Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 38 of 264
CVE-2024-5499P3HIGHCVSS 8.8v39v402024-05-30
CVE-2024-5499 [HIGH] CWE-787 CVE-2024-5499: Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacke
Out of bounds write in Streams API in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-23727P3HIGHCVSS 7.5v352021-12-29
CVE-2021-23727 [HIGH] CWE-77 CVE-2021-23727: This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored
This affects the package celery before 5.2.2. It by default trusts the messages and metadata stored in backends (result stores). When reading task metadata from the backend, the data is deserialized. Given that an attacker can gain access to, or somehow manipulate the metadata within a celery backend, they could trigger a stored command injection vulner
nvd
CVE-2015-7687P3CRITICALCVSS 9.8v22v232017-10-16
CVE-2015-7687 [CRITICAL] CWE-416 CVE-2015-7687: Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of
Use-after-free vulnerability in OpenSMTPD before 5.7.2 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via vectors involving req_ca_vrfy_smtp and req_ca_vrfy_mta.
nvd
CVE-2019-13764P3HIGHCVSS 8.8v30v312019-12-10
CVE-2019-13764 [HIGH] CWE-843 CVE-2019-13764: Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to pot
Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6383P3HIGHCVSS 8.8v30v312020-02-27
CVE-2020-6383 [HIGH] CWE-843 CVE-2020-6383: Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentiall
Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-19334P3CRITICALCVSS 9.8v312019-12-06
CVE-2019-19334 [CRITICAL] CWE-121 CVE-2019-19334: In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way li
In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an attacker to cause a denial of service or possibly gain code execution.
nvd
CVE-2015-0778P3HIGHCVSS 7.5v20v21+1 more2015-03-16
CVE-2015-0778 [HIGH] CWE-77 CVE-2015-0778: osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in
osc before 0.151.0 allows remote attackers to execute arbitrary commands via shell metacharacters in a _service file.
nvd
CVE-2021-21996P3HIGHCVSS 7.5v33v34+1 more2021-09-08
CVE-2021-21996 [HIGH] CVE-2021-21996: An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and s
An issue was discovered in SaltStack Salt before 3003.3. A user who has control of the source, and source_hash URLs can gain full file system access as root on a salt minion.
nvd
CVE-2021-20231P3CRITICALCVSS 9.8v342021-03-12
CVE-2021-20231 [CRITICAL] CWE-416 CVE-2021-20231: A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to
A flaw was found in gnutls. A use after free issue in client sending key_share extension may lead to memory corruption and other consequences.
nvd
CVE-2021-23214P3HIGHCVSS 8.1v34v352022-03-04
CVE-2021-23214 [HIGH] CWE-89 CVE-2021-23214: When the server is configured to use trust authentication with a clientcert requirement or to use ce
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
nvd
CVE-2020-26154P3CRITICALCVSS 9.8v32v332020-09-30
CVE-2020-26154 [CRITICAL] CWE-120 CVE-2020-26154: url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrate
url.cpp in libproxy through 0.4.15 is prone to a buffer overflow when PAC is enabled, as demonstrated by a large PAC file that is delivered without a Content-length header.
nvd
CVE-2019-3833P3HIGHCVSS 7.5v28v29+1 more2019-03-14
CVE-2019-3833 [HIGH] CWE-835 CVE-2019-3833: Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection
Openwsman, versions up to and including 2.6.9, are vulnerable to infinite loop in process_connection() when parsing specially crafted HTTP requests. A remote, unauthenticated attacker can exploit this vulnerability by sending malicious HTTP request to cause denial of service to openwsman server.
nvd
CVE-2019-16239P3CRITICALCVSS 9.8v29v30+1 more2019-09-17
CVE-2019-16239 [CRITICAL] CWE-120 CVE-2019-16239: process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses
process_http_response in OpenConnect before 8.05 has a Buffer Overflow when a malicious server uses HTTP chunked encoding with crafted chunk sizes.
nvd
CVE-2010-0395P3CRITICALCVSS 9.3v11v12+1 more2010-06-10
CVE-2010-0395 [CRITICAL] CVE-2010-0395: OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro
OpenOffice.org 2.x and 3.0 before 3.2.1 allows user-assisted remote attackers to bypass Python macro security restrictions and execute arbitrary Python code via a crafted OpenDocument Text (ODT) file that triggers code execution when the macro directory structure is previewed.
nvd
CVE-2019-3846P3HIGHCVSS 8.8v29v302019-06-03
CVE-2019-3846 [HIGH] CWE-122 CVE-2019-3846: A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
nvd
CVE-2013-1895P3HIGHCVSS 7.5v17v182020-01-28
CVE-2013-1895 [HIGH] CWE-307 CVE-2013-1895: The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which
The py-bcrypt module before 0.3 for Python does not properly handle concurrent memory access, which allows attackers to bypass authentication via multiple authentication requests, which trigger the password hash to be overwritten.
nvd
CVE-2016-7405P3CRITICALCVSS 9.8v252016-10-03
CVE-2016-7405 [CRITICAL] CWE-89 CVE-2016-7405: The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow
The qstr method in the PDO driver in the ADOdb Library for PHP before 5.x before 5.20.7 might allow remote attackers to conduct SQL injection attacks via vectors related to incorrect quoting.
nvd
CVE-2022-24713P3HIGHCVSS 7.5v34v35+1 more2022-03-08
CVE-2022-24713 [HIGH] CWE-400 CVE-2022-24713: regex is an implementation of regular expressions for the Rust language. The regex crate features bu
regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This guarantee is documented and it's consi
nvd
CVE-2022-0391P3HIGHCVSS 7.5v34v352022-02-09
CVE-2022-0391 [HIGH] CWE-74 CVE-2022-0391: A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uni
A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path. This flaw allows an attacker to input a crafted URL, leading to injection atta
nvd
CVE-2020-2803P3HIGHCVSS 8.3v30v31+1 more2020-04-15
CVE-2020-2803 [HIGH] CVE-2020-2803: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd