cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 25 of 264
CVE-2019-20445P3CRITICALCVSS 9.1v332020-01-29
CVE-2019-20445 [CRITICAL] CWE-444 CVE-2019-20445: HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a HttpObjectDecoder.java in Netty before 4.1.44 allows a Content-Length header to be accompanied by a second Content-Length header, or by a Transfer-Encoding header.
nvd
CVE-2024-31142P3HIGHCVSS 7.5v38v402024-05-16
CVE-2024-31142 [HIGH] CWE-693 CVE-2024-31142: Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properl Because of a logical error in XSA-407 (Branch Type Confusion), the mitigation is not applied properly when it is intended to be used. XSA-434 (Speculative Return Stack Overflow) uses the same infrastructure, so is equally impacted. For more details, see: https://xenbits.xen.org/xsa/advisory-407.html https://xenbits.xen.org/xsa/advisory-434.html
nvd
CVE-2021-32749P3HIGHCVSS 8.1v34v352021-07-16
CVE-2021-32749 [HIGH] CWE-78 CVE-2021-32749: fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and p fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action mail-whois. Command `mail` from mailutils package used in mail actions like `mail-whois` can execute comma
nvd
CVE-2021-3773P3CRITICALCVSS 9.8v342022-02-16
CVE-2021-3773 [CRITICAL] CWE-200 CVE-2021-3773: A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint in A flaw in netfilter could allow a network-connected attacker to infer openvpn connection endpoint information for further use in traditional network attacks.
nvd
CVE-2020-25097P3HIGHCVSS 8.6v32v33+1 more2021-03-19
CVE-2020-25097 [HIGH] CWE-20 CVE-2020-25097: An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validatio An issue was discovered in Squid through 4.13 and 5.x through 5.0.4. Due to improper input validation, it allows a trusted client to perform HTTP Request Smuggling and access services otherwise forbidden by the security controls. This occurs for certain uri_whitespace configuration settings.
nvd
CVE-2019-11068P3CRITICALCVSS 9.8v29v302019-04-10
CVE-2019-11068 [CRITICAL] CVE-2019-11068: libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and libxslt through 1.1.33 allows bypass of a protection mechanism because callers of xsltCheckRead and xsltCheckWrite permit access even upon receiving a -1 error code. xsltCheckRead can return -1 for a crafted URL that is not actually invalid and is subsequently loaded.
nvd
CVE-2023-6185P3HIGHCVSS 8.8v382023-12-11
CVE-2023-6185 [HIGH] CVE-2023-6185: Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOff Improper Input Validation vulnerability in GStreamer integration of The Document Foundation LibreOffice allows an attacker to execute arbitrary GStreamer plugins. In affected versions the filename of the embedded video is not sufficiently escaped when passed to GStreamer enabling an attacker to run arbitrary gstreamer plugins depending on what plugins are inst
nvd
CVE-2021-38297P3CRITICALCVSS 9.8v34v352021-10-18
CVE-2021-38297 [CRITICAL] CWE-120 CVE-2021-38297: Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function in Go before 1.16.9 and 1.17.x before 1.17.2 has a Buffer Overflow via large arguments in a function invocation from a WASM module, when GOARCH=wasm GOOS=js is used.
nvd
CVE-2020-28035P3CRITICALCVSS 9.8v31v32+1 more2020-11-02
CVE-2020-28035 [CRITICAL] CVE-2020-28035: WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC. WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.
nvd
CVE-2016-4861P3CRITICALCVSS 9.8v23v24+1 more2017-02-17
CVE-2016-4861 [CRITICAL] CWE-89 CVE-2016-4861: The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might all The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.20 might allow remote attackers to conduct SQL injection attacks by leveraging failure to remove comments from an SQL statement before validation.
nvd
CVE-2016-8606P3CRITICALCVSS 9.8v23v24+1 more2017-01-12
CVE-2016-8606 [CRITICAL] CWE-284 CVE-2016-8606: The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an H The REPL server (--listen) in GNU Guile 2.0.12 allows an attacker to execute arbitrary code via an HTTP inter-protocol attack.
nvd
CVE-2024-32459P3CRITICALCVSS 9.8v38v39+1 more2024-04-22
CVE-2024-32459 [CRITICAL] CWE-125 CVE-2024-32459: FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers t FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available.
nvd
CVE-2022-26496P3CRITICALCVSS 9.8v34v35+1 more2022-03-06
CVE-2022-26496 [CRITICAL] CWE-787 CVE-2022-26496: In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a bu In nbd-server in nbd before 3.24, there is a stack-based buffer overflow. An attacker can cause a buffer overflow in the parsing of the name field by sending a crafted NBD_OPT_INFO or NBD_OPT_GO message with an large value as the length of the name.
nvd
CVE-2022-0730P3CRITICALCVSS 9.8v34v35+1 more2022-03-03
CVE-2022-0730 [CRITICAL] CWE-287 CVE-2022-0730: Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types. Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
nvd
CVE-2018-8786P3CRITICALCVSS 9.8v282018-11-29
CVE-2018-8786 [CRITICAL] CWE-680 CVE-2018-8786: FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.
nvd
CVE-2020-35701P3HIGHCVSS 8.8v32v33+1 more2021-01-11
CVE-2020-35701 [HIGH] CWE-89 CVE-2020-35701: An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.p An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.
nvd
CVE-2022-4170P3CRITICALCVSS 9.8v372022-12-09
CVE-2022-4170 [CRITICAL] CWE-74 CVE-2022-4170: The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
nvd
CVE-2024-1675P3HIGHCVSS 8.8v38v392024-02-21
CVE-2024-1675 [HIGH] CWE-284 CVE-2024-1675: Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2023-46850P3CRITICALCVSS 9.8v392023-11-11
CVE-2023-46850 [CRITICAL] CWE-416 CVE-2023-46850: Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buff Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
nvd
CVE-2023-29402P3CRITICALCVSS 9.8v382023-06-08
CVE-2023-29402 [CRITICAL] CWE-94 CVE-2023-29402: The go command may generate unexpected code at build time when using cgo. This may result in unexpec The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules which are retrieved using the go command, i.e. via "go get", are not aff
nvd
Fedoraproject Fedora vulnerabilities | cvebase