Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 47 of 264
CVE-2023-5472P3HIGHCVSS 8.8v382023-10-25
CVE-2023-5472 [HIGH] CWE-416 CVE-2023-5472: Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to pot
Use after free in Profiles in Google Chrome prior to 118.0.5993.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2885P3HIGHCVSS 8.8v38v39+1 more2024-03-26
CVE-2024-2885 [HIGH] CWE-416 CVE-2024-2885: Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentia
Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4904P3HIGHCVSS 8.6v362023-03-06
CVE-2022-4904 [HIGH] CWE-20 CVE-2022-4904: A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity o
A flaw was found in the c-ares package. The ares_set_sortlist is missing checks about the validity of the input string, which allows a possible arbitrary length stack overflow. This issue may cause a denial of service or a limited impact on confidentiality and integrity.
nvd
CVE-2022-24675P3HIGHCVSS 7.5v34v35+1 more2022-04-20
CVE-2022-24675 [HIGH] CWE-674 CVE-2022-24675: encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large am
encoding/pem in Go before 1.17.9 and 1.18.x before 1.18.1 has a Decode stack overflow via a large amount of PEM data.
nvd
CVE-2022-21699P3HIGHCVSS 8.8v34v352022-01-19
CVE-2022-21699 [HIGH] CWE-250 CVE-2022-21699: IPython (Interactive Python) is a command shell for interactive computing in multiple programming la
IPython (Interactive Python) is a command shell for interactive computing in multiple programming languages, originally developed for the Python programming language. Affected versions are subject to an arbitrary code execution vulnerability achieved by not properly managing cross user temporary files. This vulnerability allows one user to run code as
nvd
CVE-2019-7443P3HIGHCVSS 8.1v28v292019-05-07
CVE-2019-7443 [HIGH] CWE-20 CVE-2019-7443: KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as ro
KDE KAuth before 5.55 allows the passing of parameters with arbitrary types to helpers running as root over DBus via DBusHelperProxy.cpp. Certain types can cause crashes, and trigger the decoding of arbitrary images with dynamically loaded plugins. In other words, KAuth unintentionally causes this plugin code to run as root, which increases the severity
nvd
CVE-2019-9499P3HIGHCVSS 8.1v28v29+1 more2019-04-17
CVE-2019-9499 [HIGH] CWE-346 CVE-2019-9499: The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missi
The implementations of EAP-PWD in wpa_supplicant EAP Peer, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may complete authentication, session key and control of the data connection with a client. Both hostapd with SAE support and wpa_supp
nvd
CVE-2019-9898P3CRITICALCVSS 9.8v28v292019-03-21
CVE-2019-9898 [CRITICAL] CWE-330 CVE-2019-9898: Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
Potential recycling of random numbers used in cryptography exists within PuTTY before 0.71.
nvd
CVE-2019-7165P3CRITICALCVSS 9.8v302019-07-03
CVE-2019-7165 [CRITICAL] CWE-119 CVE-2019-7165: A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.
A buffer overflow in DOSBox 0.74-2 allows attackers to execute arbitrary code.
nvd
CVE-2016-1901P3CRITICALCVSS 9.8v222016-01-20
CVE-2016-1901 [CRITICAL] CWE-119 CVE-2016-1901: Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to ha
Integer overflow in the authenticate_post function in CGit before 0.12 allows remote attackers to have unspecified impact via a large value in the Content-Length HTTP header, which triggers a buffer overflow.
nvd
CVE-2016-7949P3CRITICALCVSS 9.8v24v252016-12-13
CVE-2016-7949 [CRITICAL] CWE-20 CVE-2016-7949: Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org lib
Multiple buffer overflows in the (1) XvQueryAdaptors and (2) XvQueryEncodings functions in X.org libXrender before 0.9.10 allow remote X servers to trigger out-of-bounds write operations via vectors involving length fields.
nvd
CVE-2020-11612P3HIGHCVSS 7.5v332020-04-07
CVE-2020-11612 [HIGH] CWE-770 CVE-2020-11612: The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a
The ZlibDecoders in Netty 4.1.x before 4.1.46 allow for unbounded memory allocation while decoding a ZlibEncoded byte stream. An attacker could send a large ZlibEncoded byte stream to the Netty server, forcing the server to allocate all of its free memory to a single decoder.
nvd
CVE-2021-20232P3CRITICALCVSS 9.8v342021-03-12
CVE-2021-20232 [CRITICAL] CWE-416 CVE-2021-20232: A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c
A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.
nvd
CVE-2019-18609P3CRITICALCVSS 9.8v30v312019-12-01
CVE-2019-18609 [CRITICAL] CWE-787 CVE-2019-18609: An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an i
An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller target_size value than needed. This condition is then carried on to a memcp
nvd
CVE-2021-26937P3CRITICALCVSS 9.8v32v332021-02-09
CVE-2021-26937 [CRITICAL] CWE-88 CVE-2021-26937: encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid
encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.
nvd
CVE-2019-17455P3CRITICALCVSS 9.8v32v332019-10-10
CVE-2019-17455 [CRITICAL] CWE-125 CVE-2019-17455: Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, an
Libntlm through 1.5 relies on a fixed buffer size for tSmbNtlmAuthRequest, tSmbNtlmAuthChallenge, and tSmbNtlmAuthResponse read and write operations, as demonstrated by a stack-based buffer over-read in buildSmbNtlmAuthRequest in smbutil.c for a crafted NTLM request.
nvd
CVE-2022-23222P3HIGHCVSS 7.8v34v352022-01-14
CVE-2022-23222 [HIGH] CWE-476 CVE-2022-23222: kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges beca
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
nvd
CVE-2023-3341P3HIGHCVSS 7.5v37v382023-09-20
CVE-2023-3341 [HIGH] CWE-787 CVE-2023-3341: The code that processes control channel messages sent to `named` calls certain functions recursively
The code that processes control channel messages sent to `named` calls certain functions recursively during packet parsing. Recursion depth is only limited by the maximum accepted packet size; depending on the environment, this may cause the packet-parsing code to run out of available stack memory, causing `named` to terminate unexpectedly. Since each i
nvd
CVE-2023-4232P3HIGHCVSS 8.1v39v402024-04-17
CVE-2023-4232 [HIGH] CWE-119 CVE-2023-4232: A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered with
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_status_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it
nvd
CVE-2023-4235P3HIGHCVSS 8.1v402024-04-17
CVE-2023-4235 [HIGH] CWE-119 CVE-2023-4235: A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered with
A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver_report() function during the SMS decoding. It is assumed that the attack scenario is accessible from a compromised modem, a malicious base station, or just SMS. There is a bound check for this memcpy length in decode_submit(), but it
nvd