cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 263 of 264
CVE-2016-4980P4LOWCVSS 2.5v232019-11-27
CVE-2016-4980 [LOW] CWE-330 CVE-2016-4980: A password generation weakness exists in xquest through 2016-06-13. A password generation weakness exists in xquest through 2016-06-13.
nvd
CVE-2012-3354P4MEDIUMCVSS 4.3v16v17+1 more2012-11-20
CVE-2012-3354 [MEDIUM] CWE-200 CVE-2012-3354: doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allow doku.php in DokuWiki, as used in Fedora 16, 17, and 18, when certain PHP error levels are set, allows remote attackers to obtain sensitive information via the prefix parameter, which reveals the installation path in an error message.
nvd
CVE-2013-1888P4LOWCVSS 2.1v17v18+1 more2013-08-17
CVE-2013-1888 [LOW] CWE-59 CVE-2013-1888: pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the pip before 1.3 allows local users to overwrite arbitrary files via a symlink attack on a file in the /tmp/pip-build temporary directory.
nvd
CVE-2014-0019P4LOWCVSS 1.9v19v202014-02-04
CVE-2014-0019 [LOW] CWE-119 CVE-2014-0019: Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows lo Stack-based buffer overflow in socat 1.3.0.0 through 1.7.2.2 and 2.0.0-b1 through 2.0.0-b6 allows local users to cause a denial of service (segmentation fault) via a long server name in the PROXY-CONNECT address in the command line.
nvd
CVE-2020-27818P4LOWCVSS 3.3v31v32+2 more2020-12-08
CVE-2020-27818 [LOW] CWE-120 CVE-2020-27818: A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a ma A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
nvd
CVE-2014-3537P4LOWCVSS 1.2v202014-07-23
CVE-2014-3537 [LOW] CWE-59 CVE-2014-3537: The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files vi The web interface in CUPS before 1.7.4 allows local users in the lp group to read arbitrary files via a symlink attack on a file in /var/cache/cups/rss/.
nvd
CVE-2021-2340P4LOWCVSS 2.7v33v342021-07-21
CVE-2021-2340 [LOW] CVE-2021-2340: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Memcached). Supported versions that are affected are 8.0.25 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to c
nvd
CVE-2021-36087P4LOWCVSS 3.3v352021-07-01
CVE-2021-36087 [LOW] CWE-125 CVE-2021-36087: The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indir The CIL compiler in SELinux 3.2 has a heap-based buffer over-read in ebitmap_match_any (called indirectly from cil_check_neverallow). This occurs because there is sometimes a lack of checks for invalid statements in an optional block.
nvd
CVE-2014-2524P4LOWCVSS 3.3v202014-08-20
CVE-2014-2524 [LOW] CWE-59 CVE-2014-2524: The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or The _rl_tropen function in util.c in GNU readline before 6.3 patch 3 allows local users to create or overwrite arbitrary files via a symlink attack on a /var/tmp/rltrace.[PID] file.
nvd
CVE-2023-2602P4LOWCVSS 3.3v37v382023-06-06
CVE-2023-2602 [LOW] CWE-401 CVE-2023-2602: A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicio A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
nvd
CVE-2023-5551P4LOWCVSS 3.3v382023-11-09
CVE-2023-5551 [LOW] CWE-200 CVE-2023-5551: Separate Groups mode restrictions were not honoured in the forum summary report, which would display Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.
nvd
CVE-2022-21249P4LOWCVSS 2.7v34v352022-01-19
CVE-2022-21249 [LOW] CVE-2022-21249: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versio Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to caus
nvd
CVE-2013-2207P4LOWCVSS 2.6v18v192013-10-09
CVE-2013-2207 [LOW] CWE-264 CVE-2013-2207: pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for t pt_chown in GNU C Library (aka glibc or libc6) before 2.18 does not properly check permissions for tty files, which allows local users to change the permission on the files and obtain access to arbitrary pseudo-terminals by leveraging a FUSE file system.
nvd
CVE-2015-2152P4LOWCVSS 1.9v20v21+1 more2015-03-18
CVE-2015-2152 [LOW] CWE-264 CVE-2015-2152: Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM gu Xen 4.5.x and earlier enables certain default backends when emulating a VGA device for an x86 HVM guest qemu even when the configuration disables them, which allows local guest users to obtain access to the VGA console by (1) setting the DISPLAY environment variable, when compiled with SDL support, or connecting to the VNC server on (2) ::1 or (3) 127.0.
nvd
CVE-2012-1568P4LOWCVSS 1.9v15v162013-03-01
CVE-2012-1568 [LOW] CVE-2012-1568: The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux ( The ExecShield feature in a certain Red Hat patch for the Linux kernel in Red Hat Enterprise Linux (RHEL) 5 and 6 and Fedora 15 and 16 does not properly handle use of many shared libraries by a 32-bit executable file, which makes it easier for context-dependent attackers to bypass the ASLR protection mechanism by leveraging a predictable base address for one of
nvd
CVE-2019-19004P4LOWCVSS 3.3v342021-02-11
CVE-2019-19004 [LOW] CWE-190 CVE-2019-19004: A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide a A biWidth*biBitCnt integer overflow in input-bmp.c in autotrace 0.31.1 allows attackers to provide an unexpected input value to malloc via a malformed bitmap image.
nvd
CVE-2023-5349P4LOWCVSS 3.3v372023-10-30
CVE-2023-5349 [LOW] CWE-401 CVE-2023-5349: A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue c A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
nvd
CVE-2016-9085P4LOWCVSS 3.3v24v252017-02-03
CVE-2016-9085 [LOW] CWE-190 CVE-2016-9085: Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vector Multiple integer overflows in libwebp allows attackers to have unspecified impact via unknown vectors.
nvd
CVE-2023-39978P4LOWCVSS 3.3v372023-08-08
CVE-2023-39978 [LOW] CWE-401 CVE-2023-39978: ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in M ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
nvd
CVE-2023-22038P4LOWCVSS 2.7v37v38+1 more2023-07-18
CVE-2023-22038 [LOW] CVE-2023-22038: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorize
nvd
Fedoraproject Fedora vulnerabilities | cvebase