cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 51 of 264
CVE-2024-3832P3HIGHCVSS 8.8v38v39+1 more2024-04-17
CVE-2024-3832 [HIGH] CWE-119 CVE-2024-3832: Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potenti Object corruption in V8 in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6350P3HIGHCVSS 8.8v38v392023-11-29
CVE-2023-6350 [HIGH] CWE-416 CVE-2023-6350: Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to pote Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
nvd
CVE-2024-4368P3HIGHCVSS 8.8v38v39+1 more2024-05-01
CVE-2024-4368 [HIGH] CWE-416 CVE-2024-4368: Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-4907P3HIGHCVSS 8.8v37v382023-07-29
CVE-2022-4907 [HIGH] CVE-2022-4907: Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to exe Uninitialized Use in FFmpeg in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2019-3859P3CRITICALCVSS 9.1v28v292019-03-21
CVE-2019-3859 [CRITICAL] CWE-125 CVE-2019-3859: An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_requirev functions. A remote attacker who compromises a SSH server may be able to cause a Denial of Service or read data in the client memory.
nvd
CVE-2024-0225P3HIGHCVSS 8.8v38v392024-01-04
CVE-2024-0225 [HIGH] CWE-416 CVE-2024-0225: Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to poten Use after free in WebGPU in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-0224P3HIGHCVSS 8.8v38v392024-01-04
CVE-2024-0224 [HIGH] CWE-416 CVE-2024-0224: Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to pot Use after free in WebAudio in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5997P3HIGHCVSS 8.8v37v38+1 more2023-11-15
CVE-2023-5997 [HIGH] CWE-416 CVE-2023-5997: Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attac Use after free in Garbage Collection in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6346P3HIGHCVSS 8.8v38v392023-11-29
CVE-2023-6346 [HIGH] CWE-416 CVE-2023-6346: Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to pot Use after free in WebAudio in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-1669P3HIGHCVSS 8.8v38v392024-02-21
CVE-2024-1669 [HIGH] CWE-787 CVE-2024-1669: Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attack Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-0518P3HIGHCVSS 8.8v38v392024-01-16
CVE-2024-0518 [HIGH] CWE-843 CVE-2024-0518: Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potential Type confusion in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6351P3HIGHCVSS 8.8v38v392023-11-29
CVE-2023-6351 [HIGH] CWE-416 CVE-2023-6351: Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to pote Use after free in libavif in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted avif file. (Chromium security severity: High)
nvd
CVE-2024-1060P3HIGHCVSS 8.8v38v392024-01-30
CVE-2024-1060 [HIGH] CWE-416 CVE-2024-1060: Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to poten Use after free in Canvas in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2627P3HIGHCVSS 8.8v38v39+1 more2024-03-20
CVE-2024-2627 [HIGH] CWE-416 CVE-2024-2627: Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potent Use after free in Canvas in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2019-14821P3HIGHCVSS 8.8v29v302019-09-19
CVE-2019-14821 [HIGH] CWE-787 CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Li An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process.
nvd
CVE-2024-5497P3HIGHCVSS 8.8v39v402024-05-30
CVE-2024-5497 [HIGH] CWE-787 CVE-2024-5497: Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote Out of bounds memory access in Browser UI in Google Chrome prior to 125.0.6422.141 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-2400P3HIGHCVSS 8.8v38v392024-03-13
CVE-2024-2400 [HIGH] CWE-416 CVE-2024-2400: Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote atta Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-24583P3HIGHCVSS 7.5v31v32+1 more2020-09-01
CVE-2020-24583 [HIGH] CWE-276 CVE-2020-24583: An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when P An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). FILE_UPLOAD_DIRECTORY_PERMISSIONS mode was not applied to intermediate-level directories created in the process of uploading files. It was also not applied to intermediate-level collected static directories when using the collectsta
nvd
CVE-2024-5495P3HIGHCVSS 8.8v39v402024-05-30
CVE-2024-5495 [HIGH] CWE-416 CVE-2024-5495: Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5494P3HIGHCVSS 8.8v39v402024-05-30
CVE-2024-5494 [HIGH] CWE-416 CVE-2024-5494: Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Fedoraproject Fedora vulnerabilities | cvebase