Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 31 of 264
CVE-2019-3855P3HIGHCVSS 8.8v28v29+1 more2019-03-21
CVE-2019-3855 [HIGH] CWE-190 CVE-2019-3855: An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before
An integer overflow flaw which could lead to an out of bounds write was discovered in libssh2 before 1.8.1 in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to execute code on the client system when a user connects to the server.
nvd
CVE-2019-14889P3HIGHCVSS 8.8v30v312019-12-10
CVE-2019-14889 [HIGH] CWE-78 CVE-2019-14889: A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.
A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way where users can influence the third parameter of the function, it would become
nvd
CVE-2021-32762P3HIGHCVSS 8.8v33v34+1 more2021-10-04
CVE-2021-32762 [HIGH] CWE-190 CVE-2021-32762: Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool a
Redis is an open source, in-memory database that persists on disk. The redis-cli command line tool and redis-sentinel service may be vulnerable to integer overflow when parsing specially crafted large multi-bulk network replies. This is a result of a vulnerability in the underlying hiredis library which does not perform an overflow check before callin
nvd
CVE-2009-3231P3MEDIUMCVSS 6.8v10v112009-09-17
CVE-2009-3231 [MEDIUM] CWE-287 CVE-2009-3231: The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP auth
The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password.
nvd
CVE-2023-1183P3MEDIUMCVSS 5.5v382023-07-10
CVE-2023-1183 [MEDIUM] CWE-20 CVE-2023-1183: A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/scr
A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.
nvd
CVE-2022-1379P3CRITICALCVSS 9.1v35v362022-05-14
CVE-2022-1379 [CRITICAL] CWE-918 CVE-2022-1379: URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can ab
URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal resources/servers or sending requests to third party servers.
nvd
CVE-2023-39356P3CRITICALCVSS 9.1v37v38+1 more2023-08-31
CVE-2023-39356 [CRITICAL] CWE-125 CVE-2023-39356: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. In affected versions a missing offset validation may lead to an Out Of Bound Read in the function `gdi_multi_opaque_rect`. In particular there is no code to validate if the value `multi_opaque_rect->numRectangles` is less than 45. Looping thro
nvd
CVE-2023-27533P3HIGHCVSS 8.8v362023-03-30
CVE-2023-27533 [HIGH] CWE-75 CVE-2023-27533: A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protoc
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This v
nvd
CVE-2021-30953P3HIGHCVSS 8.8v34v352021-08-24
CVE-2021-30953 [HIGH] CWE-125 CVE-2021-30953: An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 15.2,
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30951P3HIGHCVSS 8.8v34v352021-08-24
CVE-2021-30951 [HIGH] CWE-416 CVE-2021-30951: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-30936P3HIGHCVSS 8.8v342021-08-24
CVE-2021-30936 [HIGH] CWE-416 CVE-2021-30936: A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2024-34340P3CRITICALCVSS 9.1v392024-05-14
CVE-2024-34340 [CRITICAL] CWE-287 CVE-2024-34340: Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Ca
Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, Cacti calls `compat_password_hash` when users set their password. `compat_password_hash` use `password_hash` if there is it, else use `md5`. When verifying password, it calls `compat_password_verify`. In `compat_password_verify`, `password_verify` is
nvd
CVE-2020-15078P3HIGHCVSS 7.5v32v33+1 more2021-04-26
CVE-2020-15078 [HIGH] CWE-305 CVE-2020-15078: OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access con
OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.
nvd
CVE-2022-30600P3CRITICALCVSS 9.8v34v35+1 more2022-05-18
CVE-2022-30600 [CRITICAL] CWE-682 CVE-2022-30600: A flaw was found in moodle where logic used to count failed login attempts could result in the accou
A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.
nvd
CVE-2020-36242P3CRITICALCVSS 9.1v332021-02-07
CVE-2020-36242 [CRITICAL] CWE-190 CVE-2020-36242: In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrica
In the cryptography package before 3.3.2 for Python, certain sequences of update calls to symmetrically encrypt multi-GB values could result in an integer overflow and buffer overflow, as demonstrated by the Fernet class.
nvd
CVE-2022-25235P3CRITICALCVSS 9.8v34v352022-02-16
CVE-2022-25235 [CRITICAL] CWE-116 CVE-2022-25235: xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as che
xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.
nvd
CVE-2022-42823P3HIGHCVSS 8.8v35v36+1 more2022-11-01
CVE-2022-42823 [HIGH] CWE-843 CVE-2022-42823: A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2010-4258P3MEDIUMCVSS 6.2PoCv132010-12-30
CVE-2010-4258 [MEDIUM] CWE-269 CVE-2010-4258: The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by ve
nvd
CVE-2022-24810P3HIGHCVSS 8.8v362024-04-16
CVE-2022-24810 [HIGH] CWE-476 CVE-2022-24810: net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version
net-snmp provides various tools relating to the Simple Network Management Protocol. Prior to version 5.9.2, a user with read-write credentials can use a malformed OID in a SET to the nsVacmAccessTable to cause a NULL pointer dereference. Version 5.9.2 contains a patch. Users should use strong SNMPv3 credentials and avoid sharing the credentials. Those
nvd
CVE-2022-39286P3HIGHCVSS 8.8v36v372022-10-26
CVE-2022-39286 [HIGH] CWE-250 CVE-2022-39286: Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior
Jupyter Core is a package for the core common functionality of Jupyter projects. Jupyter Core prior to version 4.11.2 contains an arbitrary code execution vulnerability in `jupyter_core` that stems from `jupyter_core` executing untrusted files in CWD. This vulnerability allows one user to run code as another. Version 4.11.2 contains a patch for this is
nvd