Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 249 of 264
CVE-2023-2462P4MEDIUMCVSS 4.3v36v372023-05-03
CVE-2023-2462 [MEDIUM] CVE-2023-2462: Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote att
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2021-37967P4MEDIUMCVSS 4.3v33v352021-10-08
CVE-2021-37967 [MEDIUM] CWE-346 CVE-2021-37967: Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-4002P4MEDIUMCVSS 4.4v352022-03-03
CVE-2021-4002 [MEDIUM] CWE-459 CVE-2021-4002: A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps s
A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized access to some data.
nvd
CVE-2023-48237P4MEDIUMCVSS 4.3v37v38+1 more2023-11-16
CVE-2023-48237 [MEDIUM] CWE-190 CVE-2023-48237: Vim is an open source command line text editor. In affected versions when shifting lines in operator
Vim is an open source command line text editor. In affected versions when shifting lines in operator pending mode and using a very large value, it may be possible to overflow the size of integer. Impact is low, user interaction is required and a crash may not even happen in all situations. This issue has been addressed in commit `6bf131888` which ha
nvd
CVE-2023-48235P4MEDIUMCVSS 4.3v37v38+1 more2023-11-16
CVE-2023-48235 [MEDIUM] CWE-190 CVE-2023-48235: Vim is an open source command line text editor. When parsing relative ex addresses one may unintenti
Vim is an open source command line text editor. When parsing relative ex addresses one may unintentionally cause an
overflow. Ironically this happens in the existing overflow check, because the line number becomes negative and LONG_MAX - lnum will cause the overflow. Impact is low, user interaction is required and a crash may not even happen in all
nvd
CVE-2020-29660P4MEDIUMCVSS 4.4v32v332020-12-09
CVE-2020-29660 [MEDIUM] CWE-416 CVE-2020-29660: A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13
A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.
nvd
CVE-2021-37966P4MEDIUMCVSS 4.3v33v352021-10-08
CVE-2021-37966 [MEDIUM] CWE-346 CVE-2021-37966: Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowe
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2021-38020P4MEDIUMCVSS 4.3v342021-12-23
CVE-2021-38020 [MEDIUM] CVE-2021-38020: Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45
Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2020-15095P4MEDIUMCVSS 4.4v332020-07-07
CVE-2020-15095 [MEDIUM] CWE-532 CVE-2020-15095: Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability thro
Versions of the npm CLI prior to 6.14.6 are vulnerable to an information exposure vulnerability through log files. The CLI supports URLs like "://[[:]@][:][:][/]". The password value is not redacted and is printed to stdout and also to any generated log files.
nvd
CVE-2023-48231P4MEDIUMCVSS 4.3v37v38+1 more2023-11-16
CVE-2023-48231 [MEDIUM] CWE-416 CVE-2023-48231: Vim is an open source command line text editor. When closing a window, vim may try to access already
Vim is an open source command line text editor. When closing a window, vim may try to access already freed window structure. Exploitation beyond crashing the application has not been shown to be viable. This issue has been addressed in commit `25aabc2b` which has been included in release version 9.0.2106. Users are advised to upgrade. There are no k
nvd
CVE-2023-4363P4MEDIUMCVSS 4.3v382023-08-15
CVE-2023-4363 [MEDIUM] CVE-2023-4363: Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed
Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2009-4135P4MEDIUMCVSS 4.4v11v122009-12-11
CVE-2009-4135 [MEDIUM] CWE-59 CVE-2009-4135: The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain pr
The distcheck rule in dist-check.mk in GNU coreutils 5.2.1 through 8.1 allows local users to gain privileges via a symlink attack on a file in a directory tree under /tmp.
nvd
CVE-2015-2922P4LOWCVSS 3.3v20v21+1 more2015-05-27
CVE-2015-2922 [LOW] CWE-17 CVE-2015-2922: The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol impl
The ndisc_router_discovery function in net/ipv6/ndisc.c in the Neighbor Discovery (ND) protocol implementation in the IPv6 stack in the Linux kernel before 3.19.6 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advertisement (RA) message.
nvd
CVE-2022-2611P4MEDIUMCVSS 4.3v372022-08-12
CVE-2022-2611 [MEDIUM] CVE-2022-2611: Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 al
Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2022-3053P4MEDIUMCVSS 4.3v372022-09-26
CVE-2022-3053 [MEDIUM] CVE-2022-3053: Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed
Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.
nvd
CVE-2020-25678P4MEDIUMCVSS 4.4v332021-01-08
CVE-2020-25678 [MEDIUM] CWE-312 CVE-2020-25678: A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear
A flaw was found in ceph in versions prior to 16.y.z where ceph stores mgr module passwords in clear text. This can be found by searching the mgr logs for grafana and dashboard, with passwords visible.
nvd
CVE-2016-1900P4LOWCVSS 3.7v222016-01-20
CVE-2016-1900 [LOW] CVE-2016-1900: CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0
CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via newline characters in a filename.
nvd
CVE-2023-5542P4MEDIUMCVSS 4.3v382023-11-09
CVE-2023-5542 [MEDIUM] CWE-284 CVE-2023-5542: Students in "Only see own membership" groups could see other students in the group, which should be
Students in "Only see own membership" groups could see other students in the group, which should be hidden.
nvd
CVE-2024-0805P4MEDIUMCVSS 4.3v38v392024-01-24
CVE-2024-0805 [MEDIUM] CWE-451 CVE-2024-0805: Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote a
Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
nvd
CVE-2022-2619P4MEDIUMCVSS 4.3v372022-08-12
CVE-2022-2619 [MEDIUM] CWE-116 CVE-2022-2619: Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allow
Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.
nvd