Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 50 of 264
CVE-2021-41182P3MEDIUMCVSS 6.1v33v34+2 more2021-10-26
CVE-2021-41182 [MEDIUM] CWE-79 CVE-2021-41182: jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the valu
jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. Any string value passed to the `altField` option is now treated as a CSS selector. A workaround is to not acc
nvd
CVE-2020-15972P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15972 [HIGH] CWE-416 CVE-2020-15972: Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentia
Use after free in audio in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30604P3HIGHCVSS 8.8v33v34+1 more2021-08-26
CVE-2021-30604 [HIGH] CWE-416 CVE-2021-30604: Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potenti
Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30591P3HIGHCVSS 8.8v33v34+1 more2021-08-26
CVE-2021-30591 [HIGH] CWE-416 CVE-2021-30591: Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker
Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21772P3HIGHCVSS 8.1v32v33+1 more2021-03-10
CVE-2021-21772 [HIGH] CWE-416 CVE-2021-21772: A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3
A use-after-free vulnerability exists in the NMR::COpcPackageReader::releaseZIP() functionality of 3MF Consortium lib3mf 2.0.0. A specially crafted 3MF file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2020-26116P3HIGHCVSS 7.2v31v32+1 more2020-09-27
CVE-2020-26116 [HIGH] CWE-74 CVE-2020-26116: http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3
http.client in Python 3.x before 3.5.10, 3.6.x before 3.6.12, 3.7.x before 3.7.9, and 3.8.x before 3.8.5 allows CRLF injection if the attacker controls the HTTP request method, as demonstrated by inserting CR and LF control characters in the first argument of HTTPConnection.request.
nvd
CVE-2021-4057P3HIGHCVSS 8.8v342021-12-23
CVE-2021-4057 [HIGH] CWE-416 CVE-2021-4057: Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had
Use after free in file API in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30513P3HIGHCVSS 8.8v33v342021-06-04
CVE-2021-30513 [HIGH] CWE-843 CVE-2021-30513: Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentiall
Type confusion in V8 in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30601P3HIGHCVSS 8.8v33v34+1 more2021-08-26
CVE-2021-30601 [HIGH] CWE-416 CVE-2021-30601: Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who con
Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2009-0385P3CRITICALCVSS 9.3v9v102009-02-02
CVE-2009-0385 [CRITICAL] CVE-2009-0385: Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before re
Integer signedness error in the fourxm_read_header function in libavformat/4xm.c in FFmpeg before revision 16846 allows remote attackers to execute arbitrary code via a malformed 4X movie file with a large current_track value, which triggers a NULL pointer dereference.
nvd
CVE-2020-15962P3HIGHCVSS 8.8v31v32+1 more2020-09-21
CVE-2020-15962 [HIGH] CVE-2020-15962: Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote at
Insufficient policy validation in serial in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2019-18422P3HIGHCVSS 8.8v29v30+1 more2019-10-31
CVE-2019-18422 [HIGH] CWE-732 CVE-2019-18422: An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of servi
An issue was discovered in Xen through 4.12.x allowing ARM guest OS users to cause a denial of service or gain privileges by leveraging the erroneous enabling of interrupts. Interrupts are unconditionally unmasked in exception handlers. When an exception occurs on an ARM system which is handled without changing processor level, some interrupts are unc
nvd
CVE-2021-30578P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30578 [HIGH] CWE-908 CVE-2021-30578: Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perf
Uninitialized use in Media in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2021-30566P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30566 [HIGH] CWE-787 CVE-2021-30566: Stack buffer overflow in Printing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker
Stack buffer overflow in Printing in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit stack corruption via a crafted HTML page.
nvd
CVE-2020-15969P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15969 [HIGH] CWE-416 CVE-2020-15969: Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potenti
Use after free in WebRTC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-42072P3HIGHCVSS 8.8v34v352021-11-08
CVE-2021-42072 [HIGH] CWE-287 CVE-2021-42072: An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side impleme
An issue was discovered in Barrier before 2.4.0. The barriers component (aka the server-side implementation of Barrier) does not sufficiently verify the identify of connecting clients. Clients can thus exploit weaknesses in the provided protocol to cause denial-of-service or stage further attacks that could lead to information leaks or integrity corru
nvd
CVE-2021-30575P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30575 [HIGH] CWE-787 CVE-2021-30575: Out of bounds write in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker wh
Out of bounds write in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6537P3HIGHCVSS 8.8v332020-09-21
CVE-2020-6537 [HIGH] CWE-843 CVE-2020-6537: Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute ar
Type confusion in V8 in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2023-5218P3HIGHCVSS 8.8v37v382023-10-11
CVE-2023-5218 [HIGH] CWE-416 CVE-2023-5218: Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker t
Use after free in Site Isolation in Google Chrome prior to 118.0.5993.70 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
nvd
CVE-2023-4073P3HIGHCVSS 8.8v382023-08-03
CVE-2023-4073 [HIGH] CWE-119 CVE-2023-4073: Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790.170 allowed a remot
Out of bounds memory access in ANGLE in Google Chrome on Mac prior to 115.0.5790.170 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd