cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 4 of 264
CVE-2022-3038P1HIGHCVSS 8.8KEVv372022-09-26
CVE-2022-3038 [HIGH] CWE-416 CVE-2022-3038: Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21166P1HIGHCVSS 8.8KEVv32v33+1 more2021-03-09
CVE-2021-21166 [HIGH] CWE-362 CVE-2021-21166: Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially e Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2024-4671P1CRITICALCVSS 9.6KEVv38v39+1 more2024-05-14
CVE-2024-4671 [CRITICAL] CWE-416 CVE-2024-4671: Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-13671P1HIGHCVSS 8.8KEVRansomwarev32v332020-11-20
CVE-2020-13671 [HIGH] CWE-434 CVE-2020-13671: Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files Drupal core does not properly sanitize certain filenames on uploaded files, which can lead to files being interpreted as the incorrect extension and served as the wrong MIME type or executed as PHP for certain hosting configurations. This issue affects: Drupal Drupal Core 9.0 versions prior to 9.0.8, 8.9 versions prior to 8.9.9, 8.8 versions prior to 8
nvd
CVE-2023-42917P1HIGHCVSS 8.8KEVv38v392023-11-30
CVE-2023-42917 [HIGH] CWE-787 CVE-2023-42917: A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17 A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
nvd
CVE-2021-37973P1CRITICALCVSS 9.6KEVv33v352021-10-08
CVE-2021-37973 [CRITICAL] CWE-416 CVE-2021-37973: Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had c Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21148P1HIGHCVSS 8.8KEVv32v332021-02-09
CVE-2021-21148 [HIGH] CWE-787 CVE-2021-21148: Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to pote Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.150 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-2136P1CRITICALCVSS 9.6KEVv36v37+1 more2023-04-19
CVE-2023-2136 [CRITICAL] CWE-190 CVE-2023-2136: Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-1789P1HIGHCVSS 8.8KEVv32v332021-04-02
CVE-2021-1789 [HIGH] CWE-843 CVE-2021-1789: A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big A type confusion issue was addressed with improved state handling. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, tvOS 14.4, watchOS 7.3, iOS 14.4 and iPadOS 14.4, Safari 14.0.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2024-4761P1HIGHCVSS 8.8KEVv38v39+1 more2024-05-14
CVE-2024-4761 [HIGH] CWE-787 CVE-2024-4761: Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perf Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-1870P1CRITICALCVSS 9.8KEVv32v332021-04-02
CVE-2021-1870 [CRITICAL] CVE-2021-1870: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, S A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2021-1871P1CRITICALCVSS 9.8KEVv332021-04-02
CVE-2021-1871 [CRITICAL] CVE-2021-1871: A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, S A logic issue was addressed with improved restrictions. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, iOS 14.4 and iPadOS 14.4. A remote attacker may be able to cause arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..
nvd
CVE-2022-3075P1CRITICALCVSS 9.6KEVv372022-09-26
CVE-2022-3075 [CRITICAL] CWE-20 CVE-2022-3075: Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attac Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2023-7024P1HIGHCVSS 8.8KEVv38v392023-12-21
CVE-2023-7024 [HIGH] CWE-787 CVE-2023-7024: Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-30952P1HIGHCVSS 7.8KEVv34v352021-08-24
CVE-2021-30952 [HIGH] CWE-190 CVE-2021-30952: An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2021-21193P1HIGHCVSS 8.8KEVv322021-03-16
CVE-2021-21193 [HIGH] CWE-416 CVE-2021-21193: Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentia Use after free in Blink in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21206P1HIGHCVSS 8.8KEVv32v33+1 more2021-04-26
CVE-2021-21206 [HIGH] CWE-416 CVE-2021-21206: Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potenti Use after free in Blink in Google Chrome prior to 89.0.4389.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30554P1HIGHCVSS 8.8KEVv33v342021-07-02
CVE-2021-30554 [HIGH] CWE-416 CVE-2021-30554: Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potenti Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-42916P1MEDIUMCVSS 6.5KEVv38v392023-11-30
CVE-2023-42916 [MEDIUM] CWE-125 CVE-2023-42916: An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1. An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
nvd
CVE-2021-30533P2MEDIUMCVSS 6.5KEVv33v342021-06-07
CVE-2021-30533 [MEDIUM] CWE-863 CVE-2021-30533: Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a rem Insufficient policy enforcement in PopupBlocker in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted iframe.
nvd
Fedoraproject Fedora vulnerabilities | cvebase