c does not perform sufficient checks to prevent an unprivileged caller of the program from opening unintended filesystem paths. This allows a local attacker with access to the v4l-conf setuid-root program to test for the existence of arbitrary files and to tri
nvd
CVE-2018-12207P4MEDIUMCVSS 6.5v30v312019-11-14
CVE-2018-12207 [MEDIUM] CWE-20 CVE-2018-12207: Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(
Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of service of the host system via local access.
nvd
CVE-2010-1634P4MEDIUMCVSS 5.0v132010-05-27
CVE-2010-1634 [MEDIUM] CWE-190 CVE-2010-1634: Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow
Multiple integer overflows in audioop.c in the audioop module in Python 2.6, 2.7, 3.1, and 3.2 allow context-dependent attackers to cause a denial of service (application crash) via a large fragment, as demonstrated by a call to audioop.lin2lin with a long string in the first argument, leading to a buffer overflow. NOTE: this vulnerability exists beca
nvd
CVE-2022-33746P4MEDIUMCVSS 6.5v35v36+1 more2022-10-11
CVE-2022-33746 [MEDIUM] CWE-404 CVE-2022-33746: P2M pool freeing may take excessively long The P2M pool backing second level address translation for
P2M pool freeing may take excessively long The P2M pool backing second level address translation for guests may be of significant size. Therefore its freeing may take more time than is reasonable without intermediate preemption checks. Such checking for the need to preempt was so far missing.
nvd
CVE-2021-4147P4MEDIUMCVSS 6.5v352022-03-25
CVE-2021-4147 [MEDIUM] CWE-667 CVE-2021-4147: A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and
A flaw was found in the libvirt libxl driver. A malicious guest could continuously reboot itself and cause libvirtd on the host to deadlock or crash, resulting in a denial of service condition.
nvd
CVE-2020-25812P4MEDIUMCVSS 6.1v332020-09-27
CVE-2020-25812 [MEDIUM] CWE-79 CVE-2020-25812: An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter u
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML.
nvd
CVE-2016-8690P4MEDIUMCVSS 5.5v232017-02-15
CVE-2016-8690 [MEDIUM] CWE-476 CVE-2016-8690: The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer before 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted BMP image in an imginfo command.
nvd
CVE-2014-9639P4MEDIUMCVSS 5.0v20v212015-01-23
CVE-2014-9639 [MEDIUM] CVE-2014-9639: Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of servic
Integer overflow in oggenc in vorbis-tools 1.4.0 allows remote attackers to cause a denial of service (crash) via a crafted number of channels in a WAV file, which triggers an out-of-bounds memory access.
nvd
CVE-2016-8887P4MEDIUMCVSS 5.5v23v242017-03-23
CVE-2016-8887 [MEDIUM] CWE-476 CVE-2016-8887: The jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before 1.900.10 allows remote att
The jp2_colr_destroy function in libjasper/jp2/jp2_cod.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (NULL pointer dereference).
nvd
CVE-2020-29571P4MEDIUMCVSS 6.2v32v332020-12-15
CVE-2020-29571 [MEDIUM] CWE-476 CVE-2020-29571: An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time function
An issue was discovered in Xen through 4.14.x. A bounds check common to most operation time functions specific to FIFO event channels depends on the CPU observing consistent state. While the producer side uses appropriately ordered writes, the consumer side isn't protected against re-ordered reads, and may hence end up de-referencing a NULL pointer.
nvd
CVE-2020-29567P4MEDIUMCVSS 6.2v332020-12-15
CVE-2020-29567 [MEDIUM] CWE-770 CVE-2020-29567: An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ h
An issue was discovered in Xen 4.14.x. When moving IRQs between CPUs to distribute the load of IRQ handling, IRQ vectors are dynamically allocated and de-allocated on the relevant CPUs. De-allocation has to happen when certain constraints are met. If these conditions are not met when first checked, the checking CPU may send an interrupt to itself, i
nvd
CVE-2014-0147P4MEDIUMCVSS 6.2v202022-09-29
CVE-2014-0147 [MEDIUM] CWE-190 CVE-2014-0147: Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW vers
Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount() routine.
nvd
CVE-2013-2014P4MEDIUMCVSS 5.0v192014-06-02
CVE-2013-2014 [MEDIUM] CWE-20 CVE-2013-2014: OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (me
OpenStack Identity (Keystone) before 2013.1 allows remote attackers to cause a denial of service (memory consumption and crash) via multiple long requests.
nvd
CVE-2015-2317P4MEDIUMCVSS 4.3v222015-03-25
CVE-2015-2317 [MEDIUM] CWE-79 CVE-2015-2317: The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x befor
The utils.http.is_safe_url function in Django before 1.4.20, 1.5.x, 1.6.x before 1.6.11, 1.7.x before 1.7.7, and 1.8.x before 1.8c1 does not properly validate URLs, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a control character in a URL, as demonstrated by a \x08javascript: URL.
nvd
CVE-2016-8568P4MEDIUMCVSS 5.5v23v24+1 more2017-02-03
CVE-2016-8568 [MEDIUM] CWE-125 CVE-2016-8568: The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
nvd
CVE-2022-3190P4MEDIUMCVSS 5.5v36v372022-09-13
CVE-2022-3190 [MEDIUM] CWE-835 CVE-2022-3190: Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to
Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-11760P4MEDIUMCVSS 5.5v322020-04-14
CVE-2020-11760 [MEDIUM] CWE-125 CVE-2020-11760: An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompres
An issue was discovered in OpenEXR before 2.4.1. There is an out-of-bounds read during RLE uncompression in rleUncompress in ImfRle.cpp.
nvd
CVE-2020-11763P4MEDIUMCVSS 5.5v322020-04-14
CVE-2020-11763 [MEDIUM] CWE-125 CVE-2020-11763: An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and writ
An issue was discovered in OpenEXR before 2.4.1. There is an std::vector out-of-bounds read and write, as demonstrated by ImfTileOffsets.cpp.
nvd
CVE-2013-6371P4MEDIUMCVSS 5.0v202014-04-22
CVE-2013-6371 [MEDIUM] CWE-310 CVE-2013-6371: The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of
The hash functionality in json-c before 0.12 allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted JSON data, involving collisions.
nvd