Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 42 of 264
CVE-2019-13734P3HIGHCVSS 8.8v30v312019-12-10
CVE-2019-13734 [HIGH] CWE-787 CVE-2019-13734: Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to po
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2024-22373P3CRITICALCVSS 9.8v38v39+1 more2024-04-25
CVE-2024-22373 [CRITICAL] CWE-119 CVE-2024-22373: An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionalit
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2023-47212P3CRITICALCVSS 9.8v38v39+1 more2024-05-01
CVE-2023-47212 [CRITICAL] CWE-190 CVE-2023-47212: A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.2
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2016-2216P3HIGHCVSS 7.5v22v232016-04-07
CVE-2016-2216 [HIGH] CWE-20 CVE-2016-2216: The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before
The HTTP header parsing code in Node.js 0.10.x before 0.10.42, 0.11.6 through 0.11.16, 0.12.x before 0.12.10, 4.x before 4.3.0, and 5.x before 5.6.0 allows remote attackers to bypass an HTTP response-splitting protection mechanism via UTF-8 encoded Unicode characters in the HTTP header, as demonstrated by %c4%8d%c4%8a.
nvd
CVE-2014-1486P3CRITICALCVSS 9.8v19v202014-02-06
CVE-2014-1486 [CRITICAL] CWE-416 CVE-2014-1486: Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox
Use-after-free vulnerability in the imgRequestProxy function in Mozilla Firefox before 27.0, Firefox ESR 24.x before 24.3, Thunderbird before 24.3, and SeaMonkey before 2.24 allows remote attackers to execute arbitrary code via vectors involving unspecified Content-Type values for image data.
nvd
CVE-2009-1902P4MEDIUMCVSS 5.0PoCv9v102009-06-03
CVE-2009-1902 [MEDIUM] CWE-476 CVE-2009-1902: The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of ser
The multipart processor in ModSecurity before 2.5.9 allows remote attackers to cause a denial of service (crash) via a multipart form datapost request with a missing part header name, which triggers a NULL pointer dereference.
nvd
CVE-2022-3620P3CRITICALCVSS 9.8v35v36+1 more2022-10-20
CVE-2022-3620 [CRITICAL] CWE-119 CVE-2022-3620: A vulnerability was found in Exim and classified as problematic. This issue affects the function dma
A vulnerability was found in Exim and classified as problematic. This issue affects the function dmarc_dns_lookup of the file dmarc.c of the component DMARC Handler. The manipulation leads to use after free. The attack may be initiated remotely. The name of the patch is 12fb3842f81bcbd4a4519d5728f2d7e0e3ca1445. It is recommended to apply a patch to
nvd
CVE-2018-3846P3HIGHCVSS 8.8v282018-04-16
CVE-2018-3846 [HIGH] CWE-787 CVE-2018-3846: In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the lib
In the ffgphd and ffgtkn functions in NASA CFITSIO 3.42, specially crafted images parsed via the library can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.
nvd
CVE-2020-6402P3HIGHCVSS 8.8v302020-02-11
CVE-2020-6402 [HIGH] CWE-20 CVE-2020-6402: Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed
Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.
nvd
CVE-2021-34363P3CRITICALCVSS 9.1v34v352021-06-10
CVE-2021-34363 [CRITICAL] CWE-22 CVE-2021-34363: The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitr
The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.
nvd
CVE-2022-32206P3MEDIUMCVSS 6.5v352022-07-07
CVE-2022-32206 [MEDIUM] CWE-770 CVE-2022-32206: curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be c
curl < 7.84.0 supports "chained" HTTP compression algorithms, meaning that a serverresponse can be compressed multiple times and potentially with different algorithms. The number of acceptable "links" in this "decompression chain" was unbounded, allowing a malicious server to insert a virtually unlimited number of compression steps.The use of such a
nvd
CVE-2021-20240P3HIGHCVSS 8.8v33v342021-05-28
CVE-2021-20240 [HIGH] CWE-191 CVE-2021-20240: A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of
A flaw was found in gdk-pixbuf in versions before 2.42.0. An integer wraparound leading to an out of bounds write can occur when a crafted GIF image is loaded. An attacker may cause applications to crash or could potentially execute code on the victim system. The highest threat from this vulnerability is to data confidentiality and integrity as well a
nvd
CVE-2023-30534P4MEDIUMCVSS 4.3PoCv37v382023-09-05
CVE-2023-30534 [MEDIUM] CWE-502 CVE-2023-30534: Cacti is an open source operational monitoring and fault management framework. There are two instanc
Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included, making them inaccessible and the insecure deserializations not exploitable. Eac
nvd
CVE-2016-1522P3HIGHCVSS 8.8v22v232016-02-13
CVE-2016-1522 [HIGH] CWE-119 CVE-2016-1522: Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR
Code.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not consider recursive load calls during a size check, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly execute arbitrary code via a crafted Graphite smart font.
nvd
CVE-2020-9983P3HIGHCVSS 8.8v32v332020-10-16
CVE-2020-9983 [HIGH] CWE-787 CVE-2020-9983: An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Saf
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in Safari 14.0. Processing maliciously crafted web content may lead to code execution.
nvd
CVE-2019-18423P3HIGHCVSS 8.8v29v30+1 more2019-10-31
CVE-2019-18423 [HIGH] CWE-193 CVE-2019-18423: An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of servi
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service via a XENMEM_add_to_physmap hypercall. p2m->max_mapped_gfn is used by the functions p2m_resolve_translation_fault() and p2m_get_entry() to sanity check guest physical frame. The rest of the code in the two functions will assume that there is a valid
nvd
CVE-2022-3199P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3199 [HIGH] CWE-416 CVE-2022-3199: Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to poten
Use after free in Frames in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-24828P3HIGHCVSS 8.8v34v35+1 more2022-04-13
CVE-2022-24828 [HIGH] CWE-20 CVE-2022-24828: Composer is a dependency manager for the PHP programming language. Integrators using Composer code t
Composer is a dependency manager for the PHP programming language. Integrators using Composer code to call `VcsDriver::getFileContent` can have a code injection vulnerability if the user can control the `$file` or `$identifier` argument. This leads to a vulnerability on packagist.org for example where the composer.json's `readme` field can be used as a
nvd
CVE-2019-11036P3CRITICALCVSS 9.1v28v29+1 more2019-05-03
CVE-2019-11036 [CRITICAL] CWE-126 CVE-2019-11036: When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18
When processing certain files, PHP EXIF extension in versions 7.1.x below 7.1.29, 7.2.x below 7.2.18 and 7.3.x below 7.3.5 can be caused to read past allocated buffer in exif_process_IFD_TAG function. This may lead to information disclosure or crash.
nvd
CVE-2016-4609P3CRITICALCVSS 9.8v302016-07-22
CVE-2016-4609 [CRITICAL] CVE-2016-4609: libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud befo
libxslt in Apple iOS before 9.3.3, OS X before 10.11.6, iTunes before 12.4.2 on Windows, iCloud before 5.2.1 on Windows, tvOS before 9.2.2, and watchOS before 2.2.2 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors, a different vulnerability than CVE-2016-4607, CVE-2016-460
nvd