Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 230 of 264
CVE-2018-20592P4MEDIUMCVSS 5.5v28v292018-12-30
CVE-2018-20592 [MEDIUM] CWE-416 CVE-2018-20592: In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c f
In Mini-XML (aka mxml) v2.12, there is a use-after-free in the mxmlAdd function of the mxml-node.c file. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted xml file, as demonstrated by mxmldoc.
nvd
CVE-2015-7555P4MEDIUMCVSS 5.5v222016-04-13
CVE-2015-7555 [MEDIUM] CWE-119 CVE-2015-7555: Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial
Heap-based buffer overflow in giffix.c in giffix in giflib 5.1.1 allows attackers to cause a denial of service (program crash) via crafted image and logical screen width fields in a GIF file.
nvd
CVE-2016-6153P4MEDIUMCVSS 5.9v242016-09-26
CVE-2016-6153 [MEDIUM] CWE-20 CVE-2016-6153: os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, wh
os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging use of the current working directory for temporary files.
nvd
CVE-2019-1010317P4MEDIUMCVSS 5.5v29v30+1 more2019-07-11
CVE-2019-1010317 [MEDIUM] CWE-457 CVE-2019-1010317: WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Une
WavPack 5.1.0 and earlier is affected by: CWE-457: Use of Uninitialized Variable. The impact is: Unexpected control flow, crashes, and segfaults. The component is: ParseCaffHeaderConfig (caff.c:486). The attack vector is: Maliciously crafted .wav file. The fixed version is: After commit https://github.com/dbry/WavPack/commit/f68a9555b548306c5b1e
nvd
CVE-2020-10994P4MEDIUMCVSS 5.5v31v322020-06-25
CVE-2020-10994 [MEDIUM] CWE-125 CVE-2020-10994: In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a cr
In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there are multiple out-of-bounds reads via a crafted JP2 file.
nvd
CVE-2020-3810P4MEDIUMCVSS 5.5v322020-05-15
CVE-2020-3810 [MEDIUM] CWE-20 CVE-2020-3810: Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in d
Missing input validation in the ar/tar implementations of APT before version 2.1.2 could result in denial of service when processing specially crafted deb files.
nvd
CVE-2021-42715P4MEDIUMCVSS 5.5v33v34+1 more2021-10-21
CVE-2021-42715 [MEDIUM] CWE-835 CVE-2021-42715: An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted HDR files.
nvd
CVE-2019-18849P4MEDIUMCVSS 5.5v30v312019-11-11
CVE-2019-18849 [MEDIUM] CWE-125 CVE-2019-18849: In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file vi
In tnef before 1.4.18, an attacker may be able to write to the victim's .ssh/authorized_keys file via an e-mail message with a crafted winmail.dat application/ms-tnef attachment, because of a heap-based buffer over-read involving strdup.
nvd
CVE-2021-32617P4MEDIUMCVSS 5.5v33v342021-05-17
CVE-2021-32617 [MEDIUM] CWE-400 CVE-2021-32617: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An inefficient algorithm (quadratic complexity) was found in Exiv2 versions v0.27.3 and earlier. The inefficient algorithm is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentiall
nvd
CVE-2021-32613P4MEDIUMCVSS 5.5v33v342021-05-14
CVE-2021-32613 [MEDIUM] CWE-416 CVE-2021-32613: In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file wh
In radare2 through 5.3.0 there is a double free vulnerability in the pyc parse via a crafted file which can lead to DoS.
nvd
CVE-2008-3969P4MEDIUMCVSS 5.0v82008-09-11
CVE-2008-3969 [MEDIUM] CVE-2008-3969: Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" a
Multiple unspecified vulnerabilities in BitlBee before 1.2.3 allow remote attackers to "overwrite" and "hijack" existing accounts via unknown vectors related to "inconsistent handling of the USTATUS_IDENTIFIED state." NOTE: this issue exists because of an incomplete fix for CVE-2008-3920.
nvd
CVE-2021-23215P4MEDIUMCVSS 5.5v332021-06-08
CVE-2021-23215 [MEDIUM] CWE-400 CVE-2021-23215: An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in v
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR.
nvd
CVE-2021-44269P4MEDIUMCVSS 5.5v34v35+1 more2022-03-10
CVE-2021-44269 [MEDIUM] CWE-125 CVE-2021-44269: An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in
An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.
nvd
CVE-2020-35493P4MEDIUMCVSS 5.5v322021-01-04
CVE-2020-35493 [MEDIUM] CWE-20 CVE-2020-35493: A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be p
A flaw exists in binutils in bfd/pef.c. An attacker who is able to submit a crafted PEF file to be parsed by objdump could cause a heap buffer overflow -> out-of-bounds read that could lead to an impact to application availability. This flaw affects binutils versions prior to 2.34.
nvd
CVE-2021-29463P4MEDIUMCVSS 5.5v33v342021-04-30
CVE-2021-29463 [MEDIUM] CWE-125 CVE-2021-29463: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability t
nvd
CVE-2021-37622P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-37622 [MEDIUM] CWE-835 CVE-2021-37622: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause
nvd
CVE-2022-1122P4MEDIUMCVSS 5.5v34v35+1 more2022-03-29
CVE-2022-1122 [MEDIUM] CWE-665 CVE-2022-1122: A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input di
A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a segmentation fault and a denial of service.
nvd
CVE-2021-26260P4MEDIUMCVSS 5.5v332021-06-08
CVE-2021-26260 [MEDIUM] CVE-2021-26260: An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in v
An integer overflow leading to a heap-buffer overflow was found in the DwaCompressor of OpenEXR in versions before 3.0.1. An attacker could use this flaw to crash an application compiled with OpenEXR. This is a different flaw from CVE-2021-23215.
nvd
CVE-2022-31783P4MEDIUMCVSS 5.5v362022-06-02
CVE-2022-31783 [MEDIUM] CWE-787 CVE-2022-31783: Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstra
Liblouis 3.21.0 has an out-of-bounds write in compileRule in compileTranslationTable.c, as demonstrated by lou_trace.
nvd
CVE-2021-37623P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-37623 [MEDIUM] CWE-835 CVE-2021-37623: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause
nvd