cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 255 of 264
CVE-2020-14578P4LOWCVSS 3.7v31v322020-07-15
CVE-2020-14578 [LOW] CVE-2020-14578: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of
nvd
CVE-2020-14579P4LOWCVSS 3.7v31v322020-07-15
CVE-2020-14579 [LOW] CVE-2020-14579: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261 and 8u251; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of
nvd
CVE-2008-3218P4MEDIUMCVSS 4.3v8v92008-07-18
CVE-2008-3218 [MEDIUM] CWE-79 CVE-2008-3218: Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers Multiple cross-site scripting (XSS) vulnerabilities in Drupal 6.x before 6.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) free tagging taxonomy terms, which are not properly handled on node preview pages, and (2) unspecified OpenID values.
nvd
CVE-2020-2755P4LOWCVSS 3.7v30v31+1 more2020-04-15
CVE-2020-2755 [LOW] CVE-2020-2755: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Scripting). Supported versions that are affected are Java SE: 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks
nvd
CVE-2020-14779P4LOWCVSS 3.7v31v32+1 more2020-10-21
CVE-2020-14779 [LOW] CVE-2020-14779: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE: 7u271, 8u261, 11.0.8 and 15; Java SE Embedded: 8u261. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Succes
nvd
CVE-2009-2472P4MEDIUMCVSS 4.3v102009-07-22
CVE-2009-2472 [MEDIUM] CWE-79 CVE-2009-2472: Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass."
nvd
CVE-2020-2773P4LOWCVSS 3.7v30v31+1 more2020-04-15
CVE-2020-2773 [LOW] CVE-2020-2773: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supp Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Security). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful at
nvd
CVE-2008-3219P4MEDIUMCVSS 4.3v8v92008-07-18
CVE-2008-3219 [MEDIUM] CWE-79 CVE-2008-3219: The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of t The Drupal filter_xss_admin function in 5.x before 5.8 and 6.x before 6.3 does not "prevent use of the object HTML tag in administrator input," which has unknown impact and attack vectors, probably related to an insufficient cross-site scripting (XSS) protection mechanism.
nvd
CVE-2015-2756P4MEDIUMCVSS 4.9v20v212015-04-01
CVE-2015-2756 [MEDIUM] CWE-264 CVE-2015-2756: QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers QEMU, as used in Xen 3.3.x through 4.5.x, does not properly restrict access to PCI command registers, which might allow local HVM guest users to cause a denial of service (non-maskable interrupt and host crash) by disabling the (1) memory or (2) I/O decoding for a PCI Express device and then accessing the device, which triggers an Unsupported Request
nvd
CVE-2019-19062P4MEDIUMCVSS 4.7v30v312019-11-18
CVE-2019-19062 [MEDIUM] CWE-401 CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel throu A memory leak in the crypto_report() function in crypto/crypto_user_base.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
nvd
CVE-2015-4861P4LOWCVSS 3.5v232015-10-21
CVE-2015-4861 [LOW] CVE-2015-4861: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2019-20919P4MEDIUMCVSS 4.7v312020-09-17
CVE-2019-20919 [MEDIUM] CWE-476 CVE-2019-20919: An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requir An issue was discovered in the DBI module before 1.643 for Perl. The hv_fetch() documentation requires checking for NULL and the code does that. But, shortly thereafter, it calls SvOK(profile), causing a NULL pointer dereference.
nvd
CVE-2020-27820P4MEDIUMCVSS 4.7v332021-11-03
CVE-2020-27820 [MEDIUM] CWE-416 CVE-2020-27820: A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).
nvd
CVE-2021-43976P4MEDIUMCVSS 4.6v34v352021-11-17
CVE-2021-43976 [MEDIUM] CVE-2021-43976: In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c a In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).
nvd
CVE-2008-3220P4MEDIUMCVSS 4.3v8v92008-07-18
CVE-2008-3220 [MEDIUM] CWE-352 CVE-2008-3220: Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows r Cross-site request forgery (CSRF) vulnerability in Drupal 5.x before 5.8 and 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of "translated strings."
nvd
CVE-2015-4106P4MEDIUMCVSS 4.6v20v21+1 more2015-06-03
CVE-2015-4106 [MEDIUM] CWE-863 CVE-2015-4106: QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through de QEMU does not properly restrict write access to the PCI config space for certain PCI pass-through devices, which might allow local x86 HVM guests to gain privileges, cause a denial of service (host crash), obtain sensitive information, or possibly have other unspecified impact via unknown vectors.
nvd
CVE-2007-5594P4MEDIUMCVSS 4.3v72007-10-19
CVE-2007-5594 [MEDIUM] CWE-352 CVE-2007-5594: Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, Drupal 5.x before 5.3 does not apply its Drupal Forms API protection against the user deletion form, which allows remote attackers to delete users via a cross-site request forgery (CSRF) attack.
nvd
CVE-2022-23035P4MEDIUMCVSS 4.6v342022-01-25
CVE-2022-23035 [MEDIUM] CWE-459 CVE-2022-23035: Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical d Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of the device. In the case where an interrupt is not quiescent yet at the time this cleanup gets invoked, the cleanup attempt may be
nvd
CVE-2015-7223P4MEDIUMCVSS 4.0v22v232015-12-16
CVE-2015-7223 [MEDIUM] CWE-264 CVE-2015-7223: The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.
nvd
CVE-2022-21619P4LOWCVSS 3.7v35v362022-10-18
CVE-2022-21619 [LOW] CWE-284 CVE-2022-21619: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with
nvd