Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 229 of 264
CVE-2022-21245P4MEDIUMCVSS 4.3v34v352022-01-19
CVE-2022-21245 [MEDIUM] CVE-2022-21245: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability ca
nvd
CVE-2020-1740P4MEDIUMCVSS 4.7v30v31+1 more2020-03-16
CVE-2020-1740 [MEDIUM] CWE-377 CVE-2020-1740: A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user
A flaw was found in Ansible Engine when using Ansible Vault for editing encrypted files. When a user executes "ansible-vault edit", another user on the same computer can read the old and new secret, as it is created in a temporary file with mkstemp and the returned file descriptor is closed and the method write_data is called to write the existing sec
nvd
CVE-2019-5839P4MEDIUMCVSS 4.3v29v302019-06-27
CVE-2019-5839 [MEDIUM] CWE-20 CVE-2019-5839: Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote atta
Excessive data validation in URL parser in Google Chrome prior to 75.0.3770.80 allowed a remote attacker who convinced a user to input a URL to bypass website URL validation via a crafted URL.
nvd
CVE-2021-30152P4MEDIUMCVSS 4.3v33v342021-04-09
CVE-2021-30152 [MEDIUM] CWE-269 CVE-2021-30152: An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When us
An issue was discovered in MediaWiki before 1.31.13 and 1.32.x through 1.35.x before 1.35.2. When using the MediaWiki API to "protect" a page, a user is currently able to protect to a higher level than they currently have permissions for.
nvd
CVE-2013-1930P4MEDIUMCVSS 4.3v17v182019-10-31
CVE-2013-1930 [MEDIUM] CWE-20 CVE-2013-1930: MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close is
MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.
nvd
CVE-2021-30155P4MEDIUMCVSS 4.3v33v342021-04-09
CVE-2021-30155 [MEDIUM] CWE-862 CVE-2021-30155: An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. Content
An issue was discovered in MediaWiki before 1.31.12 and 1.32.x through 1.35.x before 1.35.2. ContentModelChange does not check if a user has correct permissions to create and set the content model of a nonexistent page.
nvd
CVE-2009-0314P4MEDIUMCVSS 6.9v92009-01-28
CVE-2009-0314 [MEDIUM] CVE-2009-0314: Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbi
Untrusted search path vulnerability in the Python module in gedit allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983).
nvd
CVE-2020-9497P4MEDIUMCVSS 4.4v32v332020-07-02
CVE-2020-9497 [MEDIUM] CWE-20 CVE-2020-9497: Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static v
Apache Guacamole 1.1.0 and older do not properly validate datareceived from RDP servers via static virtual channels. If a userconnects to a malicious or compromised RDP server, specially-craftedPDUs could result in disclosure of information within the memory ofthe guacd process handling the connection.
nvd
CVE-2008-5983P4MEDIUMCVSS 6.9v132009-01-28
CVE-2008-5983 [MEDIUM] CWE-426 CVE-2008-5983: Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and
Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory.
nvd
CVE-2023-22945P4MEDIUMCVSS 4.3v372023-01-11
CVE-2023-22945 [MEDIUM] CWE-863 CVE-2023-22945: In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows
In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.
nvd
CVE-2016-8884P4MEDIUMCVSS 5.5v23v242017-03-28
CVE-2016-8884 [MEDIUM] CVE-2016-8884: The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cau
The bmp_getdata function in libjasper/bmp/bmp_dec.c in JasPer 1.900.5 allows remote attackers to cause a denial of service (NULL pointer dereference) by calling the imginfo command with a crafted BMP image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8690.
nvd
CVE-2015-5221P4MEDIUMCVSS 5.5v23v24+1 more2017-07-25
CVE-2015-5221 [MEDIUM] CWE-416 CVE-2015-5221: Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasP
Use-after-free vulnerability in the mif_process_cmpt function in libjasper/mif/mif_cod.c in the JasPer JPEG-2000 library before 1.900.2 allows remote attackers to cause a denial of service (crash) via a crafted JPEG 2000 image file.
nvd
CVE-2014-6568P4LOWCVSS 3.5v202015-01-21
CVE-2014-6568 [LOW] CVE-2014-6568: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote authenticated users to affect availability via vectors related to Server : InnoDB : DML.
nvd
CVE-2020-29570P4MEDIUMCVSS 6.2v32v332020-12-15
CVE-2020-29570 [MEDIUM] CWE-770 CVE-2020-29570: An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maint
An issue was discovered in Xen through 4.14.x. Recording of the per-vCPU control block mapping maintained by Xen and that of pointers into the control block is reversed. The consumer assumes, seeing the former initialized, that the latter are also ready for use. Malicious or buggy guest kernels can mount a Denial of Service (DoS) attack affecting th
nvd
CVE-2016-8569P4MEDIUMCVSS 5.5v23v24+1 more2017-02-03
CVE-2016-8569 [MEDIUM] CWE-476 CVE-2016-8569: The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a de
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
nvd
CVE-2019-15143P4MEDIUMCVSS 5.5v29v30+1 more2019-08-18
CVE-2019-15143 [MEDIUM] CWE-835 CVE-2019-15143: In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error
In DjVuLibre 3.5.27, the bitmap reader component allows attackers to cause a denial-of-service error (resource exhaustion caused by a GBitmap::read_rle_raw infinite loop) by crafting a corrupted image file, related to libdjvu/DjVmDir.cpp and libdjvu/GBitmap.cpp.
nvd
CVE-2020-11765P4MEDIUMCVSS 5.5v322020-04-14
CVE-2020-11765 [MEDIUM] CWE-125 CVE-2020-11765: An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h
An issue was discovered in OpenEXR before 2.4.1. There is an off-by-one error in use of the ImfXdr.h read function by DwaCompressor::Classifier::Classifier, leading to an out-of-bounds read.
nvd
CVE-2015-7218P4MEDIUMCVSS 5.0v22v232015-12-16
CVE-2015-7218 [MEDIUM] CWE-189 CVE-2015-7218: The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial o
The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.
nvd
CVE-2021-27919P4MEDIUMCVSS 5.5v34v352021-03-11
CVE-2021-27919 [MEDIUM] CVE-2021-27919: archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon at
archive/zip in Go 1.16.x before 1.16.1 allows attackers to cause a denial of service (panic) upon attempted use of the Reader.Open API for a ZIP archive in which ../ occurs at the beginning of any filename.
nvd
CVE-2019-1010319P4MEDIUMCVSS 5.5v29v30+1 more2019-07-11
CVE-2019-1010319 [MEDIUM] CWE-457 CVE-2019-1010319: WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Une
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseWave64HeaderConfig (wave64.c:211). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/33a0025d1d63ccd0
nvd