cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 49 of 264
CVE-2020-15121P3CRITICALCVSS 9.6v31v322020-07-20
CVE-2020-15121 [CRITICAL] CWE-78 CVE-2020-15121: In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injecti In radare2 before version 4.5.0, malformed PDB file names in the PDB server path cause shell injection. To trigger the problem it's required to open the executable in radare2 and run idpd to trigger the download. The shell code will execute, and will create a file called pwned in the current directory.
nvd
CVE-2020-6424P3HIGHCVSS 8.8v30v31+1 more2020-03-23
CVE-2020-6424 [HIGH] CWE-416 CVE-2020-6424: Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potenti Use after free in media in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21223P3CRITICALCVSS 9.6v32v33+1 more2021-04-26
CVE-2021-21223 [CRITICAL] CWE-190 CVE-2021-21223: Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had co Integer overflow in Mojo in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21154P3CRITICALCVSS 9.6v32v332021-02-22
CVE-2021-21154 [CRITICAL] CWE-787 CVE-2021-21154: Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker Heap buffer overflow in Tab Strip in Google Chrome prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21115P3CRITICALCVSS 9.6v32v332021-01-08
CVE-2021-21115 [CRITICAL] CWE-416 CVE-2021-21115: User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker w User after free in safe browsing in Google Chrome prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2022-1587P3CRITICALCVSS 9.1v35v362022-05-16
CVE-2022-1587 [CRITICAL] CWE-125 CVE-2022-1587: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_leng An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.
nvd
CVE-2021-21155P3CRITICALCVSS 9.6v32v332021-02-22
CVE-2021-21155 [CRITICAL] CWE-787 CVE-2021-21155: Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remot Heap buffer overflow in Tab Strip in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21150P3CRITICALCVSS 9.6v32v332021-02-22
CVE-2021-21150 [CRITICAL] CWE-416 CVE-2021-21150: Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote atta Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-8623P3HIGHCVSS 7.5v31v322020-08-21
CVE-2020-8623 [HIGH] CWE-617 CVE-2020-8623: In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.10.5-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker that can reach a vulnerable system with a specially crafted query packet can trigger a crash. To be vulnerable, the system must: * be running BIND that was built with "--enable-native-pkcs11" * be signin
nvd
CVE-2021-21151P3CRITICALCVSS 9.6v32v332021-02-22
CVE-2021-21151 [CRITICAL] CWE-416 CVE-2021-21151: Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to pote Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-21146P3CRITICALCVSS 9.6v32v332021-02-09
CVE-2021-21146 [CRITICAL] CWE-416 CVE-2021-21146: Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who h Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2022-0860P3CRITICALCVSS 9.1v34v35+1 more2022-03-11
CVE-2022-0860 [CRITICAL] CWE-285 CVE-2022-0860: Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2. Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.
nvd
CVE-2021-38002P3CRITICALCVSS 9.6v342021-11-23
CVE-2021-38002 [CRITICAL] CWE-416 CVE-2021-38002: Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-6463P3HIGHCVSS 8.8v31v322020-05-21
CVE-2020-6463 [HIGH] CWE-416 CVE-2020-6463: Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potenti Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6524P3HIGHCVSS 8.8v31v322020-07-22
CVE-2020-6524 [HIGH] CWE-787 CVE-2020-6524: Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to Heap buffer overflow in WebAudio in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-2156P3HIGHCVSS 7.5v382023-05-09
CVE-2023-2156 [HIGH] CWE-617 CVE-2023-2156: A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL prot A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
nvd
CVE-2021-46848P3CRITICALCVSS 9.1v35v36+1 more2022-10-24
CVE-2021-46848 [CRITICAL] CWE-193 CVE-2021-46848: GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simp GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
nvd
CVE-2021-21156P3HIGHCVSS 8.8v32v332021-02-22
CVE-2021-21156 [HIGH] CWE-787 CVE-2021-21156: Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to pote Heap buffer overflow in V8 in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted script.
nvd
CVE-2019-5762P3HIGHCVSS 8.8v29v302019-02-19
CVE-2019-5762 [HIGH] CWE-119 CVE-2019-5762: Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowe Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
nvd
CVE-2019-5756P3HIGHCVSS 8.8v29v302019-02-19
CVE-2019-5756 [HIGH] CWE-416 CVE-2019-5756: Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowe Inappropriate memory management when caching in PDFium in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file.
nvd
Fedoraproject Fedora vulnerabilities | cvebase