Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 238 of 264
CVE-2022-0561P4MEDIUMCVSS 5.5v352022-02-11
CVE-2022-0561 [MEDIUM] CWE-476 CVE-2022-0561: Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_d
Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with commit eecb0712.
nvd
CVE-2022-0562P4MEDIUMCVSS 5.5v352022-02-11
CVE-2022-0562 [MEDIUM] CWE-476 CVE-2022-0562: Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dir
Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit 561599c.
nvd
CVE-2020-35521P4MEDIUMCVSS 5.5v332021-03-09
CVE-2020-35521 [MEDIUM] CWE-119 CVE-2020-35521: A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file c
A flaw was found in libtiff. Due to a memory allocation failure in tif_read.c, a crafted TIFF file can lead to an abort, resulting in denial of service.
nvd
CVE-2020-13999P4MEDIUMCVSS 5.5v31v322020-06-15
CVE-2020-13999 [MEDIUM] CWE-190 CVE-2020-13999: ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer
ScaleViewPortExtEx in libemf.cpp in libEMF (aka ECMA-234 Metafile Library) 1.0.12 allows an integer overflow and denial of service via a crafted EMF file.
nvd
CVE-2019-19746P4MEDIUMCVSS 5.5v31v322019-12-12
CVE-2019-19746 [MEDIUM] CWE-190 CVE-2019-19746: make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write bec
make_arrow in arrow.c in Xfig fig2dev 3.2.7b allows a segmentation fault and out-of-bounds write because of an integer overflow via a large arrow type.
nvd
CVE-2015-7208P4MEDIUMCVSS 5.0v22v232015-12-16
CVE-2015-7208 [MEDIUM] CWE-200 CVE-2015-7208: Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote a
Mozilla Firefox before 43.0 stores cookies containing vertical tab characters, which allows remote attackers to obtain sensitive information by reading HTTP Cookie headers.
nvd
CVE-2022-30974P4MEDIUMCVSS 5.5v372022-05-18
CVE-2022-30974 [MEDIUM] CVE-2022-30974: compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited
compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.
nvd
CVE-2021-46141P4MEDIUMCVSS 5.5v34v352022-01-06
CVE-2021-46141 [MEDIUM] CWE-416 CVE-2021-46141: An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUri
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
nvd
CVE-2021-32815P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-32815 [MEDIUM] CWE-617 CVE-2021-32815: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The assertion failure is triggered when Exiv2 is used to modify the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause a denial of service, if they can trick the victim into runnin
nvd
CVE-2021-37621P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-37621 [MEDIUM] CWE-835 CVE-2021-37621: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An infinite loop was found in Exiv2 versions v0.27.4 and earlier. The infinite loop is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vulnerability to cause
nvd
CVE-2021-46142P4MEDIUMCVSS 5.5v34v352022-01-06
CVE-2021-46142 [MEDIUM] CWE-416 CVE-2021-46142: An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormali
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
nvd
CVE-2021-37620P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-37620 [MEDIUM] CWE-125 CVE-2021-37620: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. An out-of-bounds read was found in Exiv2 versions v0.27.4 and earlier. The out-of-bounds read is triggered when Exiv2 is used to read the metadata of a crafted image file. An attacker could potentially exploit the vulnerability
nvd
CVE-2020-16592P4MEDIUMCVSS 5.5v32v332020-12-09
CVE-2020-16592 [MEDIUM] CWE-416 CVE-2020-16592: A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binuti
A use after free issue exists in the Binary File Descriptor (BFD) library (aka libbfd) in GNU Binutils 2.34 in bfd_hash_lookup, as demonstrated in nm-new, that can cause a denial of service via a crafted file.
nvd
CVE-2021-37616P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-37616 [MEDIUM] CWE-476 CVE-2021-37616: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. The null pointer dereference is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vu
nvd
CVE-2023-34151P4MEDIUMCVSS 5.5v37v382023-05-30
CVE-2023-34151 [MEDIUM] CVE-2023-34151: A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of ca
A vulnerability was found in ImageMagick. This security flaw ouccers as an undefined behaviors of casting double to size_t in svg, mvg and other coders (recurring bugs of CVE-2022-32546).
nvd
CVE-2021-37615P4MEDIUMCVSS 5.5v33v342021-08-09
CVE-2021-37615 [MEDIUM] CWE-476 CVE-2021-37615: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A null pointer dereference was found in Exiv2 versions v0.27.4 and earlier. The null pointer dereference is triggered when Exiv2 is used to print the metadata of a crafted image file. An attacker could potentially exploit the vu
nvd
CVE-2021-32434P4MEDIUMCVSS 5.5v34v35+1 more2022-03-10
CVE-2021-32434 [MEDIUM] CWE-125 CVE-2021-32434: abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at d
abcm2ps v8.14.11 was discovered to contain an out-of-bounds read in the function calculate_beam at draw.c.
nvd
CVE-2019-3886P4MEDIUMCVSS 5.4v29v302019-04-04
CVE-2019-3886 [MEDIUM] CWE-862 CVE-2019-3886: An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission wa
An incorrect permissions check was discovered in libvirt 4.8.0 and above. The readonly permission was allowed to invoke APIs depending on the guest agent, which could lead to potentially disclosing unintended information or denial of service by causing libvirt to block.
nvd
CVE-2021-3443P4MEDIUMCVSS 5.5v332021-03-25
CVE-2021-3443 [MEDIUM] CWE-476 CVE-2021-3443: A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component
A NULL pointer dereference flaw was found in the way Jasper versions before 2.0.27 handled component references in the JP2 image format decoder. A specially crafted JP2 image file could cause an application using the Jasper library to crash when opened.
nvd
CVE-2021-30471P4MEDIUMCVSS 5.5v332021-05-26
CVE-2021-30471 [MEDIUM] CWE-674 CVE-2021-30471: A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary fu
A flaw was found in PoDoFo 0.9.7. An uncontrolled recursive call in PdfNamesTree::AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp can lead to a stack overflow.
nvd