cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 246 of 264
CVE-2023-38559P4MEDIUMCVSS 5.5v37v382023-08-01
CVE-2023-38559 [MEDIUM] CWE-125 CVE-2023-38559: A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. Thi A buffer overflow flaw was found in base/gdevdevn.c:1973 in devn_pcx_write_rle() in ghostscript. This issue may allow a local attacker to cause a denial of service via outputting a crafted PDF file for a DEVN device with gs.
nvd
CVE-2022-4645P4MEDIUMCVSS 5.5v36v37+1 more2023-03-03
CVE-2022-4645 [MEDIUM] CWE-125 CVE-2022-4645: LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
nvd
CVE-2019-19055P4MEDIUMCVSS 5.5v30v312019-11-18
CVE-2019-19055 [MEDIUM] CWE-401 CVE-2019-19055: A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Lin A memory leak in the nl80211_get_ftm_responder_stats() function in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering nl80211hdr_put() failures, aka CID-1399c59fa929. NOTE: third parties dispute the relevance of this because it occurs on a code path where a succe
nvd
CVE-2021-46663P4MEDIUMCVSS 5.5v34v35+1 more2022-02-01
CVE-2021-46663 [MEDIUM] CVE-2021-46663: MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements. MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
nvd
CVE-2021-46668P4MEDIUMCVSS 5.5v34v35+1 more2022-02-01
CVE-2021-46668 [MEDIUM] CWE-400 CVE-2021-46668: MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
nvd
CVE-2020-15304P4MEDIUMCVSS 5.5v31v322020-06-26
CVE-2020-15304 [MEDIUM] CWE-476 CVE-2020-15304: An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid mem An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
nvd
CVE-2021-42373P4MEDIUMCVSS 5.5v33v342021-11-15
CVE-2021-42373 [MEDIUM] CWE-476 CVE-2021-42373: A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
nvd
CVE-2022-2476P4MEDIUMCVSS 5.5v35v362022-07-19
CVE-2022-2476 [MEDIUM] CWE-476 CVE-2022-2476: A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSani A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL ===================================================================84257==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x561b47a970c6 bp 0x7fff13952fb0 sp 0x7fff1394fca0 T0) ==84257==The signal is caused by a WR
nvd
CVE-2016-9811P4MEDIUMCVSS 4.7v352017-01-13
CVE-2016-9811 [MEDIUM] CWE-125 CVE-2016-9811: The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is s The windows_icon_typefind function in gst-plugins-base in GStreamer before 1.10.2, when G_SLICE is set to always-malloc, allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted ico file.
nvd
CVE-2023-34475P4MEDIUMCVSS 5.5v37v382023-06-16
CVE-2023-34475 [MEDIUM] CWE-416 CVE-2023-34475: A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in a denial of service.
nvd
CVE-2020-28941P4MEDIUMCVSS 5.5v32v332020-11-19
CVE-2020-28941 [MEDIUM] CWE-763 CVE-2020-28941: An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9 An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.
nvd
CVE-2022-41727P4MEDIUMCVSS 5.5v37v382023-02-28
CVE-2022-41727 [MEDIUM] CWE-770 CVE-2022-41727: An attacker can craft a malformed TIFF image which will consume a significant amount of memory when An attacker can craft a malformed TIFF image which will consume a significant amount of memory when passed to DecodeConfig. This could lead to a denial of service.
nvd
CVE-2024-26922P4MEDIUMCVSS 5.5v38v39+1 more2024-04-23
CVE-2024-26922 [MEDIUM] CVE-2024-26922: In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parame In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: validate the parameters of bo mapping operations more clearly Verify the parameters of amdgpu_vm_bo_(map/replace_map/clearing_mappings) in one common place.
nvd
CVE-2021-28951P4MEDIUMCVSS 5.5v32v33+1 more2021-03-20
CVE-2021-28951 [MEDIUM] CWE-667 CVE-2021-28951: An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to An issue was discovered in fs/io_uring.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (deadlock) because exit may be waiting to park a SQPOLL thread, but concurrently that SQPOLL thread is waiting for a signal to start, aka CID-3ebba796fa25.
nvd
CVE-2024-35947P4MEDIUMCVSS 5.5v402024-05-19
CVE-2024-35947 [MEDIUM] CVE-2024-35947: In the Linux kernel, the following vulnerability has been resolved: dyndbg: fix old BUG_ON in >cont In the Linux kernel, the following vulnerability has been resolved: dyndbg: fix old BUG_ON in >control parser Fix a BUG_ON from 2009. Even if it looks "unreachable" (I didn't really look), lets make sure by removing it, doing pr_err and return -EINVAL instead.
nvd
CVE-2023-2700P4MEDIUMCVSS 5.5v382023-05-15
CVE-2023-2700 [MEDIUM] CWE-401 CVE-2023-2700: A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IO A vulnerability was found in libvirt. This security flaw ouccers due to repeatedly querying an SR-IOV PCI device's capabilities that exposes a memory leak caused by a failure to free the virPCIVirtualFunction array within the parent struct's g_autoptr cleanup.
nvd
CVE-2015-0383P4MEDIUMCVSS 5.4v20v21+1 more2015-01-21
CVE-2015-0383 [MEDIUM] CVE-2015-0383: Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and Unspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit R27.8.4 and R28.3.4 allows local users to affect integrity and availability via unknown vectors related to Hotspot.
nvd
CVE-2019-3009P4MEDIUMCVSS 4.4v29v30+1 more2019-10-16
CVE-2019-3009 [MEDIUM] CVE-2019-3009: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection). Supported versions that are affected are 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abili
nvd
CVE-2015-6665P4MEDIUMCVSS 4.3v21v22+1 more2015-08-24
CVE-2015-6665 [MEDIUM] CWE-79 CVE-2015-6665: Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctool Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to the "a" tag.
nvd
CVE-2021-35603P4LOWCVSS 3.7v33v34+1 more2021-10-20
CVE-2021-35603 [LOW] CVE-2021-35603: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u311, 8u301, 11.0.12, 17; Oracle GraalVM Enterprise Edition: 20.3.3 and 21.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Orac
nvd
Fedoraproject Fedora vulnerabilities | cvebase