Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 227 of 264
CVE-2019-2957P4MEDIUMCVSS 4.9v29v30+1 more2019-10-16
CVE-2019-2957 [MEDIUM] CVE-2019-2957: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2023-0160P4MEDIUMCVSS 5.5v382023-07-18
CVE-2023-0160 [MEDIUM] CWE-833 CVE-2023-0160: A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to pote
A deadlock flaw was found in the Linux kernel’s BPF subsystem. This flaw allows a local user to potentially crash the system.
nvd
CVE-2021-29648P4MEDIUMCVSS 5.5v32v33+1 more2021-03-30
CVE-2021-29648 [MEDIUM] CWE-307 CVE-2021-29648: An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly cons
An issue was discovered in the Linux kernel before 5.11.11. The BPF subsystem does not properly consider that resolved_ids and resolved_sizes are intentionally uninitialized in the vmlinux BPF Type Format (BTF), which can cause a system crash upon an unexpected access attempt (in map_create in kernel/bpf/syscall.c or check_btf_info in kernel/bpf/ver
nvd
CVE-2024-27001P4MEDIUMCVSS 5.5v38v39+1 more2024-05-01
CVE-2024-27001 [MEDIUM] CVE-2024-27001: In the Linux kernel, the following vulnerability has been resolved: comedi: vmk80xx: fix incomplete
In the Linux kernel, the following vulnerability has been resolved:
comedi: vmk80xx: fix incomplete endpoint checking
While vmk80xx does have endpoint checking implemented, some things
can fall through the cracks. Depending on the hardware model,
URBs can have either bulk or interrupt type, and current version
of vmk80xx_find_usb_endpoints() function does
nvd
CVE-2022-42325P4MEDIUMCVSS 5.5v35v36+1 more2022-11-01
CVE-2022-42325 [MEDIUM] CWE-401 CVE-2022-42325: Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record
Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction and it is later deleted in the same transaction, the transaction will be terminated with an error. As t
nvd
CVE-2022-42326P4MEDIUMCVSS 5.5v35v36+1 more2022-11-01
CVE-2022-42326 [MEDIUM] CWE-401 CVE-2022-42326: Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record
Xenstore: Guests can create arbitrary number of nodes via transactions T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] In case a node has been created in a transaction and it is later deleted in the same transaction, the transaction will be terminated with an error. As t
nvd
CVE-2022-42310P4MEDIUMCVSS 5.5v35v36+1 more2022-11-01
CVE-2022-42310 [MEDIUM] CWE-459 CVE-2022-42310: Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction
Xenstore: Guests can create orphaned Xenstore nodes By creating multiple nodes inside a transaction resulting in an error, a malicious guest can create orphaned nodes in the Xenstore data base, as the cleanup after the error will not remove all nodes already created. When the transaction is committed after this situation, nodes without a valid parent
nvd
CVE-2022-21304P4MEDIUMCVSS 4.9v34v352022-01-19
CVE-2022-21304 [MEDIUM] CVE-2022-21304: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in u
nvd
CVE-2022-21303P4MEDIUMCVSS 4.9v34v352022-01-19
CVE-2022-21303 [MEDIUM] CVE-2022-21303: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Sup
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2024-0443P4MEDIUMCVSS 5.5v392024-01-12
CVE-2024-0443 [MEDIUM] CWE-402 CVE-2024-0443: A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to
A flaw was found in the blkgs destruction path in block/blk-cgroup.c in the Linux kernel, leading to a cgroup blkio memory leakage problem. When a cgroup is being destroyed, cgroup_rstat_flush() is only called at css_release_work_fn(), which is called when the blkcg reference count reaches 0. This circular dependency will prevent blkcg and some blkgs
nvd
CVE-2014-1527P4MEDIUMCVSS 5.0v192014-04-30
CVE-2014-1527 [MEDIUM] CVE-2014-1527: Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted
Mozilla Firefox before 29.0 on Android allows remote attackers to spoof the address bar via crafted JavaScript code that uses DOM events to prevent the reemergence of the actual address bar after scrolling has taken it off of the screen.
nvd
CVE-2023-40032P4MEDIUMCVSS 5.5v392023-09-11
CVE-2023-40032 [MEDIUM] CWE-476 CVE-2023-40032: libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG
libvips is a demand-driven, horizontally threaded image processing library. A specially crafted SVG input can cause libvips versions 8.14.3 or earlier to segfault when attempting to parse a malformed UTF-8 character. Users should upgrade to libvips version 8.14.4 (or later) when processing untrusted input.
nvd
CVE-2024-27004P4MEDIUMCVSS 5.5v38v39+1 more2024-05-01
CVE-2024-27004 [MEDIUM] CWE-667 CVE-2024-27004: In the Linux kernel, the following vulnerability has been resolved: clk: Get runtime PM before walk
In the Linux kernel, the following vulnerability has been resolved:
clk: Get runtime PM before walking tree during disable_unused
Doug reported [1] the following hung task:
INFO: task swapper/0:1 blocked for more than 122 seconds.
Not tainted 5.15.149-21875-gf795ebc40eb8 #1
"echo 0 > /proc/sys/kernel/hung_task_timeout_secs" disables this message.
nvd
CVE-2023-4134P4MEDIUMCVSS 5.5v382024-11-14
CVE-2023-4134 [MEDIUM] CWE-416 CVE-2023-4134: A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue
A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could allow a local user to crash the system, causing a denial of service.
nvd
CVE-2022-21515P4MEDIUMCVSS 4.9v35v362022-07-19
CVE-2022-21515 [MEDIUM] CVE-2022-21515: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported ve
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 5.7.38 and prior and 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in
nvd
CVE-2022-21525P4MEDIUMCVSS 4.9v35v362022-07-19
CVE-2022-21525 [MEDIUM] CVE-2022-21525: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2022-21517P4MEDIUMCVSS 4.9v35v362022-07-19
CVE-2022-21517 [MEDIUM] CVE-2022-21517: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause
nvd
CVE-2015-4858P4MEDIUMCVSS 4.0v232015-10-21
CVE-2015-4858 [MEDIUM] CVE-2015-4858: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via vectors related to DML, a different vulnerability than CVE-2015-4913.
nvd
CVE-2022-21531P4MEDIUMCVSS 4.9v35v362022-07-19
CVE-2022-21531 [MEDIUM] CVE-2022-21531: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2022-21530P4MEDIUMCVSS 4.9v35v362022-07-19
CVE-2022-21530 [MEDIUM] CVE-2022-21530: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability
nvd