Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 241 of 264
CVE-2022-4129P4MEDIUMCVSS 5.5v35v36+1 more2022-11-28
CVE-2022-4129 [MEDIUM] CWE-667 CVE-2022-4129: A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when cleari
A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system causing a denial of service.
nvd
CVE-2013-0237P4MEDIUMCVSS 4.3v16v17+1 more2013-07-08
CVE-2013-0237 [MEDIUM] CWE-79 CVE-2013-0237: Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
nvd
CVE-2019-2614P4MEDIUMCVSS 4.4v29v302019-04-23
CVE-2019-2614 [MEDIUM] CVE-2019-2614: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this v
nvd
CVE-2014-5353P4LOWCVSS 3.5v222014-12-16
CVE-2014-5353 [LOW] CWE-476 CVE-2014-5353: The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c
The krb5_ldap_get_password_policy_from_dn function in plugins/kdb/ldap/libkdb_ldap/ldap_pwd_policy.c in MIT Kerberos 5 (aka krb5) before 1.13.1, when the KDC uses LDAP, allows remote authenticated users to cause a denial of service (daemon crash) via a successful LDAP query with no results, as demonstrated by using an incorrect object type for a password
nvd
CVE-2020-12888P4MEDIUMCVSS 5.3v31v322020-05-15
CVE-2020-12888 [MEDIUM] CWE-755 CVE-2020-12888: The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
nvd
CVE-2019-2739P4MEDIUMCVSS 5.1v29v302019-07-23
CVE-2019-2739 [MEDIUM] CVE-2019-2739: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privile
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Suc
nvd
CVE-2022-21248P4LOWCVSS 3.7v34v352022-01-19
CVE-2022-21248 [LOW] CVE-2022-21248: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Serialization). Supported versions that are affected are Oracle Java SE: 7u321, 8u311, 11.0.13, 17.0.1; Oracle GraalVM Enterprise Edition: 20.3.4 and 21.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via mult
nvd
CVE-2015-2665P4MEDIUMCVSS 4.3v22v23+1 more2015-06-17
CVE-2015-2665 [MEDIUM] CWE-79 CVE-2015-2665: Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject ar
Cross-site scripting (XSS) vulnerability in Cacti before 0.8.8d allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
nvd
CVE-2023-39512P4MEDIUMCVSS 4.8v37v382023-09-05
CVE-2023-39512 [MEDIUM] CWE-79 CVE-2023-39512: Cacti is an open source operational monitoring and fault management framework. Affected versions are
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's b
nvd
CVE-2023-39515P4MEDIUMCVSS 4.8v37v382023-09-05
CVE-2023-39515 [MEDIUM] CWE-79 CVE-2023-39515: Cacti is an open source operational monitoring and fault management framework. Affected versions are
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the cacti's database. These data will be viewed by administrative cacti accounts and execute JavaScript code in the victim's browser at
nvd
CVE-2023-39516P4MEDIUMCVSS 4.8v37v382023-09-05
CVE-2023-39516 [MEDIUM] CWE-79 CVE-2023-39516: Cacti is an open source operational monitoring and fault management framework. Affected versions are
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by administrative _cacti_ accounts and execute JavaScript code in the victim's b
nvd
CVE-2014-8488P4MEDIUMCVSS 4.3v20v21+1 more2014-12-10
CVE-2014-8488 [MEDIUM] CWE-79 CVE-2014-8488: Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote atta
Cross-site scripting (XSS) vulnerability in the administrator panel in Yourls 1.7 allows remote attackers to inject arbitrary web script or HTML via a URL that is processed by the Shorten functionality.
nvd
CVE-2023-5380P4MEDIUMCVSS 4.7v37v38+1 more2023-10-25
CVE-2023-5380 [MEDIUM] CWE-416 CVE-2023-5380: A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specif
A use-after-free flaw was found in the xorg-x11-server. An X server crash may occur in a very specific and legacy configuration (a multi-screen setup with multiple protocol screens, also known as Zaphod mode) if the pointer is warped from within a window on one screen to the root window of the other screen and if the original window is destroyed follo
nvd
CVE-2020-6489P4MEDIUMCVSS 4.3v31v322020-05-21
CVE-2020-6489 [MEDIUM] CWE-200 CVE-2020-6489: Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a rem
Inappropriate implementation in developer tools in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had convinced the user to take certain actions in developer tools to obtain potentially sensitive information from disk via a crafted HTML page.
nvd
CVE-2020-6531P4MEDIUMCVSS 4.3v31v322020-07-22
CVE-2020-6531 [MEDIUM] CWE-203 CVE-2020-6531: Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a
Side-channel information leakage in scroll to text in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-22898P4LOWCVSS 3.1v33v342021-06-11
CVE-2021-22898 [LOW] CWE-200 CVE-2021-22898: curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, kn
curl 7.7 through 7.76.1 suffers from an information disclosure when the `-t` command line option, known as `CURLOPT_TELNETOPTIONS` in libcurl, is used to send variable=content pairs to TELNET servers. Due to a flaw in the option parser for sending NEW_ENV variables, libcurl could be made to pass on uninitialized data from a stack based buffer to the se
nvd
CVE-2020-15966P4MEDIUMCVSS 4.3v31v32+1 more2020-09-21
CVE-2020-15966 [MEDIUM] CVE-2020-15966: Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an att
Insufficient policy enforcement in extensions in Google Chrome prior to 85.0.4183.121 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
nvd
CVE-2020-6391P4MEDIUMCVSS 4.3v30v312020-02-11
CVE-2020-6391 [MEDIUM] CWE-79 CVE-2020-6391: Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a
Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2021-21185P4MEDIUMCVSS 4.3v32v33+1 more2021-03-09
CVE-2021-21185 [MEDIUM] CVE-2021-21185: Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an atta
Insufficient policy enforcement in extensions in Google Chrome prior to 89.0.4389.72 allowed an attacker who convinced a user to install a malicious extension to obtain sensitive information via a crafted Chrome Extension.
nvd
CVE-2020-6571P4MEDIUMCVSS 4.3v332020-09-21
CVE-2020-6571 [MEDIUM] CWE-20 CVE-2020-6571: Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote atta
Insufficient data validation in Omnibox in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd