cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 217 of 264
CVE-2021-2012P4MEDIUMCVSS 4.9v32v332021-01-20
CVE-2021-2012 [MEDIUM] CVE-2021-2012: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2020-16166P4LOWCVSS 3.7v31v322020-07-30
CVE-2020-16166 [LOW] CWE-330 CVE-2020-16166: The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sen The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
nvd
CVE-2019-2757P4MEDIUMCVSS 4.9v29v302019-07-23
CVE-2019-2757 [MEDIUM] CVE-2019-2757: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Suppo Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Optimizer). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resul
nvd
CVE-2021-2001P4MEDIUMCVSS 4.9v32v332021-01-20
CVE-2021-2001 [MEDIUM] CVE-2021-2001: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.6.50 and prior, 5.7.30 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabili
nvd
CVE-2021-2016P4MEDIUMCVSS 4.9v32v332021-01-20
CVE-2021-2016 [MEDIUM] CVE-2021-2016: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2020-28928P4MEDIUMCVSS 5.5v33v342020-11-24
CVE-2020-28928 [MEDIUM] CWE-787 CVE-2020-28928: In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size In musl libc through 1.2.1, wcsnrtombs mishandles particular combinations of destination buffer size and source character limit, as demonstrated by an invalid write access (buffer overflow).
nvd
CVE-2020-14586P4MEDIUMCVSS 4.9v31v32+1 more2020-07-15
CVE-2020-14586 [MEDIUM] CVE-2020-14586: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2021-35577P4MEDIUMCVSS 4.9v33v34+1 more2021-10-20
CVE-2021-35577 [MEDIUM] CVE-2021-35577: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via MySQL Protcol to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2019-2780P4MEDIUMCVSS 4.9v29v302019-07-23
CVE-2019-2780 [MEDIUM] CVE-2019-2780: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Components / Serv Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Components / Services). Supported versions that are affected are 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2022-42721P4MEDIUMCVSS 5.5v35v36+1 more2022-10-14
CVE-2022-42721 [MEDIUM] CWE-835 CVE-2022-42721: A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x b A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
nvd
CVE-2022-23824P4MEDIUMCVSS 5.5v35v372022-11-09
CVE-2022-23824 [MEDIUM] CVE-2022-23824: IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leadi IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
nvd
CVE-2019-6501P4MEDIUMCVSS 5.5v302019-03-21
CVE-2019-6501 [MEDIUM] CWE-125 CVE-2019-6501: In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read In QEMU 3.1, scsi_handle_inquiry_reply in hw/scsi/scsi-generic.c allows out-of-bounds write and read operations.
nvd
CVE-2020-24332P4MEDIUMCVSS 5.5v332020-08-13
CVE-2020-24332 [MEDIUM] CWE-59 CVE-2020-24332: An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileg An issue was discovered in TrouSerS through 0.3.14. If the tcsd daemon is started with root privileges, the creation of the system.data file is prone to symlink attacks. The tss user can be used to create or corrupt existing files, which could possibly lead to a DoS attack.
nvd
CVE-2021-26931P4MEDIUMCVSS 5.5v32v332021-02-17
CVE-2021-26931 [MEDIUM] CWE-770 CVE-2021-26931: An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and An issue was discovered in the Linux kernel 2.6.39 through 5.10.16, as used in Xen. Block, net, and SCSI backends consider certain errors a plain bug, deliberately causing a kernel crash. For errors potentially being at least under the influence of guests (such as out of memory conditions), it isn't correct to assume a plain bug. Memory allocations p
nvd
CVE-2020-0543P4MEDIUMCVSS 5.5v31v322020-06-15
CVE-2020-0543 [MEDIUM] CWE-459 CVE-2020-0543: Incomplete cleanup from specific special register read operations in some Intel(R) Processors may al Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2021-3564P4MEDIUMCVSS 5.5v342021-06-08
CVE-2021-3564 [MEDIUM] CWE-415 CVE-2021-3564: A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was fou A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13.
nvd
CVE-2022-2153P4MEDIUMCVSS 5.5v362022-08-31
CVE-2022-2153 [MEDIUM] CWE-476 CVE-2022-2153: A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it p A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific ioctl calls, causing a kernel oops condition that results in a denial of servi
nvd
CVE-2020-29566P4MEDIUMCVSS 5.5v32v332020-12-15
CVE-2020-29566 [MEDIUM] CWE-674 CVE-2020-29566: An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x An issue was discovered in Xen through 4.14.x. When they require assistance from the device model, x86 HVM guests must be temporarily de-scheduled. The device model will signal Xen when it has completed its operation, via an event channel, so that the relevant vCPU is rescheduled. If the device model were to signal Xen without having actually comple
nvd
CVE-2023-40549P4MEDIUMCVSS 5.5v392024-01-29
CVE-2023-40549 [MEDIUM] CWE-125 CVE-2023-40549: An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during An out-of-bounds read flaw was found in Shim due to the lack of proper boundary verification during the load of a PE binary. This flaw allows an attacker to load a crafted PE binary, triggering the issue and crashing Shim, resulting in a denial of service.
nvd
CVE-2022-23645P4MEDIUMCVSS 5.5v352022-02-18
CVE-2022-23645 [MEDIUM] CWE-125 CVE-2022-23645: swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versi swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid value, may cause an out-of-bounds access when the byte array representing t
nvd
Fedoraproject Fedora vulnerabilities | cvebase