Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 243 of 264
CVE-2019-5838P4MEDIUMCVSS 4.3v29v302019-06-27
CVE-2019-5838 [MEDIUM] CWE-863 CVE-2019-5838: Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.
nvd
CVE-2019-10740P4MEDIUMCVSS 4.3v292019-04-07
CVE-2019-10740 [MEDIUM] CWE-319 CVE-2019-10740: In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver repl
nvd
CVE-2019-15718P4MEDIUMCVSS 4.4v29v30+1 more2019-09-04
CVE-2019-15718 [MEDIUM] CVE-2019-15718: In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be restricted to privileged users, in order
nvd
CVE-2023-48233P4MEDIUMCVSS 4.3v37v38+1 more2023-11-16
CVE-2023-48233 [MEDIUM] CWE-190 CVE-2023-48233: Vim is an open source command line text editor. If the count after the :s command is larger than wha
Vim is an open source command line text editor. If the count after the :s command is larger than what fits into a (signed) long variable, abort with e_value_too_large. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit `ac6378773` which has been included in release v
nvd
CVE-2023-48234P4MEDIUMCVSS 4.3v37v38+1 more2023-11-16
CVE-2023-48234 [MEDIUM] CWE-190 CVE-2023-48234: Vim is an open source command line text editor. When getting the count for a normal mode z command,
Vim is an open source command line text editor. When getting the count for a normal mode z command, it may overflow for large counts given. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit `58f9befca1` which has been included in release version 9.0.2109. Users are a
nvd
CVE-2024-3846P4MEDIUMCVSS 4.3v38v39+1 more2024-04-17
CVE-2024-3846 [MEDIUM] CVE-2024-3846: Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote att
Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-48236P4MEDIUMCVSS 4.3v37v38+1 more2023-11-16
CVE-2023-48236 [MEDIUM] CWE-190 CVE-2023-48236: Vim is an open source command line text editor. When using the z= command, the user may overflow the
Vim is an open source command line text editor. When using the z= command, the user may overflow the count with values larger
than MAX_INT. Impact is low, user interaction is required and a crash may not even happen in all situations. This vulnerability has been addressed in commit `73b2d379` which has been included in release version 9.0.2111. User
nvd
CVE-2020-25685P4LOWCVSS 3.7v32v332021-01-20
CVE-2020-25685 [LOW] CVE-2020-25685: A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmas
A flaw was found in dnsmasq before version 2.83. When getting a reply from a forwarded query, dnsmasq checks in forward.c:reply_query(), which is the forwarded query that matches the reply, by only using a weak hash of the query name. Due to the weak hash (CRC32 when dnsmasq is compiled without DNSSEC, SHA-1 when it is) this flaw allows an off-path attacker to
nvd
CVE-2023-48232P4MEDIUMCVSS 4.3v37v38+1 more2023-11-16
CVE-2023-48232 [MEDIUM] CWE-755 CVE-2023-48232: Vim is an open source command line text editor. A floating point exception may occur when calculatin
Vim is an open source command line text editor. A floating point exception may occur when calculating the line offset for overlong lines and smooth scrolling is enabled and the cpo-settings include the 'n' flag. This may happen when a window border is present and when the wrapped line continues on the next physical line directly in the window border
nvd
CVE-2023-4907P4MEDIUMCVSS 4.3v37v38+1 more2023-09-12
CVE-2023-4907 [MEDIUM] CVE-2023-4907: Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-39194P4MEDIUMCVSS 4.4v382023-10-09
CVE-2023-39194 [MEDIUM] CWE-125 CVE-2023-39194: A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the proc
A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds read, potentially leading to an information disclosure.
nvd
CVE-2023-4900P4MEDIUMCVSS 4.3v37v38+1 more2023-09-12
CVE-2023-4900 [MEDIUM] CVE-2023-4900: Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allow
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4903P4MEDIUMCVSS 4.3v37v38+1 more2023-09-12
CVE-2023-4903 [MEDIUM] CVE-2023-4903: Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.6
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4364P4MEDIUMCVSS 4.3v382023-08-15
CVE-2023-4364 [MEDIUM] CVE-2023-4364: Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a
Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4365P4MEDIUMCVSS 4.3v382023-08-15
CVE-2023-4365 [MEDIUM] CVE-2023-4365: Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote
Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-4360P4MEDIUMCVSS 4.3v382023-08-15
CVE-2023-4360 [MEDIUM] CVE-2023-4360: Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attac
Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-2629P4MEDIUMCVSS 4.3v38v39+1 more2024-03-20
CVE-2024-2629 [MEDIUM] CVE-2024-2629: Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to pe
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-3844P4MEDIUMCVSS 4.3v38v39+1 more2024-04-17
CVE-2024-3844 [MEDIUM] CWE-358 CVE-2024-3844: Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
nvd
CVE-2024-2631P4MEDIUMCVSS 4.3v38v39+1 more2024-03-20
CVE-2024-2631 [MEDIUM] CWE-451 CVE-2024-2631: Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacke
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-5858P4MEDIUMCVSS 4.3v37v38+1 more2023-11-01
CVE-2023-5858 [MEDIUM] CWE-346 CVE-2023-5858: Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a r
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
nvd