Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 253 of 264
CVE-2021-21147P4MEDIUMCVSS 4.3v32v332021-02-09
CVE-2021-21147 [MEDIUM] CVE-2021-21147: Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacke
Inappropriate implementation in Skia in Google Chrome prior to 88.0.4324.146 allowed a local attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
nvd
CVE-2022-0238P4MEDIUMCVSS 4.3v34v352022-01-16
CVE-2022-0238 [MEDIUM] CWE-352 CVE-2022-0238: phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
nvd
CVE-2021-30630P4MEDIUMCVSS 4.3v33v352021-10-08
CVE-2021-30630 [MEDIUM] CWE-346 CVE-2021-30630: Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attack
Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
nvd
CVE-2023-28322P4LOWCVSS 3.7v37v382023-05-26
CVE-2023-28322 [LOW] CWE-200 CVE-2023-28322: An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl
An information disclosure vulnerability exists in curl <v8.1.0 when doing HTTP(S) transfers, libcurl might erroneously use the read callback (`CURLOPT_READFUNCTION`) to ask for data to send, even when the `CURLOPT_POSTFIELDS` option has been set, if the same handle previously wasused to issue a `PUT` request which used that callback. This flaw may surp
nvd
CVE-2014-1571P4MEDIUMCVSS 4.0v19v20+1 more2014-10-13
CVE-2014-1571 [MEDIUM] CWE-200 CVE-2014-1571: Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.
Bugzilla 2.x through 4.0.x before 4.0.15, 4.1.x and 4.2.x before 4.2.11, 4.3.x and 4.4.x before 4.4.6, and 4.5.x before 4.5.6 allows remote authenticated users to obtain sensitive private-comment information by leveraging a role as a flag recipient, related to Bug.pm, Flag.pm, and a mail template.
nvd
CVE-2020-10724P4MEDIUMCVSS 4.4v322020-05-19
CVE-2020-10724 [MEDIUM] CWE-190 CVE-2020-10724: A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing
A vulnerability was found in DPDK versions 18.11 and above. The vhost-crypto library code is missing validations for user-supplied values, potentially allowing an information leak through an out-of-bounds memory read.
nvd
CVE-2020-12402P4MEDIUMCVSS 4.4v322020-07-09
CVE-2020-12402 [MEDIUM] CWE-203 CVE-2020-12402: During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean
During RSA key generation, bignum implementations used a variation of the Binary Extended Euclidean Algorithm which entailed significantly input-dependent flow. This allowed an attacker able to perform electromagnetic-based side channel attacks to record traces leading to the recovery of the secret primes. *Note:* An unmodified Firefox browser does n
nvd
CVE-2016-1899P4LOWCVSS 3.7v222016-01-20
CVE-2016-1899 [LOW] CVE-2016-1899: CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to i
CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via CRLF sequences in the mimetype parameter, as demonstrated by a request to blob/cgit.c.
nvd
CVE-2024-2004P4LOWCVSS 3.5v39v402024-03-27
CVE-2024-2004 [LOW] CWE-436 CVE-2024-2004: When a protocol selection parameter option disables all protocols without adding any then the defaul
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to curl.se with a plaintext protocol which has been explicitly disabled. curl --proto -all,-http http://curl.s
nvd
CVE-2014-8737P4LOWCVSS 3.6v19v20+1 more2014-12-09
CVE-2014-8737 [LOW] CWE-22 CVE-2014-8737: Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to d
Multiple directory traversal vulnerabilities in GNU binutils 2.24 and earlier allow local users to delete arbitrary files via a .. (dot dot) or full path name in an archive to (1) strip or (2) objcopy or create arbitrary files via (3) a .. (dot dot) or full path name in an archive to ar.
nvd
CVE-2016-8691P4MEDIUMCVSS 5.5v252017-02-15
CVE-2016-8691 [MEDIUM] CWE-369 CVE-2016-8691: The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote a
The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted XRsiz value in a BMP image to the imginfo command.
nvd
CVE-2016-8692P4MEDIUMCVSS 5.5v252017-02-15
CVE-2016-8692 [MEDIUM] CWE-369 CVE-2016-8692: The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote a
The jpc_dec_process_siz function in libjasper/jpc/jpc_dec.c in JasPer before 1.900.4 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted YRsiz value in a BMP image to the imginfo command.
nvd
CVE-2016-4797P4MEDIUMCVSS 5.5v23v242017-02-03
CVE-2016-4797 [MEDIUM] CVE-2016-4797: Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 all
Divide-by-zero vulnerability in the opj_tcd_init_tile function in tcd.c in OpenJPEG before 2.1.1 allows remote attackers to cause a denial of service (application crash) via a crafted jp2 file. NOTE: this issue exists because of an incorrect fix for CVE-2014-7947.
nvd
CVE-2013-2139P4LOWCVSS 2.6v18v19+1 more2014-01-16
CVE-2013-2139 [LOW] CWE-119 CVE-2013-2139: Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a de
Buffer overflow in srtp.c in libsrtp in srtp 1.4.5 and earlier allows remote attackers to cause a denial of service (crash) via vectors related to a length inconsistency in the crypto_policy_set_from_profile_for_rtp and srtp_protect functions.
nvd
CVE-2022-30975P4MEDIUMCVSS 5.5v372022-05-18
CVE-2022-30975 [MEDIUM] CWE-476 CVE-2022-30975: In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonst
In Artifex MuJS through 1.2.0, jsP_dumpsyntax in jsdump.c has a NULL pointer dereference, as demonstrated by mujs-pp.
nvd
CVE-2019-20021P4MEDIUMCVSS 5.5v30v312019-12-27
CVE-2019-20021 [MEDIUM] CWE-125 CVE-2019-20021: A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Ma
A heap-based buffer over-read was discovered in canUnpack in p_mach.cpp in UPX 3.95 via a crafted Mach-O file.
nvd
CVE-2022-33070P4MEDIUMCVSS 5.5v362022-06-23
CVE-2022-33070 [MEDIUM] CVE-2022-33070: Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_a
Protobuf-c v1.4.0 was discovered to contain an invalid arithmetic shift via the function parse_tag_and_wiretype in protobuf-c/protobuf-c.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
nvd
CVE-2022-27939P4MEDIUMCVSS 5.5v35v36+1 more2022-03-26
CVE-2022-27939 [MEDIUM] CWE-617 CVE-2022-27939: tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.
nvd
CVE-2023-31489P4MEDIUMCVSS 5.5v37v38+1 more2023-05-09
CVE-2023-31489 [MEDIUM] CVE-2023-31489: An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via t
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.
nvd
CVE-2021-46022P4MEDIUMCVSS 5.5v35v362022-01-14
CVE-2021-46022 [MEDIUM] CWE-416 CVE-2021-46022: An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
nvd