Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 231 of 264
CVE-2021-34335P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-34335 [MEDIUM] CWE-369 CVE-2021-34335: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A floating point exception (FPE) due to an integer divide by zero was found in Exiv2 versions v0.27.4 and earlier. The FPE is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentia
nvd
CVE-2021-37619P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-37619 [MEDIUM] CWE-125 CVE-2021-37619: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability t
nvd
CVE-2021-37618P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-37618 [MEDIUM] CWE-125 CVE-2021-37618: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability
nvd
CVE-2022-27943P4MEDIUMCVSS 5.5v362022-03-26
CVE-2022-27943 [MEDIUM] CWE-674 CVE-2022-27943: libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrate
libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.
nvd
CVE-2021-36979P4MEDIUMCVSS 5.5v352021-07-20
CVE-2021-36979 [MEDIUM] CWE-787 CVE-2021-36979: Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb an
Unicorn Engine 1.0.2 has an out-of-bounds write in tb_flush_armeb (called from cpu_arm_exec_armeb and tcg_cpu_exec_armeb).
nvd
CVE-2021-30470P4MEDIUMCVSS 5.5v332021-05-26
CVE-2021-30470 [MEDIUM] CWE-674 CVE-2021-30470: A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), Pd
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call among PdfTokenizer::ReadArray(), PdfTokenizer::GetNextVariant() and PdfTokenizer::ReadDataType() functions can lead to a stack overflow.
nvd
CVE-2021-3996P4MEDIUMCVSS 5.5v352022-08-23
CVE-2021-3996 [MEDIUM] CWE-552 CVE-2021-3996: A logic error was found in the libmount library of util-linux in the function that allows an unprivi
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like /tmp) or mounted in a world-writable directory. An attacker may use this fl
nvd
CVE-2021-3995P4MEDIUMCVSS 5.5v352022-08-23
CVE-2021-3995 [MEDIUM] CWE-552 CVE-2021-3995: A logic error was found in the libmount library of util-linux in the function that allows an unprivi
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a prefix of the UID of the attacker in its string form. An attacker may use th
nvd
CVE-2020-14323P4MEDIUMCVSS 5.5v32v332020-10-29
CVE-2020-14323 [MEDIUM] CWE-170 CVE-2020-14323: A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, bef
A null pointer dereference flaw was found in samba's Winbind service in versions before 4.11.15, before 4.12.9 and before 4.13.1. A local user could use this flaw to crash the winbind service causing denial of service.
nvd
CVE-2022-48064P4MEDIUMCVSS 5.5v37v382023-08-22
CVE-2022-48064 [MEDIUM] CWE-770 CVE-2022-48064: GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via
GNU Binutils before 2.40 was discovered to contain an excessive memory consumption vulnerability via the function bfd_dwarf2_find_nearest_line_with_alt at dwarf2.c. The attacker could supply a crafted ELF file and cause a DNS attack.
nvd
CVE-2022-42722P4MEDIUMCVSS 5.5v35v36+1 more2022-10-14
CVE-2022-42722 [MEDIUM] CWE-476 CVE-2022-42722: In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames in
In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.
nvd
CVE-2018-18849P4MEDIUMCVSS 5.5v292019-03-21
CVE-2018-18849 [MEDIUM] CWE-125 CVE-2018-18849: In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an inv
In Qemu 3.0.0, lsi_do_msgin in hw/scsi/lsi53c895a.c allows out-of-bounds access by triggering an invalid msg_len value.
nvd
CVE-2019-5765P4MEDIUMCVSS 5.5v29v302019-02-19
CVE-2019-5765 [MEDIUM] CWE-312 CVE-2019-5765: An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allow
An exposed debugging endpoint in the browser in Google Chrome on Android prior to 72.0.3626.81 allowed a local attacker to obtain potentially sensitive information from process memory via a crafted Intent.
nvd
CVE-2021-4115P4MEDIUMCVSS 5.5v34v352022-02-21
CVE-2021-4115 [MEDIUM] CWE-400 CVE-2021-4115: There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to proc
There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and a new one being spawned
nvd
CVE-2020-11743P4MEDIUMCVSS 5.5v322020-04-14
CVE-2020-11743 [MEDIUM] CWE-755 CVE-2020-11743: An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service
An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service because of a bad error path in GNTTABOP_map_grant. Grant table operations are expected to return 0 for success, and a negative number for errors. Some misplaced brackets cause one error path to return 1 instead of a negative value. The grant table code
nvd
CVE-2020-25596P4MEDIUMCVSS 5.5v31v32+1 more2020-09-23
CVE-2020-25596 [MEDIUM] CWE-74 CVE-2020-25596: An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service
An issue was discovered in Xen through 4.14.x. x86 PV guest kernels can experience denial of service via SYSENTER. The SYSENTER instruction leaves various state sanitization activities to software. One of Xen's sanitization paths injects a #GP fault, and incorrectly delivers it twice to the guest. This causes the guest kernel to observe a kernel-priv
nvd
CVE-2022-33748P4MEDIUMCVSS 5.6v35v36+1 more2022-10-11
CVE-2022-33748 [MEDIUM] CWE-755 CVE-2022-33748: lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was
lock order inversion in transitive grant copy handling As part of XSA-226 a missing cleanup call was inserted on an error handling path. While doing so, locking requirements were not paid attention to. As a result two cooperating guests granting each other transitive grants can cause locks to be acquired nested within one another, but in respectivel
nvd
CVE-2023-3195P4MEDIUMCVSS 5.5v37v382023-06-16
CVE-2023-3195 [MEDIUM] CWE-121 CVE-2023-3195: A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an at
A stack-based buffer overflow issue was found in ImageMagick's coders/tiff.c. This flaw allows an attacker to trick the user into opening a specially crafted malicious tiff file, causing an application to crash, resulting in a denial of service.
nvd
CVE-2020-9391P4MEDIUMCVSS 5.5v312020-02-25
CVE-2020-9391 [MEDIUM] CWE-787 CVE-2020-9391: An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. I
An issue was discovered in the Linux kernel 5.4 and 5.5 through 5.5.6 on the AArch64 architecture. It ignores the top byte in the address passed to the brk system call, potentially moving the memory break downwards when the application expects it to move upwards, aka CID-dcde237319e6. This has been observed to cause heap corruption with the GNU C Libr
nvd
CVE-2022-26356P4MEDIUMCVSS 5.6v34v352022-04-05
CVE-2022-26356 [MEDIUM] CWE-667 CVE-2022-26356: Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirt
Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to XEN_DMOP_track_dirty_vram can enable log dirty while another CPU is still in the process of
nvd