cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 219 of 264
CVE-2016-0724P4MEDIUMCVSS 4.3v22v232016-02-22
CVE-2016-0724 [MEDIUM] CWE-200 CVE-2016-0724: The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in The (1) core_enrol_get_course_enrolment_methods and (2) enrol_self_get_instance_info web services in Moodle through 2.6.11, 2.7.x before 2.7.12, 2.8.x before 2.8.10, 2.9.x before 2.9.4, and 3.0.x before 3.0.2 do not consider the moodle/course:viewhiddencourses capability, which allows remote authenticated users to obtain sensitive information via a we
nvd
CVE-2024-21096P4MEDIUMCVSS 4.9v39v402024-04-16
CVE-2024-21096 [MEDIUM] CWE-829 CVE-2024-21096: Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this
nvd
CVE-2020-14559P4MEDIUMCVSS 4.3v31v32+1 more2020-07-15
CVE-2020-14559 [MEDIUM] CVE-2020-14559: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). S Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 5.6.48 and prior, 5.7.30 and prior and 8.0.20 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this
nvd
CVE-2024-3056P4MEDIUMCVSS 4.8v402024-08-02
CVE-2024-3056 [MEDIUM] CWE-400 CVE-2024-3056: A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC resources in /dev/shm. The malicious container will continue to exhaust resources until it is out-of-memory (OOM) killed. While the maliciou
nvd
CVE-2020-6441P4MEDIUMCVSS 4.3v30v31+1 more2020-04-13
CVE-2020-6441 [MEDIUM] CWE-276 CVE-2020-6441: Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote a Insufficient policy enforcement in omnibox in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
nvd
CVE-2015-5069P4MEDIUMCVSS 4.3v21v222017-09-26
CVE-2015-5069 [MEDIUM] CWE-200 CVE-2015-5069: The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in fi The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.3 and 1.13.x before 1.13.1 allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML.
nvd
CVE-2023-6004P4MEDIUMCVSS 4.8v382024-01-03
CVE-2023-6004 [MEDIUM] CWE-74 CVE-2023-6004: A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit un A flaw was found in libssh. By utilizing the ProxyCommand or ProxyJump feature, users can exploit unchecked hostname syntax on the client. This issue may allow an attacker to inject malicious code into the command of the features mentioned through the hostname parameter.
nvd
CVE-2021-30159P4MEDIUMCVSS 4.3v33v342021-04-09
CVE-2021-30159 [MEDIUM] CVE-2021-30159: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users c An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Users can bypass intended restrictions on deleting pages in certain "fast double move" situations. MovePage::isValidMoveTarget() uses FOR UPDATE, but it's only called if Title::getArticleID() returns non-zero with no special flags. Next, MovePage::moveToInternal() w
nvd
CVE-2022-24917P4MEDIUMCVSS 4.4v34v35+1 more2022-03-09
CVE-2022-24917 [MEDIUM] CWE-79 CVE-2022-24917: An authenticated user can create a link with reflected Javascript code inside it for services’ page An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can ma
nvd
CVE-2021-20229P4MEDIUMCVSS 4.3v332021-02-23
CVE-2021-20229 [MEDIUM] CWE-863 CVE-2021-20229: A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privileg A flaw was found in PostgreSQL in versions before 13.2. This flaw allows a user with SELECT privilege on one column to craft a special query that returns all columns of the table. The highest threat from this vulnerability is to confidentiality.
nvd
CVE-2022-24918P4MEDIUMCVSS 4.4v34v35+1 more2022-03-09
CVE-2022-24918 [MEDIUM] CWE-79 CVE-2022-24918: An authenticated user can create a link with reflected Javascript code inside it for items’ page and An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the rest of the web page and can make
nvd
CVE-2022-39317P4MEDIUMCVSS 4.6v36v372022-11-16
CVE-2022-39317 [MEDIUM] CWE-125 CVE-2022-39317: FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are miss FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing a range check for input offset index in ZGFX decoder. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it. This issue has been addressed in version 2.9.0. There are no known workarounds for this issue
nvd
CVE-2009-2416P4MEDIUMCVSS 6.5v10v112009-08-11
CVE-2009-2416 [MEDIUM] CWE-416 CVE-2009-2416: Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and l Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
nvd
CVE-2020-10932P4MEDIUMCVSS 4.7v31v322020-04-15
CVE-2020-10932 [MEDIUM] CWE-203 CVE-2020-10932: An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can An issue was discovered in Arm Mbed TLS before 2.16.6 and 2.7.x before 2.7.15. An attacker that can get precise enough side-channel measurements can recover the long-term ECDSA private key by (1) reconstructing the projective coordinate of the result of scalar multiplication by exploiting side channels in the conversion to affine coordinates; (2) usi
nvd
CVE-2023-39999P4MEDIUMCVSS 4.3v37v382023-10-13
CVE-2023-39999 [MEDIUM] CWE-200 CVE-2023-39999: Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5 through 5.5.12, from 5.4 through 5.4.13, from 5.3 through 5.3.15, from 5.2 thr
nvd
CVE-2020-10754P4MEDIUMCVSS 4.3v312020-06-08
CVE-2020-10754 [MEDIUM] CWE-287 CVE-2020-10754: It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path an It was found that nmcli, a command line interface to NetworkManager did not honour 802-1x.ca-path and 802-1x.phase2-ca-path settings, when creating a new profile. When a user connects to a network using this profile, the authentication does not happen and the connection is made insecurely.
nvd
CVE-2023-28336P4MEDIUMCVSS 4.3v362023-03-23
CVE-2023-28336 [MEDIUM] CWE-200 CVE-2023-28336: Insufficient filtering of grade report history made it possible for teachers to access the names of Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.
nvd
CVE-2021-27836P4MEDIUMCVSS 6.5v33v34+1 more2021-11-03
CVE-2021-27836 [MEDIUM] CWE-476 CVE-2021-27836: An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.
nvd
CVE-2007-4045P4MEDIUMCVSS 5.0v72007-07-27
CVE-2007-4045 [MEDIUM] CVE-2007-4045: The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote The CUPS service, as used in SUSE Linux before 20070720 and other Linux distributions, allows remote attackers to cause a denial of service via unspecified vectors related to an incomplete fix for CVE-2007-0720 that introduced a different denial of service problem in SSL negotiation.
nvd
CVE-2019-13038P4MEDIUMCVSS 6.1v30v312019-06-29
CVE-2019-13038 [MEDIUM] CWE-601 CVE-2019-13038: mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrat mod_auth_mellon through 0.14.2 has an Open Redirect via the login?ReturnTo= substring, as demonstrated by omitting the // after http: in the target URL.
nvd
Fedoraproject Fedora vulnerabilities | cvebase