cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 39 of 264
CVE-2016-3674P3HIGHCVSS 7.5v22v232016-05-17
CVE-2016-3674 [HIGH] CWE-200 CVE-2016-3674: Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDr Multiple XML external entity (XXE) vulnerabilities in the (1) Dom4JDriver, (2) DomDriver, (3) JDomDriver, (4) JDom2Driver, (5) SjsxpDriver, (6) StandardStaxDriver, and (7) WstxDriver drivers in XStream before 1.4.9 allow remote attackers to read arbitrary files via a crafted XML document.
nvd
CVE-2019-19010P3CRITICALCVSS 9.8v29v30+1 more2019-11-16
CVE-2019-19010 [CRITICAL] CWE-94 CVE-2019-19010: Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) a Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
nvd
CVE-2021-30475P3CRITICALCVSS 9.8v342021-06-04
CVE-2021-30475 [CRITICAL] CWE-120 CVE-2021-30475: aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow. aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
nvd
CVE-2016-6233P3CRITICALCVSS 9.8v23v24+1 more2017-02-17
CVE-2016-6233 [CRITICAL] CWE-89 CVE-2016-6233: The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might all The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.
nvd
CVE-2022-0582P3CRITICALCVSS 9.8v34v352022-02-14
CVE-2022-0582 [CRITICAL] CWE-476 CVE-2022-0582: Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 all Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
nvd
CVE-2021-20307P3CRITICALCVSS 9.8v32v33+1 more2021-04-05
CVE-2021-20307 [CRITICAL] CWE-134 CVE-2021-20307: Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlie Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
nvd
CVE-2022-36227P3CRITICALCVSS 9.8v372022-11-22
CVE-2022-36227 [CRITICAL] CWE-476 CVE-2022-36227: In libarchive before 3.6.2, the software does not check for an error after calling calloc function t In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is e
nvd
CVE-2021-32810P3CRITICALCVSS 9.8v342021-08-02
CVE-2021-32810 [CRITICAL] CWE-362 CVE-2021-32810: crossbeam-deque is a package of work-stealing deques for building task schedulers when programming i crossbeam-deque is a package of work-stealing deques for building task schedulers when programming in Rust. In versions prior to 0.7.4 and 0.8.0, the result of the race condition is that one or more tasks in the worker queue can be popped twice instead of other tasks that are forgotten and never popped. If tasks are allocated on the heap, this can
nvd
CVE-2024-21795P3CRITICALCVSS 9.8v402024-02-20
CVE-2024-21795 [CRITICAL] CWE-122 CVE-2024-21795: A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Pr A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2015-20107P3HIGHCVSS 7.6v35v36+1 more2022-04-13
CVE-2015-20107 [HIGH] CWE-77 CVE-2015-20107: In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into command In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported t
nvd
CVE-2024-22097P3CRITICALCVSS 9.8v402024-02-20
CVE-2024-22097 [CRITICAL] CWE-415 CVE-2024-22097: A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Pro A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0. A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2018-12022P3HIGHCVSS 7.5v292019-03-21
CVE-2018-12022 [HIGH] CWE-502 CVE-2018-12022: An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When De An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the servic
nvd
CVE-2018-3849P3HIGHCVSS 8.8v282018-04-16
CVE-2018-3849 [HIGH] CWE-787 CVE-2018-3849: In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cau In the ffghtb function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
nvd
CVE-2018-3848P3HIGHCVSS 8.8v282018-04-16
CVE-2018-3848 [HIGH] CWE-787 CVE-2018-3848: In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cau In the ffghbn function in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
nvd
CVE-2021-21201P3CRITICALCVSS 9.6v32v33+1 more2021-04-26
CVE-2021-21201 [CRITICAL] CWE-416 CVE-2021-21201: Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who h Use after free in permissions in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-30547P3HIGHCVSS 8.8v342021-06-15
CVE-2021-30547 [HIGH] CWE-787 CVE-2021-30547: Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to po Out of bounds write in ANGLE in Google Chrome prior to 91.0.4472.101 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2022-39956P3CRITICALCVSS 9.8v35v36+1 more2022-09-20
CVE-2022-39956 [CRITICAL] CWE-863 CVE-2022-39956: The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipar The OWASP ModSecurity Core Rule Set (CRS) is affected by a partial rule set bypass for HTTP multipart requests by submitting a payload that uses a character encoding scheme via the Content-Type or the deprecated Content-Transfer-Encoding multipart MIME header fields that will not be decoded and inspected by the web application firewall engine and
nvd
CVE-2022-1996P3CRITICALCVSS 9.1v35v362022-06-08
CVE-2022-1996 [CRITICAL] CWE-639 CVE-2022-1996: Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.
nvd
CVE-2020-6096P3HIGHCVSS 8.1v31v322020-04-01
CVE-2020-6096 [HIGH] CWE-195 CVE-2020-6096: An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU gl An exploitable signed comparison vulnerability exists in the ARMv7 memcpy() implementation of GNU glibc 2.30.9000. Calling memcpy() (on ARMv7 targets that utilize the GNU glibc implementation) with a negative value for the 'num' parameter results in a signed comparison vulnerability. If an attacker underflows the 'num' parameter to memcpy(), this vulner
nvd
CVE-2016-5386P3HIGHCVSS 8.1v23v242016-07-19
CVE-2016-5386 [HIGH] CWE-284 CVE-2016-5386: The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect a CGI application's outbound HTTP traffic to an arbitrary proxy se
nvd
Fedoraproject Fedora vulnerabilities | cvebase