Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 228 of 264
CVE-2022-21534P4MEDIUMCVSS 4.9v352022-07-19
CVE-2022-21534 [MEDIUM] CVE-2022-21534: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Sup
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.29 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2021-42374P4MEDIUMCVSS 5.3v33v342021-11-15
CVE-2021-42374 [MEDIUM] CWE-125 CVE-2021-42374: An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of servic
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
nvd
CVE-2015-1838P4MEDIUMCVSS 5.3v232017-04-13
CVE-2015-1838 [MEDIUM] CWE-19 CVE-2015-1838: modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
nvd
CVE-2015-1839P4MEDIUMCVSS 5.3v232017-04-13
CVE-2015-1839 [MEDIUM] CWE-19 CVE-2015-1839: modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
nvd
CVE-2020-5267P4MEDIUMCVSS 4.8v332020-03-19
CVE-2020-5267 [MEDIUM] CWE-80 CVE-2020-5267: In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionVi
In ActionView before versions 6.0.2.2 and 5.2.4.2, there is a possible XSS vulnerability in ActionView's JavaScript literal escape helpers. Views that use the `j` or `escape_javascript` methods may be susceptible to XSS attacks. The issue is fixed in versions 6.0.2.2 and 5.2.4.2.
nvd
CVE-2015-6938P4MEDIUMCVSS 4.3v21v22+1 more2015-09-21
CVE-2015-6938 [MEDIUM] CWE-79 CVE-2015-6938: Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython N
Cross-site scripting (XSS) vulnerability in the file browser in notebook/notebookapp.py in IPython Notebook before 3.2.2 and Jupyter Notebook 4.0.x before 4.0.5 allows remote attackers to inject arbitrary web script or HTML via a folder name. NOTE: this was originally reported as a cross-site request forgery (CSRF) vulnerability, but this may be inaccu
nvd
CVE-2019-5779P4MEDIUMCVSS 4.3v29v302019-02-19
CVE-2019-5779 [MEDIUM] CWE-862 CVE-2019-5779: Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a rem
Insufficient policy validation in ServiceWorker in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2020-25684P4LOWCVSS 3.7v32v332021-01-20
CVE-2020-25684 [LOW] CWE-358 CVE-2020-25684: A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmas
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in the forward.c:reply_query() if the reply destination address/port is used by the pending forwarded queries. However, it does not use the address/port to retrieve the exact forwarded query, substantially reducing the number of attempts an atta
nvd
CVE-2023-40551P4MEDIUMCVSS 5.1v392024-01-29
CVE-2023-40551 [MEDIUM] CWE-125 CVE-2023-40551: A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a cras
A flaw was found in the MZ binary format in Shim. An out-of-bounds read may occur, leading to a crash or possible exposure of sensitive data during the system's boot phase.
nvd
CVE-2013-5614P4MEDIUMCVSS 4.3v19v202013-12-11
CVE-2013-5614 [MEDIUM] CWE-1021 CVE-2013-5614: Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute
Mozilla Firefox before 26.0 and SeaMonkey before 2.23 do not properly consider the sandbox attribute of an IFRAME element during processing of a contained OBJECT element, which allows remote attackers to bypass intended sandbox restrictions via a crafted web site.
nvd
CVE-2020-8284P4LOWCVSS 3.7v32v332020-12-14
CVE-2020-8284 [LOW] CWE-200 CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting ba
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
nvd
CVE-2014-1573P4MEDIUMCVSS 4.3v19v20+1 more2014-10-13
CVE-2014-1573 [MEDIUM] CWE-79 CVE-2014-1573: Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 does not ensure that a scalar context is used for certain CGI parameters, which allows remote attackers to conduct cross-site scripting (XSS) attacks by sending three values for a single parameter name.
nvd
CVE-2015-4830P4MEDIUMCVSS 4.0v232015-10-21
CVE-2015-4830 [MEDIUM] CVE-2015-4830: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
nvd
CVE-2020-4032P4MEDIUMCVSS 4.3v31v322020-06-22
CVE-2020-4032 [MEDIUM] CWE-681 CVE-2020-4032: In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_
In FreeRDP before version 2.1.2, there is an integer casting vulnerability in update_recv_secondary_order. All clients with +glyph-cache /relax-order-checks are affected. This is fixed in version 2.1.2.
nvd
CVE-2020-29130P4MEDIUMCVSS 4.3v32v332020-11-26
CVE-2020-29130 [MEDIUM] CWE-125 CVE-2020-29130: slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount o
slirp.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
nvd
CVE-2019-18660P4MEDIUMCVSS 4.7v30v312019-11-27
CVE-2019-18660 [MEDIUM] CWE-200 CVE-2019-18660: The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigat
The Linux kernel before 5.4.1 on powerpc allows Information Exposure because the Spectre-RSB mitigation is not in place for all applicable CPUs, aka CID-39e72bf96f58. This is related to arch/powerpc/kernel/entry_64.S and arch/powerpc/kernel/security.c.
nvd
CVE-2020-6437P4MEDIUMCVSS 4.3v30v31+1 more2020-04-13
CVE-2020-6437 [MEDIUM] CVE-2020-6437: Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote atta
Inappropriate implementation in WebView in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to spoof security UI via a crafted application.
nvd
CVE-2020-27170P4MEDIUMCVSS 4.7v32v33+1 more2021-03-20
CVE-2020-27170 [MEDIUM] CWE-203 CVE-2020-27170: An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirabl
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c performs undesirable out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-f232326f6966. This affects pointer types that do not define a ptr_limit.
nvd
CVE-2020-6527P4MEDIUMCVSS 4.3v31v322020-07-22
CVE-2020-6527 [MEDIUM] CWE-276 CVE-2020-6527: Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attac
Insufficient policy enforcement in CSP in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2021-30589P4MEDIUMCVSS 4.3v33v34+1 more2021-08-03
CVE-2021-30589 [MEDIUM] CWE-20 CVE-2021-30589: Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowe
Insufficient validation of untrusted input in Sharing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to bypass navigation restrictions via a crafted click-to-call link.
nvd