Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 260 of 264
CVE-2019-17052P4LOWCVSS 3.3v292019-10-01
CVE-2019-17052 [LOW] CWE-276 CVE-2019-17052: ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3
ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module in the Linux kernel 3.16 through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-0614e2b73768.
nvd
CVE-2018-1002102P4LOWCVSS 2.6v312019-12-05
CVE-2018-1002102 [LOW] CWE-601 CVE-2018-1002102: Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 all
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redirect as a GET request with client-certificate credentials for authenticating to the Kubelet.
nvd
CVE-2019-18809P4MEDIUMCVSS 4.6v30v312019-11-07
CVE-2019-18809 [MEDIUM] CWE-401 CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the L
A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption), aka CID-2289adbfa559.
nvd
CVE-2019-19068P4MEDIUMCVSS 4.6v30v312019-11-18
CVE-2019-19068 [MEDIUM] CWE-401 CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl
A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
nvd
CVE-2019-19072P4MEDIUMCVSS 4.4v30v312019-11-18
CVE-2019-19072 [MEDIUM] CWE-401 CVE-2019-19072: A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux k
A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.
nvd
CVE-2021-0004P4MEDIUMCVSS 4.4v342021-08-11
CVE-2021-0004 [MEDIUM] CWE-119 CVE-2021-0004: Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers an
Improper buffer restrictions in the firmware of Intel(R) Ethernet Adapters 800 Series Controllers and associated adapters before version 1.5.3.0 may allow a privileged user to potentially enable denial of service via local access.
nvd
CVE-2022-21265P4LOWCVSS 3.8v34v352022-01-19
CVE-2022-21265 [LOW] CVE-2022-21265: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, in
nvd
CVE-2019-16232P4MEDIUMCVSS 4.1v30v312019-09-11
CVE-2019-16232 [MEDIUM] CWE-476 CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_
drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel 5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
nvd
CVE-2016-3158P4LOWCVSS 3.8v22v232016-04-13
CVE-2016-3158 [LOW] CVE-2016-3158: The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware
The xrstor function in arch/x86/xstate.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE-201
nvd
CVE-2016-3159P4LOWCVSS 3.8v22v232016-04-13
CVE-2016-3159 [LOW] CVE-2016-3159: The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardwa
The fpu_fxrstor function in arch/x86/i387.c in Xen 4.x does not properly handle writes to the hardware FSW.ES bit when running on AMD64 processors, which allows local guest OS users to obtain sensitive register content information from another guest by leveraging pending exception and mask bits. NOTE: this vulnerability exists because of an incorrect fix for CVE
nvd
CVE-2021-29623P4LOWCVSS 3.3v33v342021-05-13
CVE-2021-29623 [LOW] CWE-908 CVE-2021-29623: Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. A read of uninitialized memory was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The read of uninitialized me
nvd
CVE-2016-1544P4LOWCVSS 3.3v22v232020-02-06
CVE-2016-1544 [LOW] CWE-400 CVE-2016-1544: nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).
nvd
CVE-2015-5070P4LOWCVSS 3.1v21v222017-09-26
CVE-2015-5070 [LOW] CVE-2015-5070: The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in fi
The (1) filesystem::get_wml_location function in filesystem.cpp and (2) is_legal_file function in filesystem_boost.cpp in Battle for Wesnoth before 1.12.4 and 1.13.x before 1.13.1, when a case-insensitive filesystem is used, allow remote attackers to obtain sensitive information via vectors related to inclusion of .pbl files from WML. NOTE: this vulnerability ex
nvd
CVE-2020-15005P4LOWCVSS 3.1v322020-06-24
CVE-2020-15005 [LOW] CVE-2020-15005: In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis
In MediaWiki before 1.31.8, 1.32.x and 1.33.x before 1.33.4, and 1.34.x before 1.34.2, private wikis behind a caching server using the img_auth.php image authorization security feature may have had their files cached publicly, so any unauthorized user could view them. This occurs because Cache-Control and Vary headers were mishandled.
nvd
CVE-2019-19057P4LOWCVSS 3.3v30v312019-11-18
CVE-2019-19057 [LOW] CWE-401 CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifie
Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
nvd
CVE-2024-1454P4LOWCVSS 3.4v38v39+1 more2024-02-12
CVE-2024-1454 [LOW] CWE-416 CVE-2024-1454: The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in t
The use-after-free vulnerability was found in the AuthentIC driver in OpenSC packages, occuring in the card enrolment process using pkcs15-init when a user or administrator enrols or modifies cards. An attacker must have physical access to the computer system and requires a crafted USB device or smart card to present the system with specially crafted res
nvd
CVE-2019-17055P4LOWCVSS 3.3v292019-10-01
CVE-2019-17055 [LOW] CWE-862 CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel th
base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
nvd
CVE-2024-32020P4LOWCVSS 3.3v402024-05-14
CVE-2024-32020 [LOW] CWE-281 CVE-2024-32020: Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2,
Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, local clones may end up hardlinking files into the target repository's object database when source and target repository reside on the same disk. If the source repository is owned by a different user, then those hardlinked files may be rewritt
nvd
CVE-2021-32680P4LOWCVSS 3.3v33v342021-07-12
CVE-2021-32680 [LOW] CWE-778 CVE-2021-32680: Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.
Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13, 20.0.11, and 21.0.3.
nvd
CVE-2021-25317P4LOWCVSS 3.3v32v33+1 more2021-05-05
CVE-2021-25317 [LOW] CWE-276 CVE-2021-25317: A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Serv
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affe
nvd