cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 237 of 264
CVE-2024-2628P4MEDIUMCVSS 4.3v38v39+1 more2024-03-20
CVE-2024-2628 [MEDIUM] CWE-474 CVE-2024-2628: Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote a Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium)
nvd
CVE-2024-0811P4MEDIUMCVSS 4.3v38v392024-01-24
CVE-2024-0811 [MEDIUM] CVE-2024-0811: Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an at Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2008-2951P4MEDIUMCVSS 6.1v8v92008-07-27
CVE-2008-2951 [MEDIUM] CWE-601 CVE-2008-2951: Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to re Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
nvd
CVE-2023-45803P4MEDIUMCVSS 4.2v382023-10-17
CVE-2023-45803 [MEDIUM] CWE-200 CVE-2023-45803: urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HT urllib3 is a user-friendly HTTP client library for Python. urllib3 previously wouldn't remove the HTTP request body when an HTTP redirect response using status 301, 302, or 303 after the request had its method changed from one that could accept a request body (like `POST`) to `GET` as is required by HTTP RFCs. Although this behavior is not specified
nvd
CVE-2015-1051P4MEDIUMCVSS 5.8v20v212015-01-15
CVE-2015-1051 [MEDIUM] CVE-2015-1051: Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 fo Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination parameter.
nvd
CVE-2018-19840P4MEDIUMCVSS 5.5v28v29+1 more2018-12-04
CVE-2018-19840 [MEDIUM] CWE-835 CVE-2018-19840: The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attacke The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.
nvd
CVE-2010-4157P4MEDIUMCVSS 6.2v132010-12-10
CVE-2010-4157 [MEDIUM] CWE-190 CVE-2010-4157: Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.3 Integer overflow in the ioc_general function in drivers/scsi/gdth.c in the Linux kernel before 2.6.36.1 on 64-bit platforms allows local users to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large argument in an ioctl call.
nvd
CVE-2016-2042P4MEDIUMCVSS 5.3v22v232016-02-20
CVE-2016-2042 [MEDIUM] CWE-200 CVE-2016-2042: phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an error message.
nvd
CVE-2016-4037P4MEDIUMCVSS 6.0v22v23+1 more2016-05-23
CVE-2016-4037 [MEDIUM] CVE-2016-4037: The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to The ehci_advance_state function in hw/usb/hcd-ehci.c in QEMU allows local guest OS administrators to cause a denial of service (infinite loop and CPU consumption) via a circular split isochronous transfer descriptor (siTD) list, a related issue to CVE-2015-8558.
nvd
CVE-2020-29484P4MEDIUMCVSS 6.0v32v332020-12-15
CVE-2020-29484 [MEDIUM] CWE-476 CVE-2020-29484: An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that An issue was discovered in Xen through 4.14.x. When a Xenstore watch fires, the xenstore client that registered the watch will receive a Xenstore message containing the path of the modified Xenstore entry that triggered the watch, and the tag that was specified when registering the watch. Any communication with xenstored is done via Xenstore message
nvd
CVE-2020-35504P4MEDIUMCVSS 6.0v332021-05-28
CVE-2020-35504 [MEDIUM] CWE-476 CVE-2020-35504: A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6 A NULL pointer dereference flaw was found in the SCSI emulation support of QEMU in versions before 6.0.0. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service. The highest threat from this vulnerability is to system availability.
nvd
CVE-2019-16892P4MEDIUMCVSS 5.5v29v30+1 more2019-09-25
CVE-2019-16892 [MEDIUM] CVE-2019-16892: In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).
nvd
CVE-2019-15145P4MEDIUMCVSS 5.5v29v30+1 more2019-08-18
CVE-2019-15145 [MEDIUM] CWE-125 CVE-2019-15145: DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out- DjVuLibre 3.5.27 allows attackers to cause a denial-of-service attack (application crash via an out-of-bounds read) by crafting a corrupted JB2 image file that is mishandled in JB2Dict::JB2Codec::get_direct_context in libdjvu/JB2Image.h because of a missing zero-bytes check in libdjvu/GBitmap.h.
nvd
CVE-2015-8808P4MEDIUMCVSS 5.5v222016-07-13
CVE-2015-8808 [MEDIUM] CWE-119 CVE-2015-8808: The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file.
nvd
CVE-2022-0696P4MEDIUMCVSS 5.5v342022-02-21
CVE-2022-0696 [MEDIUM] CWE-476 CVE-2022-0696: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428. NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.
nvd
CVE-2022-1420P4MEDIUMCVSS 5.5v34v352022-04-21
CVE-2022-1420 [MEDIUM] CWE-823 CVE-2022-1420: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774. Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.
nvd
CVE-2015-1463P4MEDIUMCVSS 5.0v20v212015-02-03
CVE-2015-1463 [MEDIUM] CWE-17 CVE-2015-1463: ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted peti ClamAV before 0.98.6 allows remote attackers to cause a denial of service (crash) via a crafted petite packer file, related to an "incorrect compiler optimization."
nvd
CVE-2018-19872P4MEDIUMCVSS 5.5v28v29+1 more2019-03-21
CVE-2018-19872 [MEDIUM] CWE-369 CVE-2018-19872: An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in q An issue was discovered in Qt 5.11. A malformed PPM image causes a division by zero and a crash in qppmhandler.cpp.
nvd
CVE-2019-20485P4MEDIUMCVSS 5.7v312020-03-19
CVE-2019-20485 [MEDIUM] CWE-20 CVE-2019-20485: qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to qemu/qemu_driver.c in libvirt before 6.0.0 mishandles the holding of a monitor job during a query to a guest agent, which allows attackers to cause a denial of service (API blockage).
nvd
CVE-2022-0908P4MEDIUMCVSS 5.5v35v362022-03-11
CVE-2022-0908 [MEDIUM] CWE-476 CVE-2022-0908: Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_d Null source pointer passed as an argument to memcpy() function within TIFFFetchNormalTag () in tif_dirread.c in libtiff versions up to 4.3.0 could lead to Denial of Service via crafted TIFF file.
nvd
Fedoraproject Fedora vulnerabilities | cvebase