cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 248 of 264
CVE-2019-18222P4MEDIUMCVSS 4.7v30v312020-01-23
CVE-2019-18222 [MEDIUM] CWE-203 CVE-2019-18222: The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 doe The ECDSA signature implementation in ecdsa.c in Arm Mbed Crypto 2.1 and Mbed TLS through 2.19.1 does not reduce the blinded scalar before computing the inverse, which allows a local attacker to recover the private key via side-channel attacks.
nvd
CVE-2013-4235P4MEDIUMCVSS 4.7v16v172019-12-03
CVE-2013-4235 [MEDIUM] CWE-367 CVE-2013-4235: shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees shadow: TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees
nvd
CVE-2020-6438P4MEDIUMCVSS 4.3v30v31+1 more2020-04-13
CVE-2020-6438 [MEDIUM] CWE-209 CVE-2020-6438: Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an atta Insufficient policy enforcement in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension.
nvd
CVE-2020-27675P4MEDIUMCVSS 4.7v31v32+1 more2020-10-22
CVE-2020-27675 [MEDIUM] CWE-362 CVE-2020-27675: An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/ An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer dereference, as demonstrated by a dom0 crash via events for an in-reconfiguration paravirtualized
nvd
CVE-2020-1735P4MEDIUMCVSS 4.6v30v31+1 more2020-03-16
CVE-2020-1735 [MEDIUM] CWE-22 CVE-2020-1735: A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept th A flaw was found in the Ansible Engine when the fetch module is used. An attacker could intercept the module, inject a new path, and then choose a new destination path on the controller node. All versions in 2.7.x, 2.8.x and 2.9.x branches are believed to be vulnerable.
nvd
CVE-2020-15959P4MEDIUMCVSS 4.3v31v332020-09-21
CVE-2020-15959 [MEDIUM] CVE-2020-15959: Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an att Insufficient policy enforcement in networking in Google Chrome prior to 85.0.4183.102 allowed an attacker who convinced the user to enable logging to obtain potentially sensitive information from process memory via social engineering.
nvd
CVE-2021-34557P4MEDIUMCVSS 4.6v332021-06-10
CVE-2021-34557 [MEDIUM] CWE-120 CVE-2021-34557: XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A b XScreenSaver 5.45 can be bypassed if the machine has more than ten disconnectable video outputs. A buffer overflow in update_screen_layout() allows an attacker to bypass the standard screen lock authentication mechanism by crashing XScreenSaver. The attacker must physically disconnect many video outputs.
nvd
CVE-2024-1312P4MEDIUMCVSS 4.7v392024-02-08
CVE-2024-1312 [MEDIUM] CWE-416 CVE-2024-1312: A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins t A use-after-free flaw was found in the Linux kernel's Memory Management subsystem when a user wins two races at the same time with a fail in the mas_prev_slot function. This issue could allow a local user to crash the system.
nvd
CVE-2019-13763P4MEDIUMCVSS 4.3v30v312019-12-10
CVE-2019-13763 [MEDIUM] CVE-2019-13763: Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
nvd
CVE-2020-6570P4MEDIUMCVSS 4.3v332020-09-21
CVE-2020-6570 [MEDIUM] CWE-200 CVE-2020-6570: Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to ob Information leakage in WebRTC in Google Chrome prior to 85.0.4183.83 allowed a remote attacker to obtain potentially sensitive information via a crafted WebRTC interaction.
nvd
CVE-2015-0856P4MEDIUMCVSS 4.6v222015-11-24
CVE-2015-0856 [MEDIUM] CWE-264 CVE-2015-0856: daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allo daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.
nvd
CVE-2021-2010P4MEDIUMCVSS 4.2v32v332021-01-20
CVE-2021-2010 [MEDIUM] CVE-2021-2010: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can res
nvd
CVE-2015-4625P4MEDIUMCVSS 4.6v21v222015-10-26
CVE-2015-4625 [MEDIUM] CWE-189 CVE-2015-4625: Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0. Integer overflow in the authentication_agent_new_cookie function in PolicyKit (aka polkit) before 0.113 allows local users to gain privileges by creating a large number of connections, which triggers the issuance of a duplicate cookie value.
nvd
CVE-2020-6440P4MEDIUMCVSS 4.3v30v31+1 more2020-04-13
CVE-2020-6440 [MEDIUM] CVE-2020-6440: Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacke Inappropriate implementation in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information via a crafted Chrome Extension.
nvd
CVE-2022-0118P4MEDIUMCVSS 4.3v34v35+1 more2022-02-12
CVE-2022-0118 [MEDIUM] CVE-2022-0118: Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote att Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2022-0110P4MEDIUMCVSS 4.3v34v35+1 more2022-02-12
CVE-2022-0110 [MEDIUM] CWE-1021 CVE-2022-0110: Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker t Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2023-2465P4MEDIUMCVSS 4.3v36v37+1 more2023-05-03
CVE-2023-2465 [MEDIUM] CVE-2023-2465: Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attack Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2014-1520P4MEDIUMCVSS 6.9v19v202014-04-30
CVE-2014-1520 [MEDIUM] CWE-269 CVE-2014-1520: maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and maintenservice_installer.exe in the Maintenance Service Installer in Mozilla Firefox before 29.0 and Firefox ESR 24.x before 24.5 on Windows allows local users to gain privileges by placing a Trojan horse DLL file into a temporary directory at an unspecified point in the update process.
nvd
CVE-2023-2463P4MEDIUMCVSS 4.3v36v37+1 more2023-05-03
CVE-2023-2463 [MEDIUM] CVE-2023-2463: Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-2467P4MEDIUMCVSS 4.3v36v37+1 more2023-05-03
CVE-2023-2467 [MEDIUM] CVE-2023-2467: Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)
nvd
Fedoraproject Fedora vulnerabilities | cvebase