Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 262 of 264
CVE-2021-29473P4LOWCVSS 2.5v33v342021-04-26
CVE-2021-29473 [LOW] CWE-125 CVE-2021-29473: Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP
Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. The out-of-bounds read is triggered w
nvd
CVE-2023-25815P4LOWCVSS 2.2v37v382023-04-25
CVE-2023-25815 [LOW] CWE-22 CVE-2023-25815: In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. A
In Git for Windows, the Windows port of Git, no localized messages are shipped with the installer. As a consequence, Git is expected not to localize messages at all, and skips the gettext initialization. However, due to a change in MINGW-packages, the `gettext()` function's implicit initialization no longer uses the runtime prefix but uses the hard-code
nvd
CVE-2020-27769P4LOWCVSS 3.3v332021-05-14
CVE-2020-27769 [LOW] CWE-190 CVE-2020-27769: In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
nvd
CVE-2020-18442P4LOWCVSS 3.3v34v352021-06-18
CVE-2020-18442 [LOW] CWE-835 CVE-2020-18442: Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the retur
Infinite Loop in zziplib v0.13.69 allows remote attackers to cause a denial of service via the return value "zzip_file_read" in the function "unzzip_cat_file".
nvd
CVE-2019-2911P4LOWCVSS 2.7v29v30+1 more2019-10-16
CVE-2019-2911 [LOW] CVE-2019-2911: Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported
Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerabilit
nvd
CVE-2021-37964P4LOWCVSS 3.3v33v352021-10-08
CVE-2021-37964 [LOW] CVE-2021-37964: Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.
Inappropriate implementation in ChromeOS Networking in Google Chrome on ChromeOS prior to 94.0.4606.54 allowed an attacker with a rogue wireless access point to to potentially carryout a wifi impersonation attack via a crafted ONC file.
nvd
CVE-2023-22048P4LOWCVSS 3.1v37v38+1 more2023-07-18
CVE-2023-22048 [LOW] CVE-2023-22048: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supp
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read
nvd
CVE-2019-11884P4LOWCVSS 3.3v28v29+1 more2019-05-10
CVE-2019-11884 [LOW] CVE-2019-11884: The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allow
The do_hidp_sock_ioctl function in net/bluetooth/hidp/sock.c in the Linux kernel before 5.0.15 allows a local user to obtain potentially sensitive information from kernel stack memory via a HIDPCONNADD command, because a name field may not end with a '\0' character.
nvd
CVE-2021-36084P4LOWCVSS 3.3v352021-07-01
CVE-2021-36084 [LOW] CWE-416 CVE-2021-36084: The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_v
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __cil_verify_classpermission and __cil_pre_verify_helper).
nvd
CVE-2021-36085P4LOWCVSS 3.3v352021-07-01
CVE-2021-36085 [LOW] CWE-416 CVE-2021-36085: The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verif
The CIL compiler in SELinux 3.2 has a use-after-free in __cil_verify_classperms (called from __verify_map_perm_classperms and hashtab_map).
nvd
CVE-2021-3574P4LOWCVSS 3.3v35v36+1 more2022-08-26
CVE-2021-3574 [LOW] CWE-401 CVE-2021-3574: A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert c
A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.
nvd
CVE-2020-29623P4LOWCVSS 3.3v32v332021-04-02
CVE-2020-29623 [LOW] CVE-2020-29623: "Clear History and Website Data" did not clear the history. The issue was addressed with improved da
"Clear History and Website Data" did not clear the history. The issue was addressed with improved data deletion. This issue is fixed in macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, tvOS 14.3. A user may be unable to fully delete browsing history.
nvd
CVE-2021-20203P4LOWCVSS 3.2v332021-02-25
CVE-2021-20203 [LOW] CWE-190 CVE-2021-20203: An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.
An integer overflow issue was found in the vmxnet3 NIC emulator of the QEMU for versions up to v5.2.0. It may occur if a guest was to supply invalid values for rx/tx queue size or other NIC parameters. A privileged guest user may use this flaw to crash the QEMU process on the host resulting in DoS scenario.
nvd
CVE-2023-5543P4LOWCVSS 3.3v382023-11-09
CVE-2023-5543 [LOW] CWE-284 CVE-2023-5543: When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of us
When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.
nvd
CVE-2022-4123P4LOWCVSS 3.3v35v36+1 more2022-12-08
CVE-2022-4123 [LOW] CWE-23 CVE-2022-4123: A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to inco
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.
nvd
CVE-2023-1513P4LOWCVSS 3.3v372023-03-23
CVE-2023-1513 [LOW] CWE-665 CVE-2023-1513: A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be
A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak.
nvd
CVE-2021-3392P4LOWCVSS 3.2v332021-03-23
CVE-2021-3392 [LOW] CWE-416 CVE-2021-3392: A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing
A use-after-free flaw was found in the MegaRAID emulator of QEMU. This issue occurs while processing SCSI I/O requests in the case of an error mptsas_free_request() that does not dequeue the request object 'req' from a pending requests queue. This flaw allows a privileged guest user to crash the QEMU process on the host, resulting in a denial of service.
nvd
CVE-2019-13762P4LOWCVSS 3.3v30v312019-12-10
CVE-2019-13762 [LOW] CWE-667 CVE-2019-13762: Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allow
Insufficient policy enforcement in downloads in Google Chrome on Windows prior to 79.0.3945.79 allowed a local attacker to spoof downloaded files via local code.
nvd
CVE-2020-14394P4LOWCVSS 3.2v33v372022-08-17
CVE-2020-14394 [LOW] CWE-835 CVE-2020-14394: An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the len
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
nvd
CVE-2021-2019P4LOWCVSS 2.7v32v332021-01-20
CVE-2021-2019 [LOW] CVE-2021-2019: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges).
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized
nvd