cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 45 of 264
CVE-2019-13115P3HIGHCVSS 8.1v29v302019-07-16
CVE-2019-13115 [HIGH] CWE-125 CVE-2019-13115: In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has a In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client sy
nvd
CVE-2020-6573P3CRITICALCVSS 9.6v31v332020-09-21
CVE-2020-6573 [CRITICAL] CWE-416 CVE-2020-6573: Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker Use after free in video in Google Chrome on Android prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2022-24303P3CRITICALCVSS 9.1v34v352022-03-28
CVE-2022-24303 [CRITICAL] CVE-2022-24303: Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are misha Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.
nvd
CVE-2021-4048P3CRITICALCVSS 9.1v34v352021-12-08
CVE-2021-4048 [CRITICAL] CWE-125 CVE-2021-4048: An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack t An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
nvd
CVE-2021-21226P3CRITICALCVSS 9.6v32v33+1 more2021-04-26
CVE-2021-21226 [CRITICAL] CWE-416 CVE-2021-21226: Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who ha Use after free in navigation in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2022-40315P3CRITICALCVSS 9.8v35v362022-09-30
CVE-2022-40315 [CRITICAL] CWE-89 CVE-2022-40315: A limited SQL injection risk was identified in the "browse list of users" site administration page. A limited SQL injection risk was identified in the "browse list of users" site administration page.
nvd
CVE-2019-5771P3HIGHCVSS 8.8v29v302019-02-19
CVE-2019-5771 [HIGH] CVE-2019-5771: An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a rem An incorrect JIT of GLSL shaders in SwiftShader in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
nvd
CVE-2021-21109P3CRITICALCVSS 9.6v32v332021-01-08
CVE-2021-21109 [CRITICAL] CWE-416 CVE-2021-21109: Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had Use after free in payments in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21108P3CRITICALCVSS 9.6v32v332021-01-08
CVE-2021-21108 [CRITICAL] CWE-416 CVE-2021-21108: Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had co Use after free in media in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6556P3HIGHCVSS 8.8v332020-09-21
CVE-2020-6556 [HIGH] CWE-787 CVE-2020-6556: Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allowed a remote attacke Heap buffer overflow in SwiftShader in Google Chrome prior to 84.0.4147.135 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-37920P3CRITICALCVSS 9.8v382023-07-25
CVE-2023-37920 [CRITICAL] CWE-345 CVE-2023-37920: Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certi Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an investigation prompted by reporting of security issues in their systems. Ce
nvd
CVE-2020-15965P3HIGHCVSS 8.8v31v32+1 more2020-09-21
CVE-2020-15965 [HIGH] CWE-843 CVE-2020-15965: Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2020-15964P3HIGHCVSS 8.8v31v32+1 more2020-09-21
CVE-2020-15964 [HIGH] CWE-20 CVE-2020-15964: Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attac Insufficient data validation in media in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-3862P3CRITICALCVSS 9.1v292019-03-21
CVE-2019-3862 [CRITICAL] CWE-130 CVE-2019-3862: An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the way SSH_MSG_CHANNEL_REQUEST packets with an exit status message and no payload are parsed. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
nvd
CVE-2021-30590P3HIGHCVSS 8.8v33v34+1 more2021-08-26
CVE-2021-30590 [HIGH] CWE-787 CVE-2021-30590: Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-2805P3HIGHCVSS 8.3v30v31+1 more2020-04-15
CVE-2020-2805 [HIGH] CVE-2020-2805: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u251, 8u241, 11.0.6 and 14; Java SE Embedded: 8u241. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2020-14583P3HIGHCVSS 8.3v31v322020-07-15
CVE-2020-14583 [HIGH] CVE-2020-14583: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Sup Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Libraries). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Succe
nvd
CVE-2022-23959P3CRITICALCVSS 9.1v352022-01-26
CVE-2022-23959 [CRITICAL] CWE-444 CVE-2022-23959: In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Var In Varnish Cache before 6.6.2 and 7.x before 7.0.2, Varnish Cache 6.0 LTS before 6.0.10, and and Varnish Enterprise (Cache Plus) 4.1.x before 4.1.11r6 and 6.0.x before 6.0.9r4, request smuggling can occur for HTTP/1 connections.
nvd
CVE-2022-2852P3HIGHCVSS 8.8v372022-09-26
CVE-2022-2852 [HIGH] CWE-416 CVE-2022-2852: Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potent Use after free in FedCM in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30600P3HIGHCVSS 8.8v33v34+1 more2021-08-26
CVE-2021-30600 [HIGH] CWE-416 CVE-2021-30600: Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
Fedoraproject Fedora vulnerabilities | cvebase