cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 24 of 264
CVE-2019-3842P3HIGHCVSS 7.0PoCv302019-04-09
CVE-2019-3842 [HIGH] CWE-285 CVE-2019-3842: In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the enviro In systemd before v242-rc4, it was discovered that pam_systemd does not properly sanitize the environment before using the XDG_SEAT variable. It is possible for an attacker, in some particular configurations, to set a XDG_SEAT environment variable which allows for commands to be checked against polkit policies using the "allow_active" element rather tha
nvd
CVE-2023-39358P2HIGHCVSS 8.8v37v382023-09-05
CVE-2023-39358 [HIGH] CWE-89 CVE-2023-39358: Cacti is an open source operational monitoring and fault management framework. An authenticated SQL Cacti is an open source operational monitoring and fault management framework. An authenticated SQL injection vulnerability was discovered which allows authenticated users to perform privilege escalation and remote code execution. The vulnerability resides in the `reports_user.php` file. In `ajax_get_branches`, the `tree_id` parameter is passed to the `
nvd
CVE-2021-3449P3MEDIUMCVSS 5.9v342021-03-25
CVE-2021-3449 [MEDIUM] CWE-476 CVE-2021-3449: An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer dereference will result, leading to a cr
nvd
CVE-2021-32675P3HIGHCVSS 7.5v33v34+1 more2021-10-04
CVE-2021-32675 [HIGH] CWE-770 CVE-2021-32675: Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis St Redis is an open source, in-memory database that persists on disk. When parsing an incoming Redis Standard Protocol (RESP) request, Redis allocates memory according to user-specified values which determine the number of elements (in the multi-bulk header) and size of each element (in the bulk header). An attacker delivering specially crafted requests
nvd
CVE-2019-14867P3HIGHCVSS 8.8v30v312019-11-27
CVE-2019-14867 [HIGH] CWE-94 CVE-2019-14867: A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4. A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA serv
nvd
CVE-2022-25315P3CRITICALCVSS 9.8v34v352022-02-18
CVE-2022-25315 [CRITICAL] CWE-190 CVE-2022-25315: In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames. In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.
nvd
CVE-2021-28662P3MEDIUMCVSS 6.5v33v342021-05-27
CVE-2021-28662 [MEDIUM] CWE-116 CVE-2021-28662: An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a ce An issue was discovered in Squid 4.x before 4.15 and 5.x before 5.0.6. If a remote server sends a certain response header over HTTP or HTTPS, there is a denial of service. This header can plausibly occur in benign network traffic.
nvd
CVE-2015-6816P3CRITICALCVSS 9.8v21v22+1 more2017-08-09
CVE-2015-6816 [CRITICAL] CWE-287 CVE-2015-6816: ganglia-web before 3.7.1 allows remote attackers to bypass authentication. ganglia-web before 3.7.1 allows remote attackers to bypass authentication.
nvd
CVE-2019-9850P3CRITICALCVSS 9.8v29v302019-08-15
CVE-2019-9850 [CRITICAL] CVE-2019-9850: LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which LibreOffice is typically bundled with LibreLogo, a programmable turtle vector graphics script, which can execute arbitrary python commands contained with the document it is launched from. LibreOffice also has a feature where documents can specify that pre-installed scripts can be executed on various document script events such as mouse-over, etc. Protection
nvd
CVE-2022-42920P3CRITICALCVSS 9.8v35v36+1 more2022-11-07
CVE-2022-42920 [CRITICAL] CWE-787 CVE-2022-42920: Apache Commons BCEL has a number of APIs that would normally only allow changing specific class char Apache Commons BCEL has a number of APIs that would normally only allow changing specific class characteristics. However, due to an out-of-bounds writing issue, these APIs can be used to produce arbitrary bytecode. This could be abused in applications that pass attacker-controllable data to those APIs, giving the attacker more control over the res
nvd
CVE-2023-24329P3HIGHCVSS 7.5v36v37+1 more2023-02-17
CVE-2023-24329 [HIGH] CWE-20 CVE-2023-24329: An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisti An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
nvd
CVE-2022-22995P3CRITICALCVSS 9.8v37v38+1 more2022-03-25
CVE-2022-22995 [CRITICAL] CWE-59 CVE-2022-22995: The combination of primitives offered by SMB and AFP in their default configuration allows the arbit The combination of primitives offered by SMB and AFP in their default configuration allows the arbitrary writing of files. By exploiting these combination of primitives, an attacker can execute arbitrary code.
nvd
CVE-2019-12523P3CRITICALCVSS 9.1v30v312019-11-26
CVE-2019-12523 [CRITICAL] CVE-2019-12523: An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP reque An issue was discovered in Squid before 4.9. When handling a URN request, a corresponding HTTP request is made. This HTTP request doesn't go through the access checks that incoming HTTP requests go through. This causes all access checks to be bypassed and allows access to restricted HTTP servers, e.g., an attacker can connect to HTTP servers that only lis
nvd
CVE-2021-33477P3HIGHCVSS 8.8v33v342021-05-20
CVE-2021-33477 [HIGH] CWE-755 CVE-2021-33477: rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code executi rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
nvd
CVE-2023-31047P3CRITICALCVSS 9.8v382023-05-07
CVE-2023-31047 [CRITICAL] CWE-20 CVE-2023-31047: In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass valid In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation sug
nvd
CVE-2022-26377P3HIGHCVSS 7.5v35v362022-06-09
CVE-2022-26377 [HIGH] CWE-444 CVE-2022-26377: Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_a Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') vulnerability in mod_proxy_ajp of Apache HTTP Server allows an attacker to smuggle requests to the AJP server it forwards requests to. This issue affects Apache HTTP Server Apache HTTP Server 2.4 version 2.4.53 and prior versions.
nvd
CVE-2020-24614P3HIGHCVSS 8.8v32v332020-08-25
CVE-2020-24614 [HIGH] CWE-862 CVE-2020-24614: Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated use Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
nvd
CVE-2024-1670P3HIGHCVSS 8.8v38v392024-02-21
CVE-2024-1670 [HIGH] CWE-416 CVE-2024-1670: Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentia Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-4058P3HIGHCVSS 8.8v402024-05-01
CVE-2024-4058 [HIGH] CWE-843 CVE-2024-4058: Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potenti Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2021-32688P3HIGHCVSS 8.8v33v342021-07-12
CVE-2021-32688 [HIGH] CWE-285 CVE-2021-32688: Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports applica Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the user to not have any filesystem access. Due to a lacking permission check, th
nvd
Fedoraproject Fedora vulnerabilities | cvebase