Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 30 of 264
CVE-2020-10109P3CRITICALCVSS 9.8v31v322020-03-12
CVE-2020-10109 [CRITICAL] CWE-444 CVE-2020-10109: In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented wi
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with a content-length and a chunked encoding header, the content-length took precedence and the remainder of the request body was interpreted as a pipelined request.
nvd
CVE-2020-15049P3HIGHCVSS 8.8v312020-06-30
CVE-2020-15049 [HIGH] CWE-444 CVE-2020-15049: An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.
An issue was discovered in http/ContentLengthInterpreter.cc in Squid before 4.12 and 5.x before 5.0.3. A Request Smuggling and Poisoning attack can succeed against the HTTP cache. The client sends an HTTP request with a Content-Length header containing "+\ "-" or an uncommon shell whitespace character prefix to the length field-value.
nvd
CVE-2021-34552P3CRITICALCVSS 9.8v33v342021-07-13
CVE-2021-34552 [CRITICAL] CWE-120 CVE-2021-34552: Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass co
Pillow through 8.2.0 and PIL (aka Python Imaging Library) through 1.1.7 allow an attacker to pass controlled parameters directly into a convert function to trigger a buffer overflow in Convert.c.
nvd
CVE-2019-2126P3HIGHCVSS 8.8v30v312019-08-20
CVE-2019-2126 [HIGH] CWE-415 CVE-2019-2126: In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset
In ParseContentEncodingEntry of mkvparser.cc, there is a possible double free due to a missing reset of a freed pointer. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-
nvd
CVE-2017-18640P3HIGHCVSS 7.5v31v322019-12-12
CVE-2017-18640 [HIGH] CVE-2017-18640: The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a relate
The Alias feature in SnakeYAML before 1.26 allows entity expansion during a load operation, a related issue to CVE-2003-1564.
nvd
CVE-2019-20790P3CRITICALCVSS 9.8v33v342020-04-27
CVE-2019-20790 [CRITICAL] CWE-290 CVE-2019-20790: OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SP
OpenDMARC through 1.3.2 and 1.4.x, when used with pypolicyd-spf 2.0.2, allows attacks that bypass SPF and DMARC authentication in situations where the HELO field is inconsistent with the MAIL FROM field.
nvd
CVE-2021-21110P3CRITICALCVSS 9.6v32v332021-01-08
CVE-2021-21110 [CRITICAL] CWE-416 CVE-2021-21110: Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to
Use after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2019-18425P3CRITICALCVSS 9.8v29v30+1 more2019-10-31
CVE-2019-18425 [CRITICAL] CWE-269 CVE-2019-18425: An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS pri
An issue was discovered in Xen through 4.12.x allowing 32-bit PV guest OS users to gain guest OS privileges by installing and using descriptors. There is missing descriptor table limit checking in x86 PV emulation. When emulating certain PV guest operations, descriptor table accesses are performed by the emulating code. Such accesses should respec
nvd
CVE-2021-22879P3HIGHCVSS 8.8v332021-04-14
CVE-2021-22879 [HIGH] CWE-99 CVE-2021-22879: Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing valida
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
nvd
CVE-2023-6816P3CRITICALCVSS 9.8v392024-01-18
CVE-2023-6816 [CRITICAL] CWE-787 CVE-2023-6816: A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit f
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.
nvd
CVE-2015-3145P3HIGHCVSS 7.5v21v222015-04-24
CVE-2015-3145 [HIGH] CWE-119 CVE-2015-3145: The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calcul
The sanitize_cookie_path function in cURL and libcurl 7.31.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds write and crash) or possibly have other unspecified impact via a cookie path containing only a double-quote character.
nvd
CVE-2024-23313P3CRITICALCVSS 9.8v402024-02-20
CVE-2024-23313 [CRITICAL] CWE-191 CVE-2024-23313: An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Projec
An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2010-3438P3CRITICALCVSS 9.8v12v132019-11-12
CVE-2010-3438 [CRITICAL] CWE-134 CVE-2010-3438: libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be
libpoe-component-irc-perl before v6.32 does not remove carriage returns and line feeds. This can be used to execute arbitrary IRC commands by passing an argument such as "some text\rQUIT" to the 'privmsg' handler, which would cause the client to disconnect from the server.
nvd
CVE-2022-30599P3CRITICALCVSS 9.8v34v35+1 more2022-05-18
CVE-2022-30599 [CRITICAL] CWE-89 CVE-2022-30599: A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to con
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
nvd
CVE-2023-39352P3CRITICALCVSS 9.8v37v38+1 more2023-08-31
CVE-2023-39352 [CRITICAL] CWE-787 CVE-2023-39352: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an invalid offset validation leading to Out Of Bound Write. This can be triggered when the values `rect->left` and `rect->top` are exactly equal to `surface->width` and `surface->height`. eg. `rect->left` == `s
nvd
CVE-2023-40567P3CRITICALCVSS 9.8v37v38+1 more2023-08-31
CVE-2023-40567 [CRITICAL] CWE-787 CVE-2023-40567: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `clear_decompress_bands_data` function in which there is no offset validation. Abuse of this vulnerability may lead to an out of bounds write. This issue has been addressed in vers
nvd
CVE-2024-1284P3CRITICALCVSS 9.8v38v392024-02-07
CVE-2024-1284 [CRITICAL] CWE-416 CVE-2024-1284: Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potenti
Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5528P3HIGHCVSS 8.8v37v38+1 more2023-11-14
CVE-2023-5528 [HIGH] CWE-20 CVE-2023-5528: A security issue was discovered in Kubernetes where a user that can create pods and persistent volum
A security issue was discovered in Kubernetes where a user that can create pods and persistent volumes on Windows nodes may be able to escalate to admin privileges on those nodes. Kubernetes clusters are only affected if they are using an in-tree storage plugin for Windows nodes.
nvd
CVE-2021-21157P3HIGHCVSS 8.8v32v332021-02-22
CVE-2021-21157 [HIGH] CWE-416 CVE-2021-21157: Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote atta
Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-14869P3HIGHCVSS 8.8v29v30+1 more2019-11-15
CVE-2019-14869 [HIGH] CWE-648 CVE-2019-14869: A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, wh
A flaw was found in all versions of ghostscript 9.x before 9.50, where the `.charkeys` procedure, where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. An attacker could abuse this flaw by creating a specially crafted PostScript file that could escalate privileges within the Ghostscript and access fi
nvd