cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 226 of 264
CVE-2021-3308P4MEDIUMCVSS 5.5v322021-01-26
CVE-2021-3308 [MEDIUM] CVE-2021-3308: An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest wit An issue was discovered in Xen 4.12.3 through 4.12.4 and 4.13.1 through 4.14.x. An x86 HVM guest with PCI pass through devices can force the allocation of all IDT vectors on the system by rebooting itself with MSI or MSI-X capabilities enabled and entries setup. Such reboots will leak any vectors used by the MSI(-X) entries that the guest might had enabled, a
nvd
CVE-2020-8695P4MEDIUMCVSS 5.5v31v32+1 more2020-11-12
CVE-2020-8695 [MEDIUM] CWE-203 CVE-2020-8695: Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged use Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2022-1615P4MEDIUMCVSS 5.5v372022-09-01
CVE-2022-1615 [MEDIUM] CWE-330 CVE-2022-1615: In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values. In Samba, GnuTLS gnutls_rnd() can fail and give predictable random values.
nvd
CVE-2015-4802P4MEDIUMCVSS 4.0v232015-10-21
CVE-2015-4802 [MEDIUM] CVE-2015-4802: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4792.
nvd
CVE-2023-42754P4MEDIUMCVSS 5.5v37v38+1 more2023-10-05
CVE-2023-42754 [MEDIUM] CWE-476 CVE-2023-42754: A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) wa A NULL pointer dereference flaw was found in the Linux kernel ipv4 stack. The socket buffer (skb) was assumed to be associated with a device before calling __ip_options_compile, which is not always the case if the skb is re-routed by ipvs. This issue may allow a local user with CAP_NET_ADMIN privileges to crash the system.
nvd
CVE-2019-1020014P4MEDIUMCVSS 5.5v322019-07-29
CVE-2019-1020014 [MEDIUM] CWE-415 CVE-2019-1020014: docker-credential-helpers before 0.6.3 has a double free in the List functions. docker-credential-helpers before 0.6.3 has a double free in the List functions.
nvd
CVE-2010-4178P4MEDIUMCVSS 5.5v122019-11-06
CVE-2010-4178 [MEDIUM] CWE-522 CVE-2010-4178: MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql t MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
nvd
CVE-2020-29485P4MEDIUMCVSS 5.5v32v332020-12-15
CVE-2020-29485 [MEDIUM] CWE-401 CVE-2020-29485: An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request An issue was discovered in Xen 4.6 through 4.14.x. When acting upon a guest XS_RESET_WATCHES request, not all tracking information is freed. A guest can cause unbounded memory usage in oxenstored. This can lead to a system-wide DoS. Only systems using the Ocaml Xenstored implementation are vulnerable. Systems using the C Xenstored implementation are
nvd
CVE-2021-42375P4MEDIUMCVSS 5.5v33v342021-11-15
CVE-2021-42375 [MEDIUM] CWE-159 CVE-2021-42375: An incorrect handling of a special element in Busybox's ash applet leads to denial of service when p An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
nvd
CVE-2022-21270P4MEDIUMCVSS 4.9v34v352022-01-19
CVE-2022-21270 [MEDIUM] CVE-2022-21270: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Federated). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Federated). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2021-28699P4MEDIUMCVSS 5.5v33v34+1 more2021-08-27
CVE-2021-28699 [MEDIUM] CVE-2021-28699: inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant at inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant status. That is, when operating in this mode, a guest has two tables. As a result, guests also need to be able to retrieve the addresses that the new status tracking table can be accessed through. For 32-bit guests on x86, translation of r
nvd
CVE-2021-26932P4MEDIUMCVSS 5.5v32v332021-02-17
CVE-2021-26932 [MEDIUM] CVE-2021-26932: An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping opera An issue was discovered in the Linux kernel 3.2 through 5.10.16, as used by Xen. Grant mapping operations often occur in batch hypercalls, where a number of operations are done in a single hypercall, the success or failure of each one is reported to the backend driver, and the backend driver then loops over the results, performing follow-up actions based on
nvd
CVE-2021-43056P4MEDIUMCVSS 5.5v33v34+1 more2021-10-28
CVE-2021-43056 [MEDIUM] CVE-2021-43056: An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM gu An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation bug in the handling of the SRR1 register values.
nvd
CVE-2013-6672P4MEDIUMCVSS 4.3v19v202013-12-11
CVE-2013-6672 [MEDIUM] CWE-200 CVE-2013-6672: Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers Mozilla Firefox before 26.0 and SeaMonkey before 2.23 on Linux allow user-assisted remote attackers to read clipboard data by leveraging certain middle-click paste operations.
nvd
CVE-2012-5474P4MEDIUMCVSS 5.5v182019-12-30
CVE-2012-5474 [MEDIUM] CWE-311 CVE-2012-5474: The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Esse The file /etc/openstack-dashboard/local_settings within Red Hat OpenStack Platform 2.0 and RHOS Essex Release (python-django-horizon package before 2012.1.1) is world readable and exposes the secret key value.
nvd
CVE-2010-4177P4MEDIUMCVSS 5.5v122019-11-12
CVE-2010-4177 [MEDIUM] CWE-319 CVE-2010-4177: mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the passwor mysql-gui-tools (mysql-query-browser and mysql-admin) before 5.0r14+openSUSE-2.3 exposes the password of a user connected to the MySQL server in clear text form via the list of running processes.
nvd
CVE-2021-29646P4MEDIUMCVSS 5.5v32v33+1 more2021-03-30
CVE-2021-29646 [MEDIUM] CVE-2021-29646: An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c An issue was discovered in the Linux kernel before 5.11.11. tipc_nl_retrieve_key in net/tipc/node.c does not properly validate certain data sizes, aka CID-0217ed2848e8.
nvd
CVE-2022-2867P4MEDIUMCVSS 5.5v35v362022-08-17
CVE-2022-2867 [MEDIUM] CWE-191 CVE-2022-2867: libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. A libtiff's tiffcrop utility has a uint32_t underflow that can lead to out of bounds read and write. An attacker who supplies a crafted file to tiffcrop (likely via tricking a user to run tiffcrop on it with certain parameters) could cause a crash or in some cases, further exploitation.
nvd
CVE-2024-27399P4MEDIUMCVSS 5.5v39v402024-05-14
CVE-2024-27399 [MEDIUM] CWE-476 CVE-2024-27399: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr- In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout There is a race condition between l2cap_chan_timeout() and l2cap_chan_del(). When we use l2cap_chan_del() to delete the channel, the chan->conn will be set to null. But the conn could be dereferenced again in the mutex_lock
nvd
CVE-2022-0322P4MEDIUMCVSS 5.5v352022-03-25
CVE-2022-0322 [MEDIUM] CWE-681 CVE-2022-0322: A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP netw A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).
nvd
Fedoraproject Fedora vulnerabilities | cvebase