Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 256 of 264
CVE-2021-25284P4MEDIUMCVSS 4.4v32v33+1 more2021-02-27
CVE-2021-25284 [MEDIUM] CWE-522 CVE-2021-25284: An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credent
An issue was discovered in through SaltStack Salt before 3002.5. salt.modules.cmdmod can log credentials to the info or error log level.
nvd
CVE-2021-2007P4LOWCVSS 3.7v32v332021-01-20
CVE-2021-2007 [LOW] CVE-2021-2007: Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions tha
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can resul
nvd
CVE-2014-1517P4MEDIUMCVSS 4.0v19v202014-04-20
CVE-2014-1517 [MEDIUM] CWE-287 CVE-2014-1517: The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly hand
The login form in Bugzilla 2.x, 3.x, 4.x before 4.4.3, and 4.5.x before 4.5.3 does not properly handle a correctly authenticated but unintended login attempt, which makes it easier for remote authenticated users to obtain sensitive information by arranging for a victim to login to the attacker's account and then submit a vulnerability report, related
nvd
CVE-2021-3802P4MEDIUMCVSS 4.2v342021-11-29
CVE-2021-3802 [MEDIUM] CWE-20 CVE-2021-3802: A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image fi
A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.
nvd
CVE-2023-23908P4MEDIUMCVSS 4.4v37v382023-08-11
CVE-2023-23908 [MEDIUM] CWE-284 CVE-2023-23908: Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a priv
Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2021-3635P4MEDIUMCVSS 4.4v342021-08-13
CVE-2021-3635 [MEDIUM] CWE-119 CVE-2021-3635: A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user w
A flaw was found in the Linux kernel netfilter implementation in versions prior to 5.5-rc7. A user with root (CAP_SYS_ADMIN) access is able to panic the system when issuing netfilter netflow commands.
nvd
CVE-2014-2287P4LOWCVSS 3.5v19v202014-04-18
CVE-2014-2287 [LOW] CWE-20 CVE-2014-2287: channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x
channels/chan_sip.c in Asterisk Open Source 1.8.x before 1.8.26.1, 11.8.x before 11.8.1, and 12.1.x before 12.1.1, and Certified Asterisk 1.8.15 before 1.8.15-cert5 and 11.6 before 11.6-cert2, when chan_sip has a certain configuration, allows remote authenticated users to cause a denial of service (channel and file descriptor consumption) via an INVITE req
nvd
CVE-2020-11810P4LOWCVSS 3.7v30v322020-04-27
CVE-2020-11810 [LOW] CWE-362 CVE-2020-11810: An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_D
An issue was discovered in OpenVPN 2.4.x before 2.4.9. An attacker can inject a data channel v2 (P_DATA_V2) packet using a victim's peer-id. Normally such packets are dropped, but if this packet arrives before the data channel crypto parameters have been initialized, the victim's connection will be dropped. This requires careful timing due to the small
nvd
CVE-2023-46840P4MEDIUMCVSS 4.1v392024-03-20
CVE-2023-46840 [MEDIUM] CWE-670 CVE-2023-46840: Incorrect placement of a preprocessor directive in source code results in logic that doesn't operate
Incorrect placement of a preprocessor directive in source code results
in logic that doesn't operate as intended when support for HVM guests is
compiled out of Xen.
nvd
CVE-2020-15103P4LOWCVSS 3.5v31v322020-07-27
CVE-2020-15103 [LOW] CWE-680 CVE-2020-15103: In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation i
In FreeRDP less than or equal to 2.1.2, an integer overflow exists due to missing input sanitation in rdpegfx channel. All FreeRDP clients are affected. The input rectangles from the server are not checked against local surface coordinates and blindly accepted. A malicious server can send data that will crash the client later on (invalid length argumen
nvd
CVE-2020-16116P4LOWCVSS 3.3v31v322020-08-03
CVE-2020-16116 [LOW] CWE-22 CVE-2020-16116: In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the ext
In kerfuffle/jobs.cpp in KDE Ark before 20.08.0, a crafted archive can install files outside the extraction directory via ../ directory traversal.
nvd
CVE-2021-30501P4MEDIUMCVSS 5.5v332021-05-27
CVE-2021-30501 [MEDIUM] CWE-20 CVE-2021-30501: An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow al
An assertion abort was found in upx MemBuffer::alloc() in mem.cpp, in version UPX 4.0.0. The flow allows attackers to cause a denial of service (abort) via a crafted file.
nvd
CVE-2022-0476P4MEDIUMCVSS 5.5v35v362022-02-23
CVE-2022-0476 [MEDIUM] CWE-400 CVE-2022-0476: Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
nvd
CVE-2021-46019P4MEDIUMCVSS 5.5v35v362022-01-14
CVE-2021-46019 [MEDIUM] CWE-476 CVE-2021-46019: An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to
An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
nvd
CVE-2022-0695P4MEDIUMCVSS 5.5v35v362022-02-24
CVE-2022-0695 [MEDIUM] CWE-400 CVE-2022-0695: Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.
nvd
CVE-2022-35018P4MEDIUMCVSS 5.5v35v36+1 more2022-08-29
CVE-2022-35018 [MEDIUM] CVE-2022-35018: Advancecomp v2.3 was discovered to contain a segmentation fault.
Advancecomp v2.3 was discovered to contain a segmentation fault.
nvd
CVE-2022-35019P4MEDIUMCVSS 5.5v35v36+1 more2022-08-29
CVE-2022-35019 [MEDIUM] CVE-2022-35019: Advancecomp v2.3 was discovered to contain a segmentation fault.
Advancecomp v2.3 was discovered to contain a segmentation fault.
nvd
CVE-2023-1264P4MEDIUMCVSS 5.5v37v382023-03-07
CVE-2023-1264 [MEDIUM] CWE-476 CVE-2023-1264: NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.
nvd
CVE-2015-4792P4LOWCVSS 1.7v232015-10-21
CVE-2015-4792 [LOW] CVE-2015-4792: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows re
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : Partition, a different vulnerability than CVE-2015-4802.
nvd
CVE-2019-9704P4MEDIUMCVSS 5.5v292019-03-12
CVE-2019-9704 [MEDIUM] CWE-252 CVE-2019-9704: Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (dae
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
nvd