Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 225 of 264
CVE-2021-2169P4MEDIUMCVSS 4.9v32v33+1 more2021-04-22
CVE-2021-2169 [MEDIUM] CVE-2021-2169: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd
CVE-2020-14597P4MEDIUMCVSS 4.9v31v32+1 more2020-07-15
CVE-2020-14597 [MEDIUM] CVE-2020-14597: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.20 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2021-35575P4MEDIUMCVSS 4.9v33v34+1 more2021-10-20
CVE-2021-35575 [MEDIUM] CVE-2021-35575: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2020-2928P4MEDIUMCVSS 4.9v30v31+1 more2020-04-15
CVE-2020-2928 [MEDIUM] CVE-2020-2928: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2020-2896P4MEDIUMCVSS 4.9v30v31+1 more2020-04-15
CVE-2020-2896 [MEDIUM] CVE-2020-2896: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). S
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2020-2892P4MEDIUMCVSS 4.9v30v31+1 more2020-04-15
CVE-2020-2892 [MEDIUM] CVE-2020-2892: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2021-2196P4MEDIUMCVSS 4.9v32v33+1 more2021-04-22
CVE-2021-2196 [MEDIUM] CVE-2021-2196: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versio
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cau
nvd
CVE-2021-2179P4MEDIUMCVSS 4.9v32v33+1 more2021-04-22
CVE-2021-2179 [MEDIUM] CVE-2021-2179: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability
nvd
CVE-2022-21256P4MEDIUMCVSS 4.9v34v352022-01-19
CVE-2022-21256 [MEDIUM] CVE-2022-21256: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2015-1433P4MEDIUMCVSS 4.3v212015-02-03
CVE-2015-1433 [MEDIUM] CWE-79 CVE-2015-1433: program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, w
program/lib/Roundcube/rcube_washtml.php in Roundcube before 1.0.5 does not properly quote strings, which allows remote attackers to conduct cross-site scripting (XSS) attacks via the style attribute in an email.
nvd
CVE-2020-8698P4MEDIUMCVSS 5.5v312020-11-12
CVE-2020-8698 [MEDIUM] CWE-668 CVE-2020-8698: Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user t
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2020-2761P4MEDIUMCVSS 4.9v30v31+1 more2020-04-15
CVE-2020-2761 [MEDIUM] CVE-2020-2761: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2020-2770P4MEDIUMCVSS 4.9v30v31+1 more2020-04-15
CVE-2020-2770 [MEDIUM] CVE-2020-2770: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Logging). Supported versions that are affected are 8.0.18 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2021-2146P4MEDIUMCVSS 4.9v32v33+1 more2021-04-22
CVE-2021-2146 [MEDIUM] CVE-2021-2146: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in un
nvd
CVE-2022-21253P4MEDIUMCVSS 4.9v34v352022-01-19
CVE-2022-21253 [MEDIUM] CVE-2022-21253: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2020-15306P4MEDIUMCVSS 5.5v31v322020-06-26
CVE-2020-15306 [MEDIUM] CWE-787 CVE-2020-15306: An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap b
An issue was discovered in OpenEXR before v2.5.2. Invalid chunkCount attributes could cause a heap buffer overflow in getChunkOffsetTableSize() in IlmImf/ImfMisc.cpp.
nvd
CVE-2020-8696P4MEDIUMCVSS 5.5v312020-11-12
CVE-2020-8696 [MEDIUM] CWE-212 CVE-2020-8696: Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
nvd
CVE-2020-25652P4MEDIUMCVSS 5.5v32v332020-11-26
CVE-2020-25652 [MEDIUM] CWE-770 CVE-2020-25652: A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections t
A flaw was found in the spice-vdagentd daemon, where it did not properly handle client connections that can be established via the UNIX domain socket in `/run/spice-vdagentd/spice-vdagent-sock`. Any unprivileged local guest user could use this flaw to prevent legitimate agents from connecting to the spice-vdagentd daemon, resulting in a denial of se
nvd
CVE-2020-25600P4MEDIUMCVSS 5.5v31v32+1 more2020-09-23
CVE-2020-25600 [MEDIUM] CWE-787 CVE-2020-25600: An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit
An issue was discovered in Xen through 4.14.x. Out of bounds event channels are available to 32-bit x86 domains. The so called 2-level event channel model imposes different limits on the number of usable event channels for 32-bit x86 domains vs 64-bit or Arm (either bitness) ones. 32-bit x86 domains can use only 1023 channels, due to limited space in
nvd
CVE-2020-25601P4MEDIUMCVSS 5.5v31v32+1 more2020-09-23
CVE-2020-25601 [MEDIUM] CVE-2020-25601: An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evt
An issue was discovered in Xen through 4.14.x. There is a lack of preemption in evtchn_reset() / evtchn_destroy(). In particular, the FIFO event channel model allows guests to have a large number of event channels active at a time. Closing all of these (when resetting all event channels or when cleaning up after the guest) may take extended periods of time.
nvd