cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 254 of 264
CVE-2021-46021P4MEDIUMCVSS 5.5v35v362022-01-14
CVE-2021-46021 [MEDIUM] CWE-416 CVE-2021-46021: An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
nvd
CVE-2022-0712P4MEDIUMCVSS 5.5v35v362022-02-22
CVE-2022-0712 [MEDIUM] CWE-476 CVE-2022-0712: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4. NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.
nvd
CVE-2020-23903P4MEDIUMCVSS 5.5v34v352021-11-10
CVE-2020-23903 [MEDIUM] CWE-369 CVE-2020-23903: A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attacker A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.
nvd
CVE-2022-0419P4MEDIUMCVSS 5.5v34v352022-02-01
CVE-2022-0419 [MEDIUM] CWE-476 CVE-2022-0419: NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0. NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
nvd
CVE-2022-3278P4MEDIUMCVSS 5.5v35v36+1 more2022-09-23
CVE-2022-3278 [MEDIUM] CWE-476 CVE-2022-3278: NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552. NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.
nvd
CVE-2022-2980P4MEDIUMCVSS 5.5v372022-08-25
CVE-2022-2980 [MEDIUM] CWE-476 CVE-2022-2980: NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259. NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.
nvd
CVE-2021-46659P4MEDIUMCVSS 5.5v34v35+1 more2022-01-29
CVE-2021-46659 [MEDIUM] CVE-2021-46659: MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nes MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
nvd
CVE-2016-9960P4MEDIUMCVSS 5.5v24v252017-06-06
CVE-2016-9960 [MEDIUM] CWE-369 CVE-2016-9960: game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and proc game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
nvd
CVE-2012-1146P4MEDIUMCVSS 5.5v162012-05-17
CVE-2012-1146 [MEDIUM] CWE-476 CVE-2012-1146: The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 The mem_cgroup_usage_unregister_event function in mm/memcontrol.c in the Linux kernel before 3.2.10 does not properly handle multiple events that are attached to the same eventfd, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by registering memory threshold ev
nvd
CVE-2022-2923P4MEDIUMCVSS 5.5v352022-08-22
CVE-2022-2923 [MEDIUM] CWE-476 CVE-2022-2923: NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240. NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240.
nvd
CVE-2023-2609P4MEDIUMCVSS 5.5v372023-05-09
CVE-2023-2609 [MEDIUM] CWE-476 CVE-2023-2609: NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531. NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1531.
nvd
CVE-2022-3213P4MEDIUMCVSS 5.5v35v36+1 more2022-09-19
CVE-2022-3213 [MEDIUM] CWE-119 CVE-2022-3213: A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIF A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.
nvd
CVE-2023-5441P4MEDIUMCVSS 5.5v37v38+1 more2023-10-05
CVE-2023-5441 [MEDIUM] CWE-476 CVE-2023-5441: NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8 NULL Pointer Dereference in GitHub repository vim/vim prior to 20d161ace307e28690229b68584f2d84556f8960.
nvd
CVE-2021-46667P4MEDIUMCVSS 5.5v34v35+1 more2022-02-01
CVE-2021-46667 [MEDIUM] CWE-190 CVE-2021-46667: MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash. MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
nvd
CVE-2019-18811P4MEDIUMCVSS 5.5v30v312019-11-07
CVE-2019-18811 [MEDIUM] CWE-401 CVE-2019-18811: A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kern A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
nvd
CVE-2019-18808P4MEDIUMCVSS 5.5v30v312019-11-07
CVE-2019-18808 [MEDIUM] CWE-401 CVE-2019-18808: A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel A memory leak in the ccp_run_sha_cmd() function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-128c66429247.
nvd
CVE-2022-37290P4MEDIUMCVSS 5.5v36v372022-11-14
CVE-2022-37290 [MEDIUM] CWE-476 CVE-2022-37290: GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a paste GNOME Nautilus 42.2 allows a NULL pointer dereference and get_basename application crash via a pasted ZIP archive.
nvd
CVE-2008-1567P4MEDIUMCVSS 5.5v7v82008-03-31
CVE-2008-1567 [MEDIUM] CWE-312 CVE-2008-1567: phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secr phpMyAdmin before 2.11.5.1 stores the MySQL (1) username and (2) password, and the (3) Blowfish secret key, in cleartext in a Session file under /tmp, which allows local users to obtain sensitive information.
nvd
CVE-2024-31585P4MEDIUMCVSS 5.3v38v39+1 more2024-04-17
CVE-2024-31585 [MEDIUM] CWE-193 CVE-2024-31585: FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilt FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
nvd
CVE-2020-2754P4LOWCVSS 3.7v30v31+1 more2020-04-15
CVE-2020-2754 [LOW] CVE-2020-2754: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks
nvd
Fedoraproject Fedora vulnerabilities | cvebase