Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 41 of 264
CVE-2018-20060P3CRITICALCVSS 9.8v28v29+1 more2018-12-11
CVE-2018-20060 [CRITICAL] CVE-2018-20060: urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-ori
urllib3 before version 1.23 does not remove the Authorization HTTP header when following a cross-origin redirect (i.e., a redirect that differs in host, port, or scheme). This can allow for credentials in the Authorization header to be exposed to unintended hosts or transmitted in cleartext.
nvd
CVE-2015-0411P3HIGHCVSS 7.5v202015-01-21
CVE-2015-0411 [HIGH] CVE-2015-0411: Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows
Unspecified vulnerability in Oracle MySQL Server 5.5.40 and earlier, and 5.6.21 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Server : Security : Encryption.
nvd
CVE-2016-7942P3CRITICALCVSS 9.8v252016-12-13
CVE-2016-7942 [CRITICAL] CWE-264 CVE-2016-7942: The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges
The XGetImage function in X.org libX11 before 1.6.4 might allow remote X servers to gain privileges via vectors involving image type and geometry, which triggers out-of-bounds read operations.
nvd
CVE-2020-11008P3HIGHCVSS 7.5v31v322020-04-21
CVE-2020-11008 [HIGH] CWE-20 CVE-2020-11008: Affected versions of Git have a vulnerability whereby Git can be tricked into sending private creden
Affected versions of Git have a vulnerability whereby Git can be tricked into sending private credentials to a host controlled by an attacker. This bug is similar to CVE-2020-5260(GHSA-qm7j-c969-7j4q). The fix for that bug still left the door open for an exploit where _some_ credential is leaked (but the attacker cannot control which one). Git uses ext
nvd
CVE-2020-12693P3HIGHCVSS 8.1v31v322020-05-21
CVE-2020-12693 [HIGH] CVE-2020-12693: Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation
Slurm 19.05.x before 19.05.7 and 20.02.x before 20.02.3, in the rare case where Message Aggregation is enabled, allows Authentication Bypass via an Alternate Path or Channel. A race condition allows a user to launch a process as an arbitrary user.
nvd
CVE-2020-36327P3HIGHCVSS 8.8v342021-04-29
CVE-2020-36327 [HIGH] CVE-2020-36327: Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based o
Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly depended on by the application. NOTE: it is not c
nvd
CVE-2016-2334P3HIGHCVSS 7.8v23v242016-12-13
CVE-2016-2334 [HIGH] CWE-119 CVE-2016-2334: Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16
Heap-based buffer overflow in the NArchive::NHfs::CHandler::ExtractZlibFile method in 7zip before 16.00 and p7zip allows remote attackers to execute arbitrary code via a crafted HFS+ image.
nvd
CVE-2020-5312P3CRITICALCVSS 9.8v30v312020-01-03
CVE-2020-5312 [CRITICAL] CWE-120 CVE-2020-5312: libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.
nvd
CVE-2020-12695P3HIGHCVSS 7.5v31v322020-06-08
CVE-2020-12695 [HIGH] CWE-276 CVE-2020-12695: The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance
The Open Connectivity Foundation UPnP specification before 2020-04-17 does not forbid the acceptance of a subscription request with a delivery URL on a different network segment than the fully qualified event-subscription URL, aka the CallStranger issue.
nvd
CVE-2019-18676P3HIGHCVSS 7.5v30v312019-11-26
CVE-2019-18676 [HIGH] CWE-787 CVE-2019-18676: An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there i
An issue was discovered in Squid 3.x and 4.x through 4.8. Due to incorrect input validation, there is a heap-based buffer overflow that can result in Denial of Service to all clients using the proxy. Severity is high due to this vulnerability occurring before normal security checks; any remote client that can reach the proxy port can trivially perform
nvd
CVE-2016-7944P3CRITICALCVSS 9.8v24v252016-12-13
CVE-2016-7944 [CRITICAL] CWE-190 CVE-2016-7944: Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to
Integer overflow in X.org libXfixes before 5.0.3 on 32-bit platforms might allow remote X servers to gain privileges via a length value of INT_MAX, which triggers the client to stop reading data and get out of sync.
nvd
CVE-2022-24882P3HIGHCVSS 7.5v34v35+1 more2022-04-26
CVE-2022-24882 [HIGH] CWE-287 CVE-2022-24882: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, N
FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP clients are not affected. The vulnerability is patched in FreeRDP 2.7.0. There a
nvd
CVE-2021-28834P3CRITICALCVSS 9.8v32v33+1 more2021-03-19
CVE-2021-28834 [CRITICAL] CVE-2021-28834: Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thu
Kramdown before 2.3.1 does not restrict Rouge formatters to the Rouge::Formatters namespace, and thus arbitrary classes can be instantiated.
nvd
CVE-2020-17353P3CRITICALCVSS 9.8v31v322020-08-05
CVE-2020-17353 [CRITICAL] CVE-2020-17353: scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe i
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
nvd
CVE-2021-21215P3MEDIUMCVSS 6.5v32v33+1 more2021-04-26
CVE-2021-21215 [MEDIUM] CWE-290 CVE-2021-21215: Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote att
Inappropriate implementation in Autofill in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to spoof security UI via a crafted HTML page.
nvd
CVE-2014-0221P3MEDIUMCVSS 4.3v19v202014-06-05
CVE-2014-0221 [MEDIUM] CVE-2014-0221: The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m,
The dtls1_get_message_fragment function in d1_both.c in OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h allows remote attackers to cause a denial of service (recursion and client crash) via a DTLS hello message in an invalid DTLS handshake.
nvd
CVE-2017-9103P3CRITICALCVSS 9.8v31v322020-06-18
CVE-2017-9103 [CRITICAL] CWE-119 CVE-2017-9103: An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__f
An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. Depending on the circumstances, an attacker might be able to trick adns into crashing the calling program, leaking aspects of the contents of some of its
nvd
CVE-2022-23304P3CRITICALCVSS 9.8v352022-01-17
CVE-2022-23304 [CRITICAL] CVE-2022-23304: The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable
The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.
nvd
CVE-2021-22915P3CRITICALCVSS 9.8v33v342021-06-11
CVE-2021-22915 [CRITICAL] CWE-307 CVE-2021-22915: Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nextcloud brute-force protection.
nvd
CVE-2022-1227P3HIGHCVSS 8.8v34v352022-04-29
CVE-2022-1227 [HIGH] CWE-281 CVE-2022-1227: A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or
nvd