cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 250 of 264
CVE-2022-4917P4MEDIUMCVSS 4.3v382023-07-29
CVE-2022-4917 [MEDIUM] CWE-346 CVE-2022-4917: Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low)
nvd
CVE-2021-28163P4LOWCVSS 2.7v32v33+1 more2021-04-01
CVE-2021-28163 [LOW] CWE-200 CVE-2021-28163: In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user use In Eclipse Jetty 9.4.32 to 9.4.38, 10.0.0.beta2 to 10.0.1, and 11.0.0.beta2 to 11.0.1, if a user uses a webapps directory that is a symlink, the contents of the webapps directory is deployed as a static webapp, inadvertently serving the webapps themselves and anything else that might be in that directory.
nvd
CVE-2020-13882P4MEDIUMCVSS 4.2v31v322020-06-18
CVE-2020-13882 [MEDIUM] CWE-367 CVE-2020-13882: CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routi CISOfy Lynis before 3.0.0 has Incorrect Access Control because of a TOCTOU race condition. The routine to check the log and report file permissions was not working as intended and could be bypassed locally. Because of the race, an unprivileged attacker can set up a log and report file, and control that up to the point where the specific routine is d
nvd
CVE-2023-50007P4MEDIUMCVSS 4.0v38v39+1 more2024-04-19
CVE-2023-50007 [MEDIUM] CWE-121 CVE-2023-50007: FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.
nvd
CVE-2018-10196P4MEDIUMCVSS 5.5v27v282018-05-30
CVE-2018-10196 [MEDIUM] CWE-476 CVE-2018-10196: NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the do NULL pointer dereference vulnerability in the rebuild_vlists function in lib/dotgen/conc.c in the dotgen library in Graphviz 2.40.1 allows remote attackers to cause a denial of service (application crash) via a crafted file.
nvd
CVE-2022-1674P4MEDIUMCVSS 5.5v34v35+1 more2022-05-12
CVE-2022-1674 [MEDIUM] CWE-476 CVE-2022-1674: NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vi NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 in GitHub repository vim/vim prior to 8.2.4938. NULL Pointer Dereference in function vim_regexec_string at regexp.c:2733 allows attackers to cause a denial of service (application crash) via a crafted input.
nvd
CVE-2017-6888P4MEDIUMCVSS 5.5v32v332018-04-25
CVE-2017-6888 [MEDIUM] CWE-772 CVE-2017-6888: An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC ver An error in the "read_metadata_vorbiscomment_()" function (src/libFLAC/stream_decoder.c) in FLAC version 1.3.2 can be exploited to cause a memory leak via a specially crafted FLAC file.
nvd
CVE-2022-0909P4MEDIUMCVSS 5.5v35v362022-03-11
CVE-2022-0909 [MEDIUM] CWE-369 CVE-2022-0909: Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.
nvd
CVE-2022-0924P4MEDIUMCVSS 5.5v35v362022-03-11
CVE-2022-0924 [MEDIUM] CWE-125 CVE-2022-0924: Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service vi Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.
nvd
CVE-2022-0907P4MEDIUMCVSS 5.5v35v362022-03-11
CVE-2022-0907 [MEDIUM] CWE-252 CVE-2022-0907: Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.
nvd
CVE-2021-27815P4MEDIUMCVSS 5.5v32v33+1 more2021-04-14
CVE-2021-27815 [MEDIUM] CWE-476 CVE-2021-27815: NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in NULL Pointer Deference in the exif command line tool, when printing out XML formatted EXIF data, in exif v0.6.22 and earlier allows attackers to cause a Denial of Service (DoS) by uploading a malicious JPEG file, causing the application to crash.
nvd
CVE-2022-2231P4MEDIUMCVSS 5.5v35v362022-06-28
CVE-2022-2231 [MEDIUM] CWE-476 CVE-2022-2231: NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2. NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.
nvd
CVE-2021-3272P4MEDIUMCVSS 5.5v32v332021-01-27
CVE-2021-3272 [MEDIUM] CWE-125 CVE-2021-3272: jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when the jp2_decode in jp2/jp2_dec.c in libjasper in JasPer 2.0.24 has a heap-based buffer over-read when there is an invalid relationship between the number of channels and the number of image components.
nvd
CVE-2021-26927P4MEDIUMCVSS 5.5v32v33+1 more2021-02-23
CVE-2021-26927 [MEDIUM] CWE-476 CVE-2021-26927: A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may A flaw was found in jasper before 2.0.25. A null pointer dereference in jp2_decode in jp2_dec.c may lead to program crash and denial of service.
nvd
CVE-2020-11863P4MEDIUMCVSS 5.5v312020-05-11
CVE-2020-11863 [MEDIUM] CVE-2020-11863: libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2). libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows denial of service (issue 1 of 2).
nvd
CVE-2020-16269P4MEDIUMCVSS 5.5v32v332020-08-03
CVE-2020-16269 [MEDIUM] CVE-2020-16269: radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse radare2 4.5.0 misparses DWARF information in executable files, causing a segmentation fault in parse_typedef in type_dwarf.c via a malformed DW_AT_name in the .debug_info section.
nvd
CVE-2021-45293P4MEDIUMCVSS 5.5v34v352021-12-21
CVE-2021-45293 [MEDIUM] CWE-119 CVE-2021-45293: A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereferenc A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.
nvd
CVE-2022-48065P4MEDIUMCVSS 5.5v38v392023-08-22
CVE-2022-48065 [MEDIUM] CWE-401 CVE-2022-48065: GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c.
nvd
CVE-2022-35020P4MEDIUMCVSS 5.5v35v36+1 more2022-08-29
CVE-2022-35020 [MEDIUM] CWE-787 CVE-2022-35020: Advancecomp v2.3 was discovered to contain a heap buffer overflow via the component __interceptor_me Advancecomp v2.3 was discovered to contain a heap buffer overflow via the component __interceptor_memcpy at /sanitizer_common/sanitizer_common_interceptors.inc.
nvd
CVE-2022-35015P4MEDIUMCVSS 5.5v35v36+1 more2022-08-29
CVE-2022-35015 [MEDIUM] CWE-787 CVE-2022-35015: Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianr Advancecomp v2.3 was discovered to contain a heap buffer overflow via le_uint32_read at /lib/endianrw.h.
nvd
Fedoraproject Fedora vulnerabilities | cvebase