Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 32 of 264
CVE-2021-32687P3HIGHCVSS 7.5v33v34+1 more2021-10-04
CVE-2021-32687 [HIGH] CWE-190 CVE-2021-32687: Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting
Redis is an open source, in-memory database that persists on disk. An integer overflow bug affecting all versions of Redis can be exploited to corrupt the heap and potentially be used to leak arbitrary contents of the heap or trigger remote code execution. The vulnerability involves changing the default set-max-intset-entries configuration parameter t
nvd
CVE-2016-7943P3CRITICALCVSS 9.8v252016-12-13
CVE-2016-7943 [CRITICAL] CWE-787 CVE-2016-7943: The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges
The XListFonts function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving length fields, which trigger out-of-bounds write operations.
nvd
CVE-2023-6186P3HIGHCVSS 8.8v382023-12-11
CVE-2023-6186 [HIGH] CWE-281 CVE-2023-6186: Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker t
Insufficient macro permission validation of The Document Foundation LibreOffice allows an attacker to execute built-in macros without warning.
In affected versions LibreOffice supports hyperlinks with macro or similar built-in command targets that can be executed when activated without warning the user.
nvd
CVE-2021-32627P3HIGHCVSS 7.5v33v34+1 more2021-10-04
CVE-2021-32627 [HIGH] CWE-190 CVE-2021-32627: Redis is an open source, in-memory database that persists on disk. In affected versions an integer o
Redis is an open source, in-memory database that persists on disk. In affected versions an integer overflow bug in Redis can be exploited to corrupt the heap and potentially result with remote code execution. The vulnerability involves changing the default proto-max-bulk-len and client-query-buffer-limit configuration parameters to very large values a
nvd
CVE-2024-4215P3HIGHCVSS 8.8v402024-05-02
CVE-2024-4215 [HIGH] CWE-89 CVE-2024-4215: pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability
pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions within the application, such as managing files and executing SQL queries, regardless of the account’s MFA e
nvd
CVE-2021-21225P3HIGHCVSS 8.8v32v33+1 more2021-04-26
CVE-2021-21225 [HIGH] CWE-787 CVE-2021-21225: Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker t
Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-17368P3CRITICALCVSS 9.8v31v322020-08-11
CVE-2020-17368 [CRITICAL] CWE-78 CVE-2020-17368: Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stder
Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.
nvd
CVE-2022-30292P3CRITICALCVSS 10.0v35v362022-05-04
CVE-2022-30292 [CRITICAL] CWE-787 CVE-2022-30292: Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack
Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.
nvd
CVE-2022-28615P3CRITICALCVSS 9.1v35v362022-06-09
CVE-2022-28615 [CRITICAL] CWE-190 CVE-2022-28615: Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds
Apache HTTP Server 2.4.53 and earlier may crash or disclose information due to a read beyond bounds in ap_strcmp_match() when provided with an extremely large input buffer. While no code distributed with the server can be coerced into such a call, third-party modules or lua scripts that use ap_strcmp_match() may hypothetically be affected.
nvd
CVE-2020-10108P3CRITICALCVSS 9.8v31v322020-03-12
CVE-2020-10108 [CRITICAL] CWE-444 CVE-2020-10108: In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented wi
In Twisted Web through 19.10.0, there was an HTTP request splitting vulnerability. When presented with two content-length headers, it ignored the first header. When the second content-length value was set to zero, the request body was interpreted as a pipelined request.
nvd
CVE-2016-6254P3CRITICALCVSS 9.1v23v242016-08-19
CVE-2016-6254 [CRITICAL] CWE-119 CVE-2016-6254: Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.
Heap-based buffer overflow in the parse_packet function in network.c in collectd before 5.4.3 and 5.x before 5.5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted network packet.
nvd
CVE-2020-12460P3CRITICALCVSS 9.8v33v342020-07-27
CVE-2020-12460 [CRITICAL] CWE-787 CVE-2020-12460: OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function
OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption when a '\0' byte overwrites the heap metadata of the next chunk and its
nvd
CVE-2016-9400P3CRITICALCVSS 9.8v232017-02-22
CVE-2016-9400 [CRITICAL] CWE-119 CVE-2016-9400: The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows
The CClient::ProcessServerPacket method in engine/client/client.cpp in Teeworlds before 0.6.4 allows remote servers to write to arbitrary physical memory locations and possibly execute arbitrary code via vectors involving snap handling.
nvd
CVE-2015-5739P3CRITICALCVSS 9.8v21v222017-10-18
CVE-2015-5739 [CRITICAL] CWE-444 CVE-2015-5739: The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP head
The net/http library in net/textproto/reader.go in Go before 1.4.3 does not properly parse HTTP header keys, which allows remote attackers to conduct HTTP request smuggling attacks via a space instead of a hyphen, as demonstrated by "Content Length" instead of "Content-Length."
nvd
CVE-2023-39323P3HIGHCVSS 8.1v37v38+1 more2023-10-05
CVE-2023-39323 [HIGH] CVE-2023-39323: Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowin
Line directives ("//line") can be used to bypass the restrictions on "//go:cgo_" directives, allowing blocked linker and compiler flags to be passed during compilation. This can result in unexpected execution of arbitrary code when running "go build". The line directive requires the absolute path of the file in which the directive lives, which makes exploitin
nvd
CVE-2016-0729P3CRITICALCVSS 9.8v22v23+1 more2016-04-07
CVE-2016-0729 [CRITICAL] CWE-119 CVE-2016-0729: Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cp
Multiple buffer overflows in (1) internal/XMLReader.cpp, (2) util/XMLURL.cpp, and (3) util/XMLUri.cpp in the XML Parser library in Apache Xerces-C before 3.1.3 allow remote attackers to cause a denial of service (segmentation fault or memory corruption) or possibly execute arbitrary code via a crafted document.
nvd
CVE-2021-30599P3HIGHCVSS 8.8v33v34+1 more2021-08-26
CVE-2021-30599 [HIGH] CWE-843 CVE-2021-30599: Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute ar
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2021-40391P3CRITICALCVSS 9.8v362021-11-19
CVE-2021-40391 [CRITICAL] CWE-390 CVE-2021-40391: An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of
An out-of-bounds write vulnerability exists in the drill format T-code tool number functionality of Gerbv 2.7.0, dev (commit b5f1eacd), and the forked version of Gerbv (commit 71493260). A specially-crafted drill file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2020-35628P3CRITICALCVSS 9.8v33v342021-03-04
CVE-2020-35628 [CRITICAL] CWE-129 CVE-2020-35628: A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->incident_sface. An attacker can provide malicious input to trigger this vulnerability.
nvd
CVE-2020-28601P3CRITICALCVSS 9.8v33v342021-03-04
CVE-2020-28601 [CRITICAL] CWE-129 CVE-2020-28601: A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability.
nvd