Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 264 of 264
CVE-2023-3674P4LOWCVSS 2.8v382023-07-19
CVE-2023-3674 [LOW] CWE-1283 CVE-2023-3674: A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM q
A flaw was found in the keylime attestation verifier, which fails to flag a device's submitted TPM quote as faulty when the quote's signature does not validate for some reason. Instead, it will only emit an error in the log without flagging the device as untrusted.
nvd
CVE-2020-14791P4LOWCVSS 2.2v31v32+1 more2020-10-21
CVE-2020-14791 [LOW] CVE-2020-14791: Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions th
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.21 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a
nvd
CVE-2020-29480P4LOWCVSS 2.3v32v332020-12-15
CVE-2020-29480 [LOW] CWE-862 CVE-2020-29480: An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission c
An issue was discovered in Xen through 4.14.x. Neither xenstore implementation does any permission checks when reporting a xenstore watch event. A guest administrator can watch the root xenstored node, which will cause notifications for every created, modified, and deleted key. A guest administrator can also use the special watches, which will cause a
nvd
CVE-2021-3923P4LOWCVSS 2.3v372023-03-27
CVE-2021-3923 [LOW] CWE-200 CVE-2021-3923: A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a pr
A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel stack information when issuing commands to the /dev/infiniband/rdma_cm device node. While this access is unlikely to leak sensitive user information, it can be further used to defeat existing kernel protection mechani
nvd
CVE-2014-9585P4LOWCVSS 2.1v212015-01-09
CVE-2014-9585 [LOW] CVE-2014-9585: The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly c
The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
nvd
CVE-2009-1186P4LOWCVSS 2.1v9v102009-04-17
CVE-2009-1186 [LOW] CWE-120 CVE-2009-1186: Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 all
Buffer overflow in the util_path_encode function in udev/lib/libudev-util.c in udev before 1.4.1 allows local users to cause a denial of service (service outage) via vectors that trigger a call with crafted arguments.
nvd
CVE-2020-2933P4LOWCVSS 2.2v32v332020-04-15
CVE-2020-2933 [LOW] CVE-2020-2933: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported ve
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 5.1.48 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability
nvd
CVE-2009-2910P4LOWCVSS 2.1v102009-10-20
CVE-2009-2910 [LOW] CWE-200 CVE-2009-2910: arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear
arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.31.4 on the x86_64 platform does not clear certain kernel registers before a return to user mode, which allows local users to read register values from an earlier process by switching an ia32 process to 64-bit mode.
nvd
CVE-2014-3956P4LOWCVSS 1.9v202014-06-04
CVE-2014-3956 [LOW] CWE-200 CVE-2014-3956: The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order,
The sm_close_on_exec function in conf.c in sendmail before 8.14.9 has arguments in the wrong order, and consequently skips setting expected FD_CLOEXEC flags, which allows local users to access unintended high-numbered file descriptors via a custom mail-delivery program.
nvd
CVE-2021-27645P4LOWCVSS 2.5v33v342021-02-24
CVE-2021-27645 [LOW] CWE-415 CVE-2021-27645: The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, wh
The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to netgroupcache.c.
nvd
CVE-2015-1563P4LOWCVSS 2.1v212015-02-09
CVE-2015-1563 [LOW] CWE-399 CVE-2015-1563: The ARM GIC distributor virtualization in Xen 4.4.x and 4.5.x allows local guests to cause a denial
The ARM GIC distributor virtualization in Xen 4.4.x and 4.5.x allows local guests to cause a denial of service by causing a large number messages to be logged.
nvd
CVE-2009-3612P4LOWCVSS 2.1v102009-10-19
CVE-2009-3612 [LOW] CVE-2009-3612: The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x
The tcf_fill_node function in net/sched/cls_api.c in the netlink subsystem in the Linux kernel 2.6.x before 2.6.32-rc5, and 2.4.37.6 and earlier, does not initialize a certain tcm__pad2 structure member, which might allow local users to obtain sensitive information from kernel memory via unspecified vectors. NOTE: this issue exists because of an incomplete fix f
nvd
CVE-2015-2157P4LOWCVSS 2.1v20v222015-03-27
CVE-2015-2157 [LOW] CWE-200 CVE-2015-2157: The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not prop
The (1) ssh2_load_userkey and (2) ssh2_save_userkey functions in PuTTY 0.51 through 0.63 do not properly wipe SSH-2 private keys from memory, which allows local users to obtain sensitive information by reading the memory.
nvd
CVE-2015-2045P4LOWCVSS 2.1v20v21+1 more2015-03-12
CVE-2015-2045 [LOW] CWE-200 CVE-2015-2045: The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data st
The HYPERVISOR_xen_version hypercall in Xen 3.2.x through 4.5.x does not properly initialize data structures, which allows local guest users to obtain sensitive information via unspecified vectors.
nvd
CVE-2014-0103P4LOWCVSS 2.1v19v202014-07-29
CVE-2014-0103 [LOW] CWE-310 CVE-2014-0103: WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allow
WebAccess in Zarafa before 7.1.10 and WebApp before 1.6 stores credentials in cleartext, which allows local Apache users to obtain sensitive information by reading the PHP session files.
nvd
CVE-2019-20386P4LOWCVSS 2.4v302020-01-21
CVE-2019-20386 [LOW] CWE-401 CVE-2019-20386: An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executin
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
nvd
CVE-2013-0348P4LOWCVSS 2.1v17v182013-12-13
CVE-2013-0348 [LOW] CWE-264 CVE-2013-0348: thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/th
thttpd.c in sthttpd before 2.26.4-r2 and thttpd 2.25b use world-readable permissions for /var/log/thttpd.log, which allows local users to obtain sensitive information by reading the file.
nvd
CVE-2012-4453P4LOWCVSS 2.1v16v172012-10-09
CVE-2012-4453 [LOW] CWE-276 CVE-2012-4453: dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other pro
dracut.sh in dracut, as used in Red Hat Enterprise Linux 6, Fedora 16 and 17, and possibly other products, creates initramfs images with world-readable permissions, which might allow local users to obtain sensitive information.
nvd
CVE-2011-1943P4LOWCVSS 2.1v152011-06-14
CVE-2011-1943 [LOW] CWE-532 CVE-2011-1943: The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.
The destroy_one_secret function in nm-setting-vpn.c in libnm-util in the NetworkManager package 0.8.999-3.git20110526 in Fedora 15 creates a log entry containing a certificate password, which allows local users to obtain sensitive information by reading a log file.
nvd
← Previous264 / 264