Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 258 of 264
CVE-2019-19073P4MEDIUMCVSS 4.0v30v312019-11-18
CVE-2019-19073 [MEDIUM] CWE-401 CVE-2019-19073: Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow at
Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config_pipe_credits() function, the htc_setup_complete() function, and the htc_connect_service() function, aka CID-853
nvd
CVE-2020-11054P4LOWCVSS 3.5v31v322020-05-07
CVE-2020-11054 [LOW] CWE-684 CVE-2020-11054: In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL
In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently loaded again, the URL was mistakenly displayed as green (colors.statusbar.u
nvd
CVE-2023-31124P4LOWCVSS 3.7v37v382023-05-25
CVE-2023-31124 [LOW] CWE-330 CVE-2023-31124: c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools buil
c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE will not be set, as seen when cross compiling aarch64 android. This will downgrade to using rand() as a fallback which could allow an attacker to take advantage of the lack of entropy by not using a CSPRNG. This issue was patc
nvd
CVE-2020-1739P4LOWCVSS 3.9v30v31+1 more2020-03-12
CVE-2020-1739 [LOW] CWE-200 CVE-2020-1739: A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password i
A flaw was found in Ansible 2.7.16 and prior, 2.8.8 and prior, and 2.9.5 and prior when a password is set with the argument "password" of svn module, it is used on svn command line, disclosing to other users within the same node. An attacker could take advantage by reading the cmdline file from that particular PID on the procfs.
nvd
CVE-2023-45143P4LOWCVSS 3.5v37v38+1 more2023-10-12
CVE-2023-45143 [LOW] CWE-200 CVE-2023-45143: Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici alrea
Undici is an HTTP/1.1 client written from scratch for Node.js. Prior to version 5.26.2, Undici already cleared Authorization headers on cross-origin redirects, but did not clear `Cookie` headers. By design, `cookie` headers are forbidden request headers, disallowing them to be set in RequestInit.headers in browser environments. Since undici handles hea
nvd
CVE-2023-4535P4LOWCVSS 3.8v38v392023-11-06
CVE-2023-4535 [LOW] CWE-125 CVE-2023-4535: An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handli
An out-of-bounds read vulnerability was found in OpenSC packages within the MyEID driver when handling symmetric key encryption. Exploiting this flaw requires an attacker to have physical access to the computer and a specially crafted USB device or smart card. This flaw allows the attacker to manipulate APDU responses and potentially gain unauthorized ac
nvd
CVE-2022-41862P4LOWCVSS 3.7v82023-03-03
CVE-2022-41862 [LOW] CWE-200 CVE-2022-41862: In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establi
In PostgreSQL, a modified, unauthenticated server can send an unterminated string during the establishment of Kerberos transport encryption. In certain conditions a server can cause a libpq client to over-read and report an error message containing uninitialized bytes.
nvd
CVE-2020-24654P4LOWCVSS 3.3v32v332020-09-02
CVE-2020-24654 [LOW] CWE-59 CVE-2020-24654: In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extract
In KDE Ark before 20.08.1, a crafted TAR archive with symlinks can install files outside the extraction directory, as demonstrated by a write operation to a user's home directory.
nvd
CVE-2024-30261P4LOWCVSS 3.5v38v39+1 more2024-04-04
CVE-2024-30261 [LOW] CWE-284 CVE-2024-30261: Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity
Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid even if they have been tampered. This vulnerability was patched in version(s) 5.28.4 and 6.11.1.
nvd
CVE-2023-51796P4LOWCVSS 3.6v38v39+1 more2024-04-19
CVE-2023-51796 [LOW] CWE-120 CVE-2023-51796: Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arb
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.
nvd
CVE-2020-4050P4LOWCVSS 3.1v31v322020-06-12
CVE-2020-4050 [LOW] CWE-288 CVE-2020-4050: In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows ar
In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This has been patched in version 5.4.2, along with all the previously affected ver
nvd
CVE-2019-20051P4MEDIUMCVSS 5.5v30v312019-12-27
CVE-2019-20051 [MEDIUM] CWE-682 CVE-2019-20051: A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The
A floating-point exception was discovered in PackLinuxElf::elf_hash in p_lx_elf.cpp in UPX 3.95. The vulnerability causes an application crash, which leads to denial of service.
nvd
CVE-2018-20123P4MEDIUMCVSS 5.5v302018-12-17
CVE-2018-20123 [MEDIUM] CWE-772 CVE-2018-20123: pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
pvrdma_realize in hw/rdma/vmw/pvrdma_main.c in QEMU has a Memory leak after an initialisation error.
nvd
CVE-2019-19054P4MEDIUMCVSS 4.7v30v312019-11-18
CVE-2019-19054 [MEDIUM] CWE-401 CVE-2019-19054: A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Li
A memory leak in the cx23888_ir_probe() function in drivers/media/pci/cx23885/cx23888-ir.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering kfifo_alloc() failures, aka CID-a7b2df76b42b.
nvd
CVE-2010-4162P4MEDIUMCVSS 4.7v132011-01-03
CVE-2010-4162 [MEDIUM] CWE-190 CVE-2010-4162: Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to caus
Multiple integer overflows in fs/bio.c in the Linux kernel before 2.6.36.2 allow local users to cause a denial of service (system crash) via a crafted device ioctl to a SCSI device.
nvd
CVE-2019-19056P4MEDIUMCVSS 4.7v30v312019-11-18
CVE-2019-19056 [MEDIUM] CWE-401 CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifie
A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
nvd
CVE-2019-19058P4MEDIUMCVSS 4.7v30v312019-11-18
CVE-2019-19058 [MEDIUM] CWE-401 CVE-2019-19058: A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the
A memory leak in the alloc_sgtable() function in drivers/net/wireless/intel/iwlwifi/fw/dbg.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering alloc_page() failures, aka CID-b4b814fec1a5.
nvd
CVE-2019-14834P4LOWCVSS 3.7v312020-01-07
CVE-2019-14834 [LOW] CWE-770 CVE-2019-14834: A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attack
A vulnerability was found in dnsmasq before version 2.81, where the memory leak allows remote attackers to cause a denial of service (memory consumption) via vectors involving DHCP response creation.
nvd
CVE-2015-4895P4LOWCVSS 3.5v232015-10-21
CVE-2015-4895 [LOW] CVE-2015-4895: Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated user
Unspecified vulnerability in Oracle MySQL Server 5.6.25 and earlier allows remote authenticated users to affect availability via unknown vectors related to Server : InnoDB.
nvd
CVE-2020-10726P4MEDIUMCVSS 4.4v322020-05-20
CVE-2020-10726 [MEDIUM] CWE-190 CVE-2020-10726: A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct ac
A vulnerability was found in DPDK versions 19.11 and above. A malicious container that has direct access to the vhost-user socket can keep sending VHOST_USER_GET_INFLIGHT_FD messages, causing a resource leak (file descriptors and virtual memory), which may result in a denial of service.
nvd