cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 36 of 264
CVE-2020-27619P3CRITICALCVSS 9.8v33v342020-10-22
CVE-2020-27619 [CRITICAL] CVE-2020-27619: In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on con In Python 3 through 3.9.0, the Lib/test/multibytecodec_support.py CJK codec tests call eval() on content retrieved via HTTP.
nvd
CVE-2021-3420P3CRITICALCVSS 9.8v32v33+1 more2021-03-05
CVE-2021-3420 [CRITICAL] CWE-190 CVE-2021-3420: A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory al A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buffer and then to a heap-based buffer overflow.
nvd
CVE-2022-31799P3CRITICALCVSS 9.8v35v362022-06-02
CVE-2022-31799 [CRITICAL] CWE-755 CVE-2022-31799: Bottle before 0.12.20 mishandles errors during early request binding. Bottle before 0.12.20 mishandles errors during early request binding.
nvd
CVE-2023-39332P3CRITICALCVSS 9.8v392023-10-18
CVE-2023-39332 [CRITICAL] CVE-2023-39332: Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Nod Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class extends the `Uint8Array` class. Node.js prevents path traversal through strings (see CVE-2023-30584) and `Buffer` objects (see CVE-2023-32004), but not through non-`Buffer` `Uint8Array` objects. This is distinct from C
nvd
CVE-2021-21106P3CRITICALCVSS 9.6v32v332021-01-08
CVE-2021-21106 [CRITICAL] CWE-416 CVE-2021-21106: Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had Use after free in autofill in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2024-23305P3CRITICALCVSS 9.8v402024-02-20
CVE-2024-23305 [CRITICAL] CWE-787 CVE-2024-23305: An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Bi An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vmrk file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2024-23606P3CRITICALCVSS 9.8v402024-02-20
CVE-2024-23606 [CRITICAL] CWE-131 CVE-2024-23606: An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Proj An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2024-23809P3CRITICALCVSS 9.8v402024-02-20
CVE-2024-23809 [CRITICAL] CWE-415 CVE-2024-23809: A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Bios A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2019-9278P3HIGHCVSS 8.8v31v322019-09-27
CVE-2019-9278 [HIGH] CWE-190 CVE-2019-9278: In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to r In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
nvd
CVE-2024-32658P3CRITICALCVSS 9.8v38v39+1 more2024-04-23
CVE-2024-32658 [CRITICAL] CWE-125 CVE-2024-32658: FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to vers FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
nvd
CVE-2023-3432P3CRITICALCVSS 10.0v392023-06-27
CVE-2023-3432 [CRITICAL] CWE-918 CVE-2023-3432: Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9. Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.
nvd
CVE-2019-0160P3CRITICALCVSS 9.8v302019-03-27
CVE-2019-0160 [CRITICAL] CWE-120 CVE-2019-0160: Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable e Buffer overflow in system firmware for EDK II may allow unauthenticated user to potentially enable escalation of privilege and/or denial of service via network access.
nvd
CVE-2020-10543P3HIGHCVSS 8.2v312020-06-05
CVE-2020-10543 [HIGH] CWE-190 CVE-2020-10543: Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular ex Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
nvd
CVE-2019-5481P3CRITICALCVSS 9.8v29v30+1 more2019-09-16
CVE-2019-5481 [CRITICAL] CWE-415 CVE-2019-5481: Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3. Double-free vulnerability in the FTP-kerberos code in cURL 7.52.0 to 7.65.3.
nvd
CVE-2024-32659P3CRITICALCVSS 9.8v38v39+1 more2024-04-23
CVE-2024-32659 [CRITICAL] CWE-125 CVE-2024-32659: FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to vers FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients prior to version 3.5.1 are vulnerable to out-of-bounds read if `((nWidth == 0) and (nHeight == 0))`. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
nvd
CVE-2021-3518P3HIGHCVSS 8.8v33v342021-05-18
CVE-2021-3518 [HIGH] CWE-416 CVE-2021-3518: There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted fil There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
nvd
CVE-2023-40569P3CRITICALCVSS 9.8v37v38+1 more2023-08-31
CVE-2023-40569 [CRITICAL] CWE-787 CVE-2023-40569: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Write in the `progressive_decompress` function. This issue is likely down to incorrect calculations of the `nXSrc` and `nYSrc` variables. This issue has been addressed in versions 2.11.0 and 3.
nvd
CVE-2021-3115P3HIGHCVSS 7.5v332021-01-26
CVE-2021-3115 [HIGH] CWE-427 CVE-2021-3115: Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an untrusted download).
nvd
CVE-2023-1531P3HIGHCVSS 8.8v36v37+1 more2023-03-21
CVE-2023-1531 [HIGH] CWE-416 CVE-2023-1531: Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potent Use after free in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-0808P3CRITICALCVSS 9.8v38v392024-01-24
CVE-2024-0808 [CRITICAL] CWE-191 CVE-2024-0808: Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to pote Integer underflow in WebUI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
nvd
Fedoraproject Fedora vulnerabilities | cvebase