cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 240 of 264
CVE-2024-4855P4MEDIUMCVSS 5.5v39v402024-05-14
CVE-2024-4855 [MEDIUM] CWE-416 CVE-2024-4855: Use after free issue in editcap could cause denial of service via crafted capture file Use after free issue in editcap could cause denial of service via crafted capture file
nvd
CVE-2021-28698P4MEDIUMCVSS 5.5v33v34+1 more2021-08-27
CVE-2021-28698 [MEDIUM] CWE-835 CVE-2021-28698: long running loops in grant table handling In order to properly monitor resource use, Xen maintains long running loops in grant table handling In order to properly monitor resource use, Xen maintains information on the grant mappings a domain may create to map grants offered by other domains. In the process of carrying out certain actions, Xen would iterate over all such entries, including ones which aren't in use anymore and some which may have be
nvd
CVE-2023-23457P4MEDIUMCVSS 5.5v36v372023-01-12
CVE-2023-23457 [MEDIUM] CWE-119 CVE-2023-23457: A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An att A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.
nvd
CVE-2021-28950P4MEDIUMCVSS 5.5v33v342021-03-20
CVE-2021-28950 [MEDIUM] CWE-834 CVE-2021-28950: An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.
nvd
CVE-2024-0232P4MEDIUMCVSS 5.5v392024-01-16
CVE-2024-0232 [MEDIUM] CWE-416 CVE-2024-0232: A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
nvd
CVE-2023-4256P4MEDIUMCVSS 5.5v392023-12-21
CVE-2023-4256 [MEDIUM] CWE-415 CVE-2023-4256: Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cl Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack.
nvd
CVE-2022-28389P4MEDIUMCVSS 5.5v34v35+1 more2022-04-03
CVE-2022-28389 [MEDIUM] CWE-415 CVE-2022-28389: mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a doubl mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
nvd
CVE-2023-6622P4MEDIUMCVSS 5.5v38v392023-12-08
CVE-2023-6622 [MEDIUM] CWE-476 CVE-2023-6622: A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset. A null pointer dereference vulnerability was found in nft_dynset_init() in net/netfilter/nft_dynset.c in nf_tables in the Linux kernel. This issue may allow a local attacker with CAP_NET_ADMIN user privilege to trigger a denial of service.
nvd
CVE-2023-6679P4MEDIUMCVSS 5.5v382023-12-11
CVE-2023-6679 [MEDIUM] CWE-476 CVE-2023-6679: A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll A null pointer dereference vulnerability was found in dpll_pin_parent_pin_set() in drivers/dpll/dpll_netlink.c in the Digital Phase Locked Loop (DPLL) subsystem in the Linux kernel. This issue could be exploited to trigger a denial of service.
nvd
CVE-2022-2868P4MEDIUMCVSS 5.5v35v362022-08-17
CVE-2022-2868 [MEDIUM] CWE-20 CVE-2022-2868: libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read libtiff's tiffcrop utility has a improper input validation flaw that can lead to out of bounds read and ultimately cause a crash if an attacker is able to supply a crafted file to tiffcrop.
nvd
CVE-2021-29649P4MEDIUMCVSS 5.5v32v33+1 more2021-03-30
CVE-2021-29649 [MEDIUM] CWE-401 CVE-2021-29649: An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_pr An issue was discovered in the Linux kernel before 5.11.11. The user mode driver (UMD) has a copy_process() memory leak, related to a lack of cleanup steps in kernel/usermode_driver.c and kernel/bpf/preload/bpf_preload_kern.c, aka CID-f60a85cad677.
nvd
CVE-2023-32627P4MEDIUMCVSS 5.5v382023-07-10
CVE-2023-32627 [MEDIUM] CWE-1077 CVE-2023-32627: A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/v A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.
nvd
CVE-2024-26994P4MEDIUMCVSS 5.5v38v39+1 more2024-05-01
CVE-2024-26994 [MEDIUM] CVE-2024-26994: In the Linux kernel, the following vulnerability has been resolved: speakup: Avoid crash on very lo In the Linux kernel, the following vulnerability has been resolved: speakup: Avoid crash on very long word In case a console is set up really large and contains a really long word (> 256 characters), we have to stop before the length of the word buffer.
nvd
CVE-2022-45873P4MEDIUMCVSS 5.5v362022-11-23
CVE-2022-45873 [MEDIUM] CWE-400 CVE-2022-45873: systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to caus
nvd
CVE-2024-27400P4MEDIUMCVSS 5.5v39v402024-05-14
CVE-2024-27400 [MEDIUM] CVE-2024-27400: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the c In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2 This reverts drm/amdgpu: fix ftrace event amdgpu_bo_move always move on same heap. The basic problem here is that after the move the old location is simply not available any more. Some fixes were suggested, but essentially we
nvd
CVE-2019-2938P4MEDIUMCVSS 4.4v29v30+1 more2019-10-16
CVE-2019-2938 [MEDIUM] CVE-2019-2938: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.27 and prior and 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2024-27015P4MEDIUMCVSS 5.5v38v39+1 more2024-05-01
CVE-2024-27015 [MEDIUM] CVE-2024-27015: In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: incorrect In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: incorrect pppoe tuple pppoe traffic reaching ingress path does not match the flowtable entry because the pppoe header is expected to be at the network header offset. This bug causes a mismatch in the flow table lookup, so pppoe packets enter the classical forwarding p
nvd
CVE-2014-2326P4MEDIUMCVSS 4.3v19v202014-03-27
CVE-2014-2326 [MEDIUM] CWE-79 CVE-2014-2326: Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows rem Cross-site scripting (XSS) vulnerability in cdef.php in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2023-26590P4MEDIUMCVSS 5.5v382023-07-10
CVE-2023-26590 [MEDIUM] CWE-1077 CVE-2023-26590: A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.
nvd
CVE-2021-2372P4MEDIUMCVSS 4.4v33v34+1 more2021-07-21
CVE-2021-2372 [MEDIUM] CVE-2021-2372: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.34 and prior and 8.0.25 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
Fedoraproject Fedora vulnerabilities | cvebase