cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 48 of 264
CVE-2020-11979P3HIGHCVSS 7.5v31v32+1 more2020-10-01
CVE-2020-11979 [HIGH] CWE-379 CVE-2020-11979: As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it crea As mitigation for CVE-2020-1945 Apache Ant 1.10.8 changed the permissions of temporary files it created so that only the current user was allowed to access them. Unfortunately the fixcrlf task deleted the temporary file and created a new one without said protection, effectively nullifying the effort. This would still allow an attacker to inject modifi
nvd
CVE-2020-10232P3CRITICALCVSS 9.8v30v31+1 more2020-03-09
CVE-2020-10232 [CRITICAL] CWE-787 CVE-2020-10232: In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability In version 4.8.0 and earlier of The Sleuth Kit (TSK), there is a stack buffer overflow vulnerability in the YAFFS file timestamp parsing logic in yaffsfs_istat() in fs/yaffs.c.
nvd
CVE-2019-16378P3CRITICALCVSS 9.8v29v30+1 more2019-09-17
CVE-2019-16378 [CRITICAL] CWE-290 CVE-2019-16378: OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability w OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 is prone to a signature-bypass vulnerability with multiple From: addresses, which might affect applications that consider a domain name to be relevant to the origin of an e-mail message.
nvd
CVE-2021-28879P3CRITICALCVSS 9.8v32v33+1 more2021-04-11
CVE-2021-28879 [CRITICAL] CWE-190 CVE-2021-28879: In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size d In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow. This bug can lead to a buffer overflow when a consumed Zip iterator is used again.
nvd
CVE-2021-43859P3HIGHCVSS 7.5v34v352022-02-01
CVE-2021-43859 [HIGH] CWE-400 CVE-2021-43859: XStream is an open source java library to serialize objects to XML and back again. Versions prior to XStream is an open source java library to serialize objects to XML and back again. Versions prior to 1.4.19 may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of service only by manipulating the processed input stream. XStream 1.4.19 monitors an
nvd
CVE-2013-2166P3CRITICALCVSS 9.8v192019-12-10
CVE-2013-2166 [CRITICAL] CWE-326 CVE-2013-2166: python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
nvd
CVE-2017-9109P3CRITICALCVSS 9.8v31v322020-06-18
CVE-2017-9109 [CRITICAL] CWE-119 CVE-2017-9109: An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first R An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interleaving answers for the CNAME target, with the CNAME itself. In that case the answer data structure (o
nvd
CVE-2020-7677P3CRITICALCVSS 9.8v36v372022-07-25
CVE-2020-7677 [CRITICAL] CVE-2020-7677: This affects the package thenify before 3.3.1. The name argument provided to the package can be cont This affects the package thenify before 3.3.1. The name argument provided to the package can be controlled by users without any sanitization, and this is provided to the eval function without any sanitization.
nvd
CVE-2021-30614P3HIGHCVSS 8.8v352021-09-03
CVE-2021-30614 [HIGH] CWE-787 CVE-2021-30614: Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
nvd
CVE-2020-10878P3HIGHCVSS 8.6v312020-06-05
CVE-2020-10878 [HIGH] CWE-190 CVE-2020-10878: Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING Perl before 5.30.3 has an integer overflow related to mishandling of a "PL_regkind[OP(n)] == NOTHING" situation. A crafted regular expression could lead to malformed bytecode with a possibility of instruction injection.
nvd
CVE-2016-9014P3HIGHCVSS 8.1v24v252016-12-09
CVE-2016-9014 [HIGH] CWE-264 CVE-2016-9014: Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBU Django before 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3, when settings.DEBUG is True, allow remote attackers to conduct DNS rebinding attacks by leveraging failure to validate the HTTP Host header against settings.ALLOWED_HOSTS.
nvd
CVE-2021-33813P3HIGHCVSS 7.5v352021-06-16
CVE-2021-33813 [HIGH] CWE-611 CVE-2021-33813: An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
nvd
CVE-2022-24052P3HIGHCVSS 7.8v34v35+1 more2022-02-18
CVE-2022-24052 [HIGH] CWE-122 CVE-2022-24052: MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This v MariaDB CONNECT Storage Engine Heap-based Buffer Overflow Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of
nvd
CVE-2021-20288P3HIGHCVSS 7.2v32v33+1 more2021-04-15
CVE-2021-20288 [HIGH] CWE-287 CVE-2021-20288: An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_ An authentication flaw was found in ceph in versions before 14.2.20. When the monitor handles CEPHX_GET_AUTH_SESSION_KEY requests, it doesn't sanitize other_keys, allowing key reuse. An attacker who can request a global_id can exploit the ability of any user to request a global_id previously associated with another user, as ceph does not force the reu
nvd
CVE-2017-12170P3CRITICALCVSS 9.8v26v272017-09-21
CVE-2017-12170 [CRITICAL] CVE-2017-12170: Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due Downstream version 1.0.46-1 of pure-ftpd as shipped in Fedora was vulnerable to packaging error due to which the original configuration was ignored after update and service started running with default configuration. This has security implications because of overriding security-related configuration. This issue doesn't affect upstream version of pure-ftpd.
nvd
CVE-2019-10196P3CRITICALCVSS 9.8v272021-03-19
CVE-2019-10196 [CRITICAL] CWE-665 CVE-2019-10196: A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent pas A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker co
nvd
CVE-2022-20785P3HIGHCVSS 7.5v34v35+1 more2022-05-04
CVE-2022-20785 [HIGH] CWE-401 CVE-2022-20785: On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and e On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in HTML file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of
nvd
CVE-2022-20770P3HIGHCVSS 7.5v34v35+1 more2022-05-04
CVE-2022-20770 [HIGH] CWE-399 CVE-2022-20770: On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and e On April 20, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in CHM file parser of Clam AntiVirus (ClamAV) versions 0.104.0 through 0.104.2 and LTS version 0.103.5 and prior versions could allow an unauthenticated, remote attacker to cause a denial of
nvd
CVE-2020-6466P3CRITICALCVSS 9.6v31v322020-05-21
CVE-2020-6466 [CRITICAL] CWE-416 CVE-2020-6466: Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had com Use after free in media in Google Chrome prior to 83.0.4103.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2023-29007P3HIGHCVSS 7.8v36v37+1 more2023-04-25
CVE-2023-29007 [HIGH] CWE-74 CVE-2023-29007: Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, Git is a revision control system. Prior to versions 2.30.9, 2.31.8, 2.32.7, 2.33.8, 2.34.8, 2.35.8, 2.36.6, 2.37.7, 2.38.5, 2.39.3, and 2.40.1, a specially crafted `.gitmodules` file with submodule URLs that are longer than 1024 characters can used to exploit a bug in `config.c::git_config_copy_or_rename_section_in_file()`. This bug can be used to injec
nvd
Fedoraproject Fedora vulnerabilities | cvebase