Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 23 of 264
CVE-2020-28374P3HIGHCVSS 8.1v32v332021-01-13
CVE-2020-28374 [HIGH] CWE-22 CVE-2020-28374: In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier che
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The a
nvd
CVE-2024-32458P3CRITICALCVSS 9.8v38v39+1 more2024-04-22
CVE-2024-32458 [CRITICAL] CWE-125 CVE-2024-32458: FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a ve
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support).
nvd
CVE-2024-32460P3CRITICALCVSS 9.8v38v39+1 more2024-04-22
CVE-2024-32460 [CRITICAL] CWE-125 CVE-2024-32460: FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `
FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI` drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use modern drawing paths (e.g. `/rfx` or `/gfx` options). The wor
nvd
CVE-2019-14895P3CRITICALCVSS 9.8v30v312019-11-29
CVE-2019-14895 [CRITICAL] CWE-122 CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash)
nvd
CVE-2021-32625P3HIGHCVSS 8.8v33v342021-06-02
CVE-2021-32625 [HIGH] CVE-2021-32625: Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, a
Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer, could be exploited using the STRALGO LCS command to corrupt the heap and potentially result with remote code execution. This is a result of an incomplete fix by CVE-2021-29477. The proble
nvd
CVE-2024-0223P3HIGHCVSS 8.8v38v392024-01-04
CVE-2024-0223 [HIGH] CWE-787 CVE-2024-0223: Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to
Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-27135P3CRITICALCVSS 9.8v332021-02-10
CVE-2021-27135 [CRITICAL] CVE-2021-27135: xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of servi
xterm before Patch #366 allows remote attackers to execute arbitrary code or cause a denial of service (segmentation fault) via a crafted UTF-8 combining character sequence.
nvd
CVE-2023-5550P3CRITICALCVSS 9.8v382023-11-09
CVE-2023-5550 [CRITICAL] CWE-94 CVE-2023-5550: In a shared hosting environment that has been misconfigured to allow access to other users' content,
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
nvd
CVE-2021-41524P3HIGHCVSS 7.5v34v352021-10-05
CVE-2021-41524 [HIGH] CWE-476 CVE-2021-41524: While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request pr
While fuzzing the 2.4.49 httpd, a new null pointer dereference was detected during HTTP/2 request processing, allowing an external source to DoS the server. This requires a specially crafted request. The vulnerability was recently introduced in version 2.4.49. No exploit is known to the project.
nvd
CVE-2023-40186P3CRITICALCVSS 9.8v37v38+1 more2023-08-31
CVE-2023-40186 [CRITICAL] CWE-190 CVE-2023-40186: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an IntegerOverflow leading to Out-Of-Bound Write Vulnerability in the `gdi_CreateSurface` function. This issue affects FreeRDP based clients only. FreeRDP proxies are not affected as image decoding is not done
nvd
CVE-2019-13767P3HIGHCVSS 8.8v302020-01-10
CVE-2019-13767 [HIGH] CWE-416 CVE-2019-13767: Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who
Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-46175P3HIGHCVSS 8.8v372022-12-24
CVE-2022-46175 [HIGH] CWE-1321 CVE-2022-46175: JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain b
JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing specially crafted strings to pollute the prototype of the resulting obje
nvd
CVE-2020-15094P3HIGHCVSS 8.8v32v332020-09-02
CVE-2020-15094 [HIGH] CWE-212 CVE-2020-15094: In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony
In Symfony before versions 4.4.13 and 5.1.5, the CachingHttpClient class from the HttpClient Symfony component relies on the HttpCache class to handle requests. HttpCache uses internal headers like X-Body-Eval and X-Body-File to control the restoration of cached responses. The class was initially written with surrogate caching and ESI support in mind
nvd
CVE-2021-3570P2HIGHCVSS 8.8v33v342021-07-09
CVE-2021-3570 [HIGH] CWE-119 CVE-2021-3570: A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwardin
A flaw was found in the ptp4l program of the linuxptp package. A missing length check when forwarding a PTP message between ports allows a remote attacker to cause an information leak, crash, or potentially remote code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability. This flaw
nvd
CVE-2014-4172P3CRITICALCVSS 9.8v202020-01-24
CVE-2014-4172 [CRITICAL] CWE-74 CVE-2014-4172: A URL parameter injection vulnerability was found in the back-channel ticket validation step of the
A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via the (1) service parameter to validation/AbstractUrlBasedTicketValidator.java
nvd
CVE-2022-46340P3HIGHCVSS 8.8v36v372022-12-14
CVE-2022-46340 [HIGH] CWE-787 CVE-2022-46340: A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTest
A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead to local privileges elevation on systems where the X server is running p
nvd
CVE-2019-0217P3HIGHCVSS 7.5v28v29+1 more2019-04-08
CVE-2019-0217 [HIGH] CWE-362 CVE-2019-0217: In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running
In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions.
nvd
CVE-2022-46343P3HIGHCVSS 8.8v36v372022-12-14
CVE-2022-46343 [HIGH] CWE-416 CVE-2022-46343: A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSave
A vulnerability was found in X.Org. This security flaw occurs because the handler for the ScreenSaverSetAttributes request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
nvd
CVE-2017-18342P3CRITICALCVSS 9.8v28v29+1 more2018-06-27
CVE-2017-18342 [CRITICAL] CWE-502 CVE-2017-18342: In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data.
In PyYAML before 5.1, the yaml.load() API could execute arbitrary code if used with untrusted data. The load() function has been deprecated in version 5.1 and the 'UnsafeLoader' has been introduced for backward compatibility with the function.
nvd
CVE-2022-45152P3CRITICALCVSS 9.1v35v36+1 more2022-11-25
CVE-2022-45152 [CRITICAL] CWE-918 CVE-2022-45152: A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due t
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application
nvd