cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 221 of 264
CVE-2020-35503P4MEDIUMCVSS 6.0v332021-06-02
CVE-2020-35503 [MEDIUM] CWE-476 CVE-2020-35503: A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEM A NULL pointer dereference flaw was found in the megasas-gen2 SCSI host bus adapter emulation of QEMU in versions before and including 6.0. This issue occurs in the megasas_command_cancelled() callback function while dropping a SCSI request. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of serv
nvd
CVE-2020-29385P4MEDIUMCVSS 5.5v33v342020-12-26
CVE-2020-29385 [MEDIUM] CWE-835 CVE-2020-29385: GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c i GNOME gdk-pixbuf (aka GdkPixbuf) before 2.42.2 allows a denial of service (infinite loop) in lzw.c in the function write_indexes. if c->self_code equals 10, self->code_table[10].extends will assign the value 11 to c. The next execution in the loop will assign self->code_table[11].extends to c, which will give the value of 10. This will make the loop
nvd
CVE-2020-27842P4MEDIUMCVSS 5.5v32v332021-01-05
CVE-2020-27842 [MEDIUM] CWE-125 CVE-2020-27842: There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provi There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.
nvd
CVE-2022-2085P4MEDIUMCVSS 5.5v35v362022-06-16
CVE-2022-2085 [MEDIUM] CWE-476 CVE-2022-2085: A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to ren A NULL pointer dereference vulnerability was found in Ghostscript, which occurs when it tries to render a large number of bits in memory. When allocating a buffer device, it relies on an init_device_procs defined for the device that uses it as a prototype that depends upon the number of bits per pixel. For bpp > 64, mem_x_device is used and does not h
nvd
CVE-2015-1827P4MEDIUMCVSS 5.0v21v222015-03-30
CVE-2015-1827 [MEDIUM] CWE-19 CVE-2015-1827: The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly real The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.
nvd
CVE-2021-45930P4MEDIUMCVSS 5.5v34v352022-01-01
CVE-2021-45930 [MEDIUM] CWE-787 CVE-2021-45930: Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::Q Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).
nvd
CVE-2019-14464P4MEDIUMCVSS 5.5v30v312019-07-31
CVE-2019-14464 [MEDIUM] CWE-787 CVE-2019-14464: XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow. XMFile::read in XMFile.cpp in milkyplay in MilkyTracker 1.02.00 has a heap-based buffer overflow.
nvd
CVE-2018-18409P4MEDIUMCVSS 5.5v28v292018-10-17
CVE-2018-18409 [MEDIUM] CWE-125 CVE-2018-18409: A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received inco A stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect computation, leading to denial of service during an address_histogram call or a get_histogram call.
nvd
CVE-2021-20246P4MEDIUMCVSS 5.5v332021-03-09
CVE-2021-20246 [MEDIUM] CWE-369 CVE-2021-20246: A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file tha A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd
CVE-2019-19797P4MEDIUMCVSS 5.5v30v312019-12-15
CVE-2019-19797 [MEDIUM] CWE-787 CVE-2019-19797: read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write. read_colordef in read.c in Xfig fig2dev 3.2.7b has an out-of-bounds write.
nvd
CVE-2019-1010301P4MEDIUMCVSS 5.5v29v302019-07-15
CVE-2019-1010301 [MEDIUM] CWE-787 CVE-2019-1010301: jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsi jhead 3.03 is affected by: Buffer Overflow. The impact is: Denial of service. The component is: gpsinfo.c Line 151 ProcessGpsInfo(). The attack vector is: Open a specially crafted JPEG file.
nvd
CVE-2021-20245P4MEDIUMCVSS 5.5v332021-03-09
CVE-2021-20245 [MEDIUM] CWE-369 CVE-2021-20245: A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is pro A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
nvd
CVE-2020-35495P4MEDIUMCVSS 5.5v322021-01-04
CVE-2020-35495 [MEDIUM] CWE-476 CVE-2020-35495: There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be There's a flaw in binutils /bfd/pef.c. An attacker who is able to submit a crafted input file to be processed by the objdump program could cause a null pointer dereference. The greatest threat from this flaw is to application availability. This flaw affects binutils versions prior to 2.34.
nvd
CVE-2020-15989P4MEDIUMCVSS 5.5v31v32+1 more2020-11-03
CVE-2020-15989 [MEDIUM] CWE-908 CVE-2020-15989: Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obt Uninitialized data in PDFium in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted PDF file.
nvd
CVE-2020-10378P4MEDIUMCVSS 5.5v31v322020-06-25
CVE-2020-10378 [MEDIUM] CWE-125 CVE-2020-10378: In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX f In libImaging/PcxDecode.c in Pillow before 7.1.0, an out-of-bounds read can occur when reading PCX files where state->shuffle is instructed to read beyond state->buffer.
nvd
CVE-2019-2960P4MEDIUMCVSS 4.9v29v30+1 more2019-10-16
CVE-2019-2960 [MEDIUM] CVE-2019-2960: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supporte Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result i
nvd
CVE-2021-2383P4MEDIUMCVSS 4.9v33v342021-07-21
CVE-2021-2383 [MEDIUM] CVE-2021-2383: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2342P4MEDIUMCVSS 4.9v33v342021-07-21
CVE-2021-2342 [MEDIUM] CVE-2021-2342: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd
CVE-2021-2357P4MEDIUMCVSS 4.9v33v342021-07-21
CVE-2021-2357 [MEDIUM] CVE-2021-2357: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2367P4MEDIUMCVSS 4.9v33v342021-07-21
CVE-2021-2367 [MEDIUM] CVE-2021-2367: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
Fedoraproject Fedora vulnerabilities | cvebase