cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 44 of 264
CVE-2016-7947P3CRITICALCVSS 9.8v24v252016-12-13
CVE-2016-7947 [CRITICAL] CWE-190 CVE-2016-7947: Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of- Multiple integer overflows in X.org libXrandr before 1.5.1 allow remote X servers to trigger out-of-bounds write operations via a crafted response.
nvd
CVE-2016-7948P3CRITICALCVSS 9.8v24v252016-12-13
CVE-2016-7948 [CRITICAL] CWE-787 CVE-2016-7948: X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by le X.org libXrandr before 1.5.1 allows remote X servers to trigger out-of-bounds write operations by leveraging mishandling of reply data.
nvd
CVE-2013-4409P3CRITICALCVSS 9.8v18v19+1 more2019-11-04
CVE-2013-4409 [CRITICAL] CWE-20 CVE-2013-4409: An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board An eval() vulnerability exists in Python Software Foundation Djblets 0.7.21 and Beanbag Review Board before 1.7.15 when parsing JSON requests.
nvd
CVE-2021-23358P3HIGHCVSS 7.2v33v342021-03-29
CVE-2021-23358 [HIGH] CWE-94 CVE-2021-23358: The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerabl The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.
nvd
CVE-2019-10746P3CRITICALCVSS 9.8v30v312019-08-23
CVE-2019-10746 [CRITICAL] CWE-88 CVE-2019-10746: mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The func mixin-deep is vulnerable to Prototype Pollution in versions before 1.3.2 and version 2.0.0. The function mixin-deep could be tricked into adding or modifying properties of Object.prototype using a constructor payload.
nvd
CVE-2016-9956P3HIGHCVSS 7.5v24v252017-02-22
CVE-2016-9956 [HIGH] CWE-284 CVE-2016-9956: The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files The route manager in FlightGear before 2016.4.4 allows remote attackers to write to arbitrary files via a crafted Nasal script.
nvd
CVE-2018-21029P3CRITICALCVSS 9.8v312019-10-30
CVE-2018-21029 [CRITICAL] CWE-295 CVE-2018-21029: systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Ov systemd 239 through 245 accepts any certificate signed by a trusted certificate authority for DNS Over TLS. Server Name Indication (SNI) is not sent, and there is no hostname validation with the GnuTLS backend. NOTE: This has been disputed by the developer as not a vulnerability since hostname validation does not have anything to do with this issu
nvd
CVE-2013-7088P3CRITICALCVSS 9.8v17v182019-11-15
CVE-2013-7088 [CRITICAL] CWE-120 CVE-2013-7088: ClamAV before 0.97.7 has buffer overflow in the libclamav component ClamAV before 0.97.7 has buffer overflow in the libclamav component
nvd
CVE-2024-32462P3HIGHCVSS 8.4v39v402024-04-18
CVE-2024-32462 [HIGH] CWE-88 CVE-2024-32462: Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. in versions before 1.10.9, 1.12.9, 1.14.6, and 1.15.8, a malicious or compromised Flatpak app could execute arbitrary code outside its sandbox. Normally, the `--command` argument of `flatpak run` expects to be given a command to run in the specified Fla
nvd
CVE-2023-2794P3HIGHCVSS 8.1v39v402024-04-10
CVE-2023-2794 [HIGH] CWE-119 CVE-2023-2794: A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered with A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it was fo
nvd
CVE-2023-4234P3HIGHCVSS 8.1v38v39+1 more2024-04-17
CVE-2023-4234 [HIGH] CWE-119 CVE-2023-4234: A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered with A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_submit_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it
nvd
CVE-2021-20314P3CRITICALCVSS 9.8v33v34+1 more2021-08-12
CVE-2021-20314 [CRITICAL] CWE-787 CVE-2021-20314: Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead t Stack buffer overflow in libspf2 versions below 1.2.11 when processing certain SPF macros can lead to Denial of service and potentially code execution via malicious crafted SPF explanation messages.
nvd
CVE-2022-27404P3CRITICALCVSS 9.8v34v35+1 more2022-04-22
CVE-2022-27404 [CRITICAL] CWE-787 CVE-2022-27404: FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer ove FreeType commit 1e2eb65048f75c64b68708efed6ce904c31f3b2f was discovered to contain a heap buffer overflow via the function sfnt_init_face.
nvd
CVE-2022-30767P3CRITICALCVSS 9.8v362022-05-16
CVE-2022-30767 [CRITICAL] CVE-2022-30767: nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbound nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.
nvd
CVE-2016-5157P3HIGHCVSS 8.8v23v24+1 more2016-09-11
CVE-2016-5157 [HIGH] CWE-119 CVE-2016-5157: Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDF Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
nvd
CVE-2020-13584P3HIGHCVSS 8.8v322020-12-03
CVE-2020-13584 [HIGH] CWE-416 CVE-2020-13584: An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specia An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs to visit a malicious web site to trigger this vulnerability.
nvd
CVE-2016-1283P3CRITICALCVSS 9.8v22v232016-01-03
CVE-2016-1283 [CRITICAL] CWE-119 CVE-2016-1283: The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}- The pcre_compile2 function in pcre_compile.c in PCRE 8.38 mishandles the /((?:F?+(?:^(?(R)a+\"){99}-))(?J)(?'R'(?'R'<((?'RR'(?'R'\){97)?J)?J)(?'R'(?'R'\){99|(:(?|(?'R')(\k'R')|((?'R')))H'R'R)(H'R))))))/ pattern and related patterns with named subgroups, which allows remote attackers to cause a denial of service (heap-based buffer overflow) or possib
nvd
CVE-2022-24048P3HIGHCVSS 7.8v34v35+1 more2022-02-18
CVE-2022-24048 [HIGH] CWE-121 CVE-2022-24048: MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This MariaDB CONNECT Storage Engine Stack-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of
nvd
CVE-2022-29154P3HIGHCVSS 7.4v35v362022-08-02
CVE-2022-29154 [HIGH] CWE-20 CVE-2022-29154: An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrar An issue was discovered in rsync before 3.2.5 that allows malicious remote servers to write arbitrary files inside the directories of connecting peers. The server chooses which files/directories are sent to the client. However, the rsync client performs insufficient validation of file names. A malicious rsync server (or Man-in-The-Middle attacker) can
nvd
CVE-2021-41184P3MEDIUMCVSS 6.1v33v34+2 more2021-10-26
CVE-2021-41184 [MEDIUM] CWE-79 CVE-2021-41184: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `of` option is now treated as a CSS selector. A workaround is to not accept the val
nvd
Fedoraproject Fedora vulnerabilities | cvebase