cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 247 of 264
CVE-2010-5109P4MEDIUMCVSS 4.3v16v172014-05-05
CVE-2010-5109 [MEDIUM] CWE-189 CVE-2010-5109: Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remo Off-by-one error in the DecompressRTF function in ytnef.c in Yerase's TNEF Stream Reader allows remote attackers to cause a denial of service (crash) via a crafted TNEF file, which triggers a buffer overflow.
nvd
CVE-2019-3018P4MEDIUMCVSS 4.4v29v30+1 more2019-10-16
CVE-2019-3018 [MEDIUM] CVE-2019-3018: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.17 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause
nvd
CVE-2013-4589P4MEDIUMCVSS 4.3v182013-11-23
CVE-2013-4589 [MEDIUM] CVE-2013-4589: The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote a The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
nvd
CVE-2021-22878P4MEDIUMCVSS 4.8v342021-03-03
CVE-2021-22878 [MEDIUM] CWE-79 CVE-2021-22878: Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack o Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
nvd
CVE-2022-3500P4MEDIUMCVSS 5.1v35v36+1 more2022-11-22
CVE-2022-3500 [MEDIUM] CWE-248 CVE-2022-3500: A vulnerability was found in keylime. This security issue happens in some circumstances, due to some A vulnerability was found in keylime. This security issue happens in some circumstances, due to some improperly handled exceptions, there exists the possibility that a rogue agent could create errors on the verifier that stopped attestation attempts for that host leaving it in an attested state but not verifying that anymore.
nvd
CVE-2019-2617P4MEDIUMCVSS 4.4v29v302019-04-23
CVE-2019-2617 [MEDIUM] CVE-2019-2617: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Sup Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd
CVE-2021-2174P4MEDIUMCVSS 4.4v32v33+1 more2021-04-22
CVE-2021-2174 [MEDIUM] CVE-2021-2174: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthori
nvd
CVE-2021-2022P4MEDIUMCVSS 4.4v32v332021-01-20
CVE-2021-2022 [MEDIUM] CVE-2021-2022: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can r
nvd
CVE-2020-2926P4MEDIUMCVSS 4.4v30v31+1 more2020-04-15
CVE-2020-2926 [MEDIUM] CVE-2020-2926: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS) Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication GCS). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unautho
nvd
CVE-2020-2921P4MEDIUMCVSS 4.4v30v31+1 more2020-04-15
CVE-2020-2921 [MEDIUM] CVE-2020-2921: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plug Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Group Replication Plugin). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unau
nvd
CVE-2021-2171P4MEDIUMCVSS 4.4v32v33+1 more2021-04-22
CVE-2021-2171 [MEDIUM] CVE-2021-2171: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supporte Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result
nvd
CVE-2020-2930P4MEDIUMCVSS 4.4v30v31+1 more2020-04-15
CVE-2020-2930 [MEDIUM] CVE-2020-2930: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported ver Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Parser). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability t
nvd
CVE-2019-9495P4LOWCVSS 3.7v28v29+1 more2019-04-17
CVE-2019-9495 [LOW] CWE-524 CVE-2019-9495: The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks The implementations of EAP-PWD in hostapd and wpa_supplicant are vulnerable to side-channel attacks as a result of cache access patterns. All versions of hostapd and wpa_supplicant with EAP-PWD support are vulnerable. The ability to install and execute applications is necessary for a successful attack. Memory access patterns are visible in a shared cache.
nvd
CVE-2023-22058P4MEDIUMCVSS 4.4v37v38+1 more2023-07-18
CVE-2023-22058 [MEDIUM] CVE-2023-22058: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versi Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to
nvd
CVE-2020-14573P4LOWCVSS 3.7v31v322020-07-15
CVE-2020-14573 [LOW] CVE-2020-14573: Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that Vulnerability in the Java SE product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Java SE: 11.0.7 and 14.0.1. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. Successful attacks of this vulnerability can result in unauthorized update, insert
nvd
CVE-2015-4913P4LOWCVSS 3.5v232015-10-22
CVE-2015-4913 [LOW] CVE-2015-4913: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via vectors related to Server : DML, a different vulnerability than CVE-2015-4858.
nvd
CVE-2012-1158P4MEDIUMCVSS 4.3v15v16+1 more2019-11-14
CVE-2012-1158 [MEDIUM] CWE-200 CVE-2012-1158: Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden gr Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export
nvd
CVE-2012-1161P4MEDIUMCVSS 4.3v15v16+1 more2019-11-14
CVE-2012-1161 [MEDIUM] CWE-200 CVE-2012-1161: Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search result Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results
nvd
CVE-2020-4788P4MEDIUMCVSS 4.7v32v332020-11-20
CVE-2020-4788 [MEDIUM] CVE-2020-4788: IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive info IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
nvd
CVE-2015-7810P4MEDIUMCVSS 4.7v17v182019-11-22
CVE-2015-7810 [MEDIUM] CWE-367 CVE-2015-7810: libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files libbluray MountManager class has a time-of-check time-of-use (TOCTOU) race when expanding JAR files
nvd
Fedoraproject Fedora vulnerabilities | cvebase