Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 242 of 264
CVE-2020-6529P4MEDIUMCVSS 4.3v31v322020-07-22
CVE-2020-6529 [MEDIUM] CWE-295 CVE-2020-6529: Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in
Inappropriate implementation in WebRTC in Google Chrome prior to 84.0.4147.89 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-13759P4MEDIUMCVSS 4.3v30v312019-12-10
CVE-2019-13759 [MEDIUM] CVE-2019-13759: Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attac
Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2019-13756P4MEDIUMCVSS 4.3v30v312019-12-10
CVE-2019-13756 [MEDIUM] CVE-2019-13756: Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker t
Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
nvd
CVE-2021-37968P4MEDIUMCVSS 4.3v33v352021-10-08
CVE-2021-37968 [MEDIUM] CWE-203 CVE-2021-37968: Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2019-13758P4MEDIUMCVSS 4.3v30v312019-12-10
CVE-2019-13758 [MEDIUM] CVE-2019-13758: Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allo
Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-13755P4MEDIUMCVSS 4.3v30v312019-12-10
CVE-2019-13755 [MEDIUM] CVE-2019-13755: Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remot
Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page.
nvd
CVE-2021-37965P4MEDIUMCVSS 4.3v33v352021-10-08
CVE-2021-37965 [MEDIUM] CVE-2021-37965: Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2024-27019P4MEDIUMCVSS 4.7v38v39+1 more2024-05-01
CVE-2024-27019 [MEDIUM] CWE-362 CVE-2024-27019: In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: Fix poten
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get()
nft_unregister_obj() can concurrent with __nft_obj_type_get(),
and there is not any protection when iterate over nf_tables_objects
list in __nft_obj_type_get(). Therefore, there is potential data-race
of nf_table
nvd
CVE-2022-0116P4MEDIUMCVSS 4.3v34v35+1 more2022-02-12
CVE-2022-0116 [MEDIUM] CVE-2022-0116: Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote
Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2021-37963P4MEDIUMCVSS 4.3v33v352021-10-08
CVE-2021-37963 [MEDIUM] CVE-2021-37963: Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote
Side-channel information leakage in DevTools in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to bypass site isolation via a crafted HTML page.
nvd
CVE-2015-3455P4LOWCVSS 2.6v222015-05-18
CVE-2015-3455 [LOW] CWE-20 CVE-2015-3455: Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when co
Squid 3.2.x before 3.2.14, 3.3.x before 3.3.14, 3.4.x before 3.4.13, and 3.5.x before 3.5.4, when configured with client-first SSL-bump, do not properly validate the domain or hostname fields of X.509 certificates, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate.
nvd
CVE-2021-30537P4MEDIUMCVSS 4.3v33v342021-06-07
CVE-2021-30537 [MEDIUM] CWE-863 CVE-2021-30537: Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote a
Insufficient policy enforcement in cookies in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass cookie policy via a crafted HTML page.
nvd
CVE-2015-0374P4LOWCVSS 3.5v202015-01-21
CVE-2015-0374 [LOW] CVE-2015-0374: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier and 5.6.21 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges : Foreign Key.
nvd
CVE-2019-13761P4MEDIUMCVSS 4.3v30v312019-12-10
CVE-2019-13761 [MEDIUM] CVE-2019-13761: Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to
Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2021-21228P4MEDIUMCVSS 4.3v32v33+1 more2021-04-30
CVE-2021-21228 [MEDIUM] CWE-863 CVE-2021-21228: Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an atta
Insufficient policy enforcement in extensions in Google Chrome prior to 90.0.4430.93 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.
nvd
CVE-2023-5851P4MEDIUMCVSS 4.3v37v38+1 more2023-11-01
CVE-2023-5851 [MEDIUM] CWE-346 CVE-2023-5851: Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-42843P4MEDIUMCVSS 4.3v402024-02-21
CVE-2023-42843 [MEDIUM] CWE-290 CVE-2023-42843: An inconsistent user interface issue was addressed with improved state management. This issue is fix
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
nvd
CVE-2023-6511P4MEDIUMCVSS 4.3v38v392023-12-06
CVE-2023-6511 [MEDIUM] CVE-2023-6511: Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote at
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2022-2165P4MEDIUMCVSS 4.3v35v362022-07-28
CVE-2022-2165 [MEDIUM] CVE-2022-2165: Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a rem
Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.
nvd
CVE-2023-2466P4MEDIUMCVSS 4.3v36v37+1 more2023-05-03
CVE-2023-2466 [MEDIUM] CVE-2023-2466: Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote att
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)
nvd