Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 244 of 264
CVE-2023-5853P4MEDIUMCVSS 4.3v37v38+1 more2023-11-01
CVE-2023-5853 [MEDIUM] CWE-346 CVE-2023-5853: Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacke
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-2464P4MEDIUMCVSS 4.3v36v37+1 more2023-05-03
CVE-2023-2464 [MEDIUM] CVE-2023-2464: Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2020-28368P4MEDIUMCVSS 4.4v322020-11-10
CVE-2020-28368 [MEDIUM] CWE-862 CVE-2020-28368: Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys
Xen through 4.14.x allows guest OS administrators to obtain sensitive information (such as AES keys from outside the guest) via a side-channel attack on a power/energy monitoring interface, aka a "Platypus" attack. NOTE: there is only one logically independent fix: to change the access control for each such interface in Xen.
nvd
CVE-2023-5859P4MEDIUMCVSS 4.3v37v38+1 more2023-11-01
CVE-2023-5859 [MEDIUM] CWE-346 CVE-2023-5859: Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remot
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4908P4MEDIUMCVSS 4.3v37v38+1 more2023-09-12
CVE-2023-4908 [MEDIUM] CVE-2023-4908: Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2023-4909P4MEDIUMCVSS 4.3v37v38+1 more2023-09-12
CVE-2023-4909 [MEDIUM] CVE-2023-4909: Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remo
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2024-3843P4MEDIUMCVSS 4.3v38v39+1 more2024-04-17
CVE-2024-3843 [MEDIUM] CWE-290 CVE-2024-3843: Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote a
Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-40316P4MEDIUMCVSS 4.3v35v362022-09-30
CVE-2022-40316 [MEDIUM] CWE-862 CVE-2022-40316: The H5P activity attempts report did not filter by groups, which in separate groups mode could revea
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
nvd
CVE-2022-0984P4MEDIUMCVSS 4.3v34v35+1 more2022-04-29
CVE-2022-0984 [MEDIUM] CWE-863 CVE-2022-0984: Users with the capability to configure badge criteria (teachers and managers by default) were able t
Users with the capability to configure badge criteria (teachers and managers by default) were able to configure course badges with profile field criteria, which should only be available for site badges.
nvd
CVE-2024-0809P4MEDIUMCVSS 4.3v38v392024-01-24
CVE-2024-0809 [MEDIUM] CWE-693 CVE-2024-0809: Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote at
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2018-19841P4MEDIUMCVSS 5.5v28v29+2 more2018-12-04
CVE-2018-19841 [MEDIUM] CWE-125 CVE-2018-19841: The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allow
The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack.
nvd
CVE-2014-7154P4MEDIUMCVSS 6.1v19v202014-10-02
CVE-2014-7154 [MEDIUM] CWE-362 CVE-2014-7154: Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of th
Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.
nvd
CVE-2017-6312P4MEDIUMCVSS 5.5v30v312017-03-10
CVE-2017-6312 [MEDIUM] CWE-190 CVE-2017-6312: Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of s
Integer overflow in io-ico.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (segmentation fault and application crash) via a crafted image entry offset in an ICO file, which triggers an out-of-bounds read, related to compiler optimizations.
nvd
CVE-2017-6314P4MEDIUMCVSS 5.5v30v312017-03-10
CVE-2017-6314 [MEDIUM] CWE-835 CVE-2017-6314: The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers t
The make_available_at_least function in io-tiff.c in gdk-pixbuf allows context-dependent attackers to cause a denial of service (infinite loop) via a large TIFF file.
nvd
CVE-2019-15144P4MEDIUMCVSS 5.5v29v30+1 more2019-08-18
CVE-2019-15144 [MEDIUM] CWE-674 CVE-2019-15144: In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate<TYPE>::sort) allows attackers to
In DjVuLibre 3.5.27, the sorting functionality (aka GArrayTemplate::sort) allows attackers to cause a denial-of-service (application crash due to an Uncontrolled Recursion) by crafting a PBM image file that is mishandled in libdjvu/GContainer.h.
nvd
CVE-2021-4183P4MEDIUMCVSS 5.5v34v352021-12-30
CVE-2021-4183 [MEDIUM] CWE-125 CVE-2021-4183: Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
nvd
CVE-2019-20093P4MEDIUMCVSS 5.5v30v312019-12-30
CVE-2019-20093 [MEDIUM] CWE-476 CVE-2019-20093: The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers
The PoDoFo::PdfVariant::DelayedLoad function in PdfVariant.h in PoDoFo 0.9.6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted file, because of ImageExtractor.cpp.
nvd
CVE-2009-3094P4LOWCVSS 2.6v10v122009-09-08
CVE-2009-3094 [LOW] CWE-476 CVE-2009-3094: The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Ap
The ap_proxy_ftp_handler function in modules/proxy/proxy_ftp.c in the mod_proxy_ftp module in the Apache HTTP Server 2.0.63 and 2.2.13 allows remote FTP servers to cause a denial of service (NULL pointer dereference and child process crash) via a malformed reply to an EPSV command.
nvd
CVE-2022-2208P4MEDIUMCVSS 5.5v35v362022-06-27
CVE-2022-2208 [MEDIUM] CWE-476 CVE-2022-2208: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.5163.
nvd
CVE-2022-1623P4MEDIUMCVSS 5.5v35v362022-05-11
CVE-2022-1623 [MEDIUM] CWE-125 CVE-2022-1623: LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing atta
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
nvd