cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 252 of 264
CVE-2015-2752P4MEDIUMCVSS 4.9v20v212015-04-01
CVE-2015-2752 [MEDIUM] CWE-20 CVE-2015-2752: The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough dev The XEN_DOMCTL_memory_mapping hypercall in Xen 3.2.x through 4.5.x, when using a PCI passthrough device, is not preemptible, which allows local x86 HVM domain users to cause a denial of service (host CPU consumption) via a crafted request to the device model (qemu-dm).
nvd
CVE-2020-14577P4LOWCVSS 3.7v31v322020-07-15
CVE-2020-14577 [LOW] CVE-2020-14577: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supporte Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: JSSE). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TLS to compromise Java SE, Java SE Embedded. Successful attacks of this
nvd
CVE-2020-14581P4LOWCVSS 3.7v31v322020-07-15
CVE-2020-14581 [LOW] CVE-2020-14581: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of
nvd
CVE-2022-21522P4MEDIUMCVSS 4.4v35v362022-07-19
CVE-2022-21522 [MEDIUM] CVE-2022-21522: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Sup Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Stored Procedure). Supported versions that are affected are 8.0.29 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2022-25258P4MEDIUMCVSS 4.6v352022-02-16
CVE-2022-25258 [MEDIUM] CWE-476 CVE-2022-25258: An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The US An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.
nvd
CVE-2021-22890P4LOWCVSS 3.7v32v33+1 more2021-04-01
CVE-2021-22890 [LOW] CWE-300 CVE-2021-22890: curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MI curl 7.63.0 to and including 7.75.0 includes vulnerability that allows a malicious HTTPS proxy to MITM a connection due to bad handling of TLS 1.3 session tickets. When using a HTTPS proxy and TLS 1.3, libcurl can confuse session tickets arriving from the HTTPS proxy but work as if they arrived from the remote server and then wrongly "short-cut" the ho
nvd
CVE-2023-21947P4MEDIUMCVSS 4.4v37v38+1 more2023-04-18
CVE-2023-21947 [MEDIUM] CVE-2023-21947: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2023-21940P4MEDIUMCVSS 4.4v37v38+1 more2023-04-18
CVE-2023-21940 [MEDIUM] CVE-2023-21940: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthor
nvd
CVE-2023-22005P4MEDIUMCVSS 4.4v37v38+1 more2023-07-18
CVE-2023-22005 [MEDIUM] CVE-2023-22005: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Support Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized abi
nvd
CVE-2011-5268P4MEDIUMCVSS 4.3v18v19+1 more2013-12-24
CVE-2011-5268 [MEDIUM] CWE-310 CVE-2011-5268: connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to c connection.c in Bip before 0.8.9 does not properly close sockets, which allows remote attackers to cause a denial of service (file descriptor consumption and crash) via multiple failed SSL handshakes, a different vulnerability than CVE-2013-4550. NOTE: this issue was SPLIT from CVE-2013-4550 because it is a different type of issue.
nvd
CVE-2023-22033P4MEDIUMCVSS 4.4v37v38+1 more2023-07-18
CVE-2023-22033 [MEDIUM] CVE-2023-22033: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions t Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause
nvd
CVE-2012-0049P4MEDIUMCVSS 4.3v15v162019-11-07
CVE-2012-0049 [MEDIUM] CWE-400 CVE-2012-0049: OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joinin OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.
nvd
CVE-2023-42756P4MEDIUMCVSS 4.7v37v38+1 more2023-09-28
CVE-2023-42756 [MEDIUM] CWE-362 CVE-2023-42756: A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ A flaw was found in the Netfilter subsystem of the Linux kernel. A race condition between IPSET_CMD_ADD and IPSET_CMD_SWAP can lead to a kernel panic due to the invocation of `__ip_set_put` on a wrong `set`. This issue may allow a local user to crash the system.
nvd
CVE-2021-28964P4MEDIUMCVSS 4.7v32v33+1 more2021-03-22
CVE-2021-28964 [MEDIUM] CWE-362 CVE-2021-28964: A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11 A race condition was discovered in get_old_root in fs/btrfs/ctree.c in the Linux kernel through 5.11.8. It allows attackers to cause a denial of service (BUG) because of a lack of locking on an extent buffer before a cloning operation, aka CID-dbcc7d57bffc.
nvd
CVE-2021-21184P4MEDIUMCVSS 4.3v32v33+1 more2021-03-09
CVE-2021-21184 [MEDIUM] CWE-346 CVE-2021-21184: Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a re Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2021-21183P4MEDIUMCVSS 4.3v32v33+1 more2021-03-09
CVE-2021-21183 [MEDIUM] CWE-346 CVE-2021-21183: Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a re Inappropriate implementation in performance APIs in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
nvd
CVE-2018-5730P4LOWCVSS 3.8v26v272018-03-06
CVE-2018-5730 [LOW] CWE-90 CVE-2018-5730: MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Ke MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a container DN string but is not hierarchically within the container DN.
nvd
CVE-2019-5833P4MEDIUMCVSS 4.3v29v302019-06-27
CVE-2019-5833 [MEDIUM] CVE-2019-5833: Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a Incorrect dialog box scoping in browser in Google Chrome on Android prior to 75.0.3770.80 allowed a remote attacker to display misleading security UI via a crafted HTML page.
nvd
CVE-2014-8112P4MEDIUMCVSS 4.0v222015-03-10
CVE-2014-8112 [MEDIUM] CWE-200 CVE-2014-8112: 389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" 389 Directory Server 1.3.1.x, 1.3.2.x before 1.3.2.27, and 1.3.3.x before 1.3.3.9 stores "unhashed" passwords even when the nsslapd-unhashed-pw-switch option is set to off, which allows remote authenticated users to obtain sensitive information by reading the Changelog.
nvd
CVE-2013-2191P4MEDIUMCVSS 4.3v17v182014-02-08
CVE-2013-2191 [MEDIUM] CWE-20 CVE-2013-2191: python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle at python-bugzilla before 0.9.0 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof Bugzilla servers via a crafted certificate.
nvd
Fedoraproject Fedora vulnerabilities | cvebase