cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 218 of 264
CVE-2020-26570P4MEDIUMCVSS 5.5v332020-10-06
CVE-2020-26570 [MEDIUM] CWE-787 CVE-2020-26570: The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.
nvd
CVE-2022-1204P4MEDIUMCVSS 5.5v34v352022-08-29
CVE-2022-1204 [MEDIUM] CWE-416 CVE-2022-1204: A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the system.
nvd
CVE-2020-25686P4LOWCVSS 3.7v32v332021-01-20
CVE-2020-25686 [LOW] CVE-2020-25686: A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for A flaw was found in dnsmasq before version 2.83. When receiving a query, dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default, a maximum of 150 pending queries can be sent to upstream servers, so there can be at most 150 queries for the same name. This flaw allows an off-path attacker on the network to
nvd
CVE-2021-29647P4MEDIUMCVSS 5.5v32v33+1 more2021-03-30
CVE-2021-29647 [MEDIUM] CWE-909 CVE-2021-29647: An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows a An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.
nvd
CVE-2022-21264P4MEDIUMCVSS 4.9v34v352022-01-19
CVE-2022-21264 [MEDIUM] CVE-2022-21264: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2024-25629P4MEDIUMCVSS 5.5v38v39+1 more2024-02-23
CVE-2024-25629 [MEDIUM] CWE-127 CVE-2024-25629: c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local conf c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIASES` file, and if using a c-ares version prior to 1.27.0, the `/etc/hosts` file. If any of these configuration files has an embedded `NULL` character as the first character
nvd
CVE-2023-22056P4MEDIUMCVSS 4.9v37v38+1 more2023-07-18
CVE-2023-22056 [MEDIUM] CVE-2023-22056: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2020-12459P4MEDIUMCVSS 5.5v31v322020-04-29
CVE-2020-12459 [MEDIUM] CWE-732 CVE-2020-12459: In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/graf In certain Red Hat packages for Grafana 6.x through 6.3.6, the configuration files /etc/grafana/grafana.ini and /etc/grafana/ldap.toml (which contain a secret_key and a bind_password) are world readable.
nvd
CVE-2022-2873P4MEDIUMCVSS 5.5v362022-08-22
CVE-2022-2873 [MEDIUM] CWE-131 CVE-2022-2873: An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a user triggers the I2C_SMBUS_BLOCK_DATA (with the ioctl I2C_SMBUS) with malicious input data. This flaw allows a local user to crash the system.
nvd
CVE-2022-21339P4MEDIUMCVSS 4.9v34v352022-01-19
CVE-2022-21339 [MEDIUM] CVE-2022-21339: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2024-1062P4MEDIUMCVSS 5.5v39v40+1 more2024-02-12
CVE-2024-1062 [MEDIUM] CWE-122 CVE-2024-1062: A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing A heap overflow flaw was found in 389-ds-base. This issue leads to a denial of service when writing a value larger than 256 chars in log_entry_attr.
nvd
CVE-2023-22084P4MEDIUMCVSS 4.9v37v38+1 more2023-10-17
CVE-2023-22084 [MEDIUM] CVE-2023-22084: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43 and prior, 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in una
nvd
CVE-2022-40768P4MEDIUMCVSS 5.5v35v36+1 more2022-09-18
CVE-2022-40768 [MEDIUM] CWE-908 CVE-2022-40768: drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive inform drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
nvd
CVE-2023-22338P4MEDIUMCVSS 5.5v37v38+1 more2023-08-11
CVE-2023-22338 [MEDIUM] CWE-125 CVE-2023-22338: Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authentic Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2021-4023P4MEDIUMCVSS 5.5v352022-03-10
CVE-2021-4023 [MEDIUM] CWE-200 CVE-2021-4023: A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allows a local user with permissions to execute io-uring requests to possibly crash the system.
nvd
CVE-2015-5235P4MEDIUMCVSS 4.3v21v222015-10-09
CVE-2015-5235 [MEDIUM] CWE-20 CVE-2015-5235: IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned a IcedTea-Web before 1.5.3 and 1.6.x before 1.6.1 does not properly determine the origin of unsigned applets, which allows remote attackers to bypass the approval process or trick users into approving applet execution via a crafted web page.
nvd
CVE-2020-8552P4MEDIUMCVSS 4.3v322020-03-27
CVE-2020-8552 [MEDIUM] CWE-789 CVE-2020-8552: The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 ha The Kubernetes API server component in versions prior to 1.15.9, 1.16.0-1.16.6, and 1.17.0-1.17.2 has been found to be vulnerable to a denial of service attack via successful API requests.
nvd
CVE-2019-11281P4MEDIUMCVSS 4.8v30v312019-10-16
CVE-2019-11281 [MEDIUM] CWE-79 CVE-2019-11281: Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, Pivotal RabbitMQ, versions prior to v3.7.18, and RabbitMQ for PCF, versions 1.15.x prior to 1.15.13, versions 1.16.x prior to 1.16.6, and versions 1.17.x prior to 1.17.3, contain two components, the virtual host limits page, and the federation management UI, which do not properly sanitize user input. A remote authenticated malicious user with adminis
nvd
CVE-2020-1733P4MEDIUMCVSS 5.0v30v31+1 more2020-03-11
CVE-2020-1733 [MEDIUM] CWE-377 CVE-2020-1733: A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior A race condition flaw was found in Ansible Engine 2.7.17 and prior, 2.8.9 and prior, 2.9.6 and prior when running a playbook with an unprivileged become user. When Ansible needs to run a module with become user, the temporary directory is created in /var/tmp. This directory is created with "umask 77 && mkdir -p "; this operation does not fail if the d
nvd
CVE-2020-14553P4MEDIUMCVSS 4.3v31v32+1 more2020-07-15
CVE-2020-14553 [MEDIUM] CVE-2020-14553: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Suppo Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can resu
nvd
Fedoraproject Fedora vulnerabilities | cvebase