cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 257 of 264
CVE-2022-2719P4MEDIUMCVSS 5.5v362022-08-10
CVE-2022-2719 [MEDIUM] CWE-617 CVE-2022-2719: In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was mad In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.
nvd
CVE-2024-26986P4MEDIUMCVSS 5.5v38v39+1 more2024-05-01
CVE-2024-26986 [MEDIUM] CWE-401 CVE-2024-26986: In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix memory leak in In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Fix memory leak in create_process failure Fix memory leak due to a leaked mmget reference on an error handling code path that is triggered when attempting to create KFD processes while a GPU reset is in progress.
nvd
CVE-2009-1903P4MEDIUMCVSS 4.3v9v102009-06-03
CVE-2009-1903 [MEDIUM] CVE-2009-1903: The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial The PDF XSS protection feature in ModSecurity before 2.5.8 allows remote attackers to cause a denial of service (Apache httpd crash) via a request for a PDF file that does not use the GET method.
nvd
CVE-2009-1242P4MEDIUMCVSS 4.9v102009-04-06
CVE-2009-1242 [MEDIUM] CWE-20 CVE-2009-1242: The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the The vmx_set_msr function in arch/x86/kvm/vmx.c in the VMX implementation in the KVM subsystem in the Linux kernel before 2.6.29.1 on the i386 platform allows guest OS users to cause a denial of service (OOPS) by setting the EFER_LME (aka "Long mode enable") bit in the Extended Feature Enable Register (EFER) model-specific register, which is specific to
nvd
CVE-2010-4169P4MEDIUMCVSS 4.9v132010-11-22
CVE-2010-4169 [MEDIUM] CWE-416 CVE-2010-4169: Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local use Use-after-free vulnerability in mm/mprotect.c in the Linux kernel before 2.6.37-rc2 allows local users to cause a denial of service via vectors involving an mprotect system call.
nvd
CVE-2010-3698P4MEDIUMCVSS 4.9v132010-11-26
CVE-2010-3698 [MEDIUM] CWE-400 CVE-2010-3698: The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segm The KVM implementation in the Linux kernel before 2.6.36 does not properly reload the FS and GS segment registers, which allows host OS users to cause a denial of service (host OS crash) via a KVM_RUN ioctl call in conjunction with a modified Local Descriptor Table (LDT).
nvd
CVE-2019-19063P4MEDIUMCVSS 4.6v30v312019-11-18
CVE-2019-19063 [MEDIUM] CWE-401 CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in th Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption), aka CID-3f9361695113.
nvd
CVE-2019-19066P4MEDIUMCVSS 4.7v30v312019-11-18
CVE-2019-19066 [MEDIUM] CWE-401 CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kerne A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
nvd
CVE-2018-19489P4MEDIUMCVSS 4.7v292018-12-13
CVE-2018-19489 [MEDIUM] CWE-362 CVE-2018-19489: v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) becaus v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.
nvd
CVE-2010-3442P4MEDIUMCVSS 4.7v132010-10-04
CVE-2010-3442 [MEDIUM] CWE-190 CVE-2010-3442: Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel b Multiple integer overflows in the snd_ctl_new function in sound/core/control.c in the Linux kernel before 2.6.36-rc5-next-20100929 allow local users to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a crafted (1) SNDRV_CTL_IOCTL_ELEM_ADD or (2) SNDRV_CTL_IOCTL_ELEM_REPLACE ioctl call.
nvd
CVE-2019-19059P4MEDIUMCVSS 4.7v30v312019-11-18
CVE-2019-19059 [MEDIUM] CWE-401 CVE-2019-19059: Multiple memory leaks in the iwl_pcie_ctxt_info_gen3_init() function in drivers/net/wireless/intel/i Multiple memory leaks in the iwl_pcie_ctxt_info_gen3_init() function in drivers/net/wireless/intel/iwlwifi/pcie/ctxt-info-gen3.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering iwl_pcie_init_fw_sec() or dma_alloc_coherent() failures, aka CID-0f4f199443fa.
nvd
CVE-2020-25604P4MEDIUMCVSS 4.7v31v32+1 more2020-09-23
CVE-2020-25604 [MEDIUM] CWE-362 CVE-2020-25604: An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers betwe An issue was discovered in Xen through 4.14.x. There is a race condition when migrating timers between x86 HVM vCPUs. When migrating timers of x86 HVM guests between its vCPUs, the locking model used allows for a second vCPU of the same guest (also operating on the timers) to release a lock that it didn't acquire. The most likely effect of the issue
nvd
CVE-2021-2341P4LOWCVSS 3.1v33v342021-07-21
CVE-2021-2341 [LOW] CVE-2021-2341: Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component Vulnerability in the Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Java SE: 7u301, 8u291, 11.0.11, 16.0.1; Oracle GraalVM Enterprise Edition: 20.3.2 and 21.1.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to c
nvd
CVE-2008-3221P4MEDIUMCVSS 4.3v8v92008-07-18
CVE-2008-3221 [MEDIUM] CWE-352 CVE-2008-3221: Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to Cross-site request forgery (CSRF) vulnerability in Drupal 6.x before 6.3 allows remote attackers to perform administrative actions via vectors involving deletion of OpenID identities.
nvd
CVE-2015-4807P4LOWCVSS 3.5v232015-10-21
CVE-2015-4807 [LOW] CVE-2015-4807: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier, when run Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier and 5.6.26 and earlier, when running on Windows, allows remote authenticated users to affect availability via unknown vectors related to Server : Query Cache.
nvd
CVE-2022-0216P4MEDIUMCVSS 4.4v372022-08-26
CVE-2022-0216 [MEDIUM] CWE-416 CVE-2022-0216: A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.
nvd
CVE-2023-3212P4MEDIUMCVSS 4.4v382023-06-23
CVE-2023-3212 [MEDIUM] CWE-476 CVE-2023-3212: A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on A NULL pointer dereference issue was found in the gfs2 file system in the Linux kernel. It occurs on corrupt gfs2 file systems when the evict code tries to reference the journal descriptor structure after it has been freed and set to NULL. A privileged local user could use this flaw to cause a kernel panic.
nvd
CVE-2015-4836P4LOWCVSS 2.8v232015-10-21
CVE-2015-4836 [LOW] CVE-2015-4836: Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated users to affect availability via unknown vectors related to Server : SP.
nvd
CVE-2022-39399P4LOWCVSS 3.7v35v362022-10-18
CVE-2022-39399 [LOW] CWE-284 CVE-2022-39399: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Networking). Supported versions that are affected are Oracle Java SE: 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access v
nvd
CVE-2022-21624P4LOWCVSS 3.7v35v362022-10-18
CVE-2022-21624 [LOW] CWE-502 CVE-2022-21624: Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (co Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: JNDI). Supported versions that are affected are Oracle Java SE: 8u341, 8u345-perf, 11.0.16.1, 17.0.4.1, 19; Oracle GraalVM Enterprise Edition: 20.3.7, 21.3.3 and 22.2.0. Difficult to exploit vulnerability allows unauthenticated attacker with net
nvd
Fedoraproject Fedora vulnerabilities | cvebase