cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 251 of 264
CVE-2023-22840P4MEDIUMCVSS 5.5v37v38+1 more2023-08-11
CVE-2023-22840 [MEDIUM] CWE-86 CVE-2023-22840: Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may a Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable denial of service via local access.
nvd
CVE-2022-4285P4MEDIUMCVSS 5.5v372023-01-27
CVE-2022-4285 [MEDIUM] CVE-2022-4285: An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corr An illegal memory access flaw was found in the binutils package. Parsing an ELF file containing corrupt symbol version information may result in a denial of service. This issue is the result of an incomplete fix for CVE-2020-16599.
nvd
CVE-2023-2731P4MEDIUMCVSS 5.5v382023-05-17
CVE-2023-2731 [MEDIUM] CWE-476 CVE-2023-2731: A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c A NULL pointer dereference flaw was found in Libtiff's LZWDecode() function in the libtiff/tif_lzw.c file. This flaw allows a local attacker to craft specific input data that can cause the program to dereference a NULL pointer when decompressing a TIFF format file, resulting in a program crash or denial of service.
nvd
CVE-2024-4853P4MEDIUMCVSS 5.5v39v402024-05-14
CVE-2024-4853 [MEDIUM] CWE-762 CVE-2024-4853: Memory handling issue in editcap could cause denial of service via crafted capture file Memory handling issue in editcap could cause denial of service via crafted capture file
nvd
CVE-2021-44647P4MEDIUMCVSS 5.5v342022-01-11
CVE-2021-44647 [MEDIUM] CWE-843 CVE-2021-44647: Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.
nvd
CVE-2021-46661P4MEDIUMCVSS 5.5v34v35+1 more2022-02-01
CVE-2021-46661 [MEDIUM] CVE-2021-46661: MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list vi MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).
nvd
CVE-2021-46665P4MEDIUMCVSS 5.5v34v35+1 more2022-02-01
CVE-2021-46665 [MEDIUM] CVE-2021-46665: MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expe MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.
nvd
CVE-2021-46664P4MEDIUMCVSS 5.5v34v35+1 more2022-02-01
CVE-2021-46664 [MEDIUM] CWE-476 CVE-2021-46664: MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of a MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.
nvd
CVE-2019-19043P4MEDIUMCVSS 5.5v30v312019-11-18
CVE-2019-19043 [MEDIUM] CWE-401 CVE-2019-19043: A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c i A memory leak in the i40e_setup_macvlans() function in drivers/net/ethernet/intel/i40e/i40e_main.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering i40e_setup_channel() failures, aka CID-27d461333459.
nvd
CVE-2013-1820P4MEDIUMCVSS 5.5v172019-11-08
CVE-2013-1820 [MEDIUM] CWE-20 CVE-2013-1820: tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
nvd
CVE-2023-34474P4MEDIUMCVSS 5.5v37v382023-06-16
CVE-2023-34474 [MEDIUM] CWE-122 CVE-2023-34474: A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in c A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
nvd
CVE-2023-38252P4MEDIUMCVSS 5.5v382023-07-14
CVE-2023-38252 [MEDIUM] CWE-125 CVE-2023-38252: An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may al An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
nvd
CVE-2023-38253P4MEDIUMCVSS 5.5v382023-07-14
CVE-2023-38253 [MEDIUM] CWE-125 CVE-2023-38253: An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue m An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.
nvd
CVE-2019-9705P4MEDIUMCVSS 5.5v292019-03-12
CVE-2019-9705 [MEDIUM] CWE-770 CVE-2019-9705: Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (mem Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.
nvd
CVE-2022-38533P4MEDIUMCVSS 5.5v36v372022-08-26
CVE-2022-38533 [MEDIUM] CWE-787 CVE-2022-38533: In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when c In GNU Binutils before 2.40, there is a heap-buffer-overflow in the error function bfd_getl32 when called from the strip_main function in strip-new via a crafted file.
nvd
CVE-2021-4148P4MEDIUMCVSS 5.5v352022-03-23
CVE-2021-4148 [MEDIUM] CWE-354 CVE-2021-4148: A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesyste A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.
nvd
CVE-2014-7821P4MEDIUMCVSS 4.0v202014-11-24
CVE-2014-7821 [MEDIUM] CWE-20 CVE-2014-7821: OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to OpenStack Neutron before 2014.1.4 and 2014.2.x before 2014.2.1 allows remote authenticated users to cause a denial of service (crash) via a crafted dns_nameservers value in the DNS configuration.
nvd
CVE-2020-2756P4LOWCVSS 3.7v30v31+1 more2020-04-15
CVE-2020-2756 [LOW] CWE-502 CVE-2020-2756: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2020-2757P4LOWCVSS 3.7v30v31+1 more2020-04-15
CVE-2020-2757 [LOW] CWE-502 CVE-2020-2757: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded.
nvd
CVE-2013-1416P4MEDIUMCVSS 4.0v17v182013-04-19
CVE-2013-1416 [MEDIUM] CWE-476 CVE-2013-1416: The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos The prep_reprocess_req function in do_tgs_req.c in the Key Distribution Center (KDC) in MIT Kerberos 5 (aka krb5) before 1.10.5 does not properly perform service-principal realm referral, which allows remote authenticated users to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted TGS-REQ request.
nvd
Fedoraproject Fedora vulnerabilities | cvebase