Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 52 of 264
CVE-2024-5834P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5834 [HIGH] CWE-94 CVE-2024-5834: Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attack
Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6291P3HIGHCVSS 8.8v39v402024-06-24
CVE-2024-6291 [HIGH] CWE-416 CVE-2024-6291: Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to
Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-29923P3HIGHCVSS 7.5v362021-08-07
CVE-2021-29923 [HIGH] CVE-2021-29923: Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP addre
Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
nvd
CVE-2024-5838P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5838 [HIGH] CWE-843 CVE-2024-5838: Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform ou
Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6293P3HIGHCVSS 8.8v39v402024-06-24
CVE-2024-6293 [HIGH] CWE-416 CVE-2024-6293: Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potenti
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6290P3HIGHCVSS 8.8v39v402024-06-24
CVE-2024-6290 [HIGH] CWE-416 CVE-2024-6290: Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potenti
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-3603P3HIGHCVSS 8.1v33v342021-06-17
CVE-2021-3603 [HIGH] CWE-829 CVE-2021-3603: PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (
PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the default, defined by PHPMailer::$validator), and the global namespace contains a function called php, it will
nvd
CVE-2024-6292P3HIGHCVSS 8.8v39v402024-06-24
CVE-2024-6292 [HIGH] CWE-416 CVE-2024-6292: Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potenti
Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5831P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5831 [HIGH] CWE-416 CVE-2024-5831: Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentia
Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5832P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5832 [HIGH] CWE-416 CVE-2024-5832: Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentia
Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2019-9498P3HIGHCVSS 8.1v28v29+1 more2019-04-17
CVE-2019-9498 [HIGH] CWE-346 CVE-2019-9498: The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing ex
The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or lea
nvd
CVE-2015-8540P3HIGHCVSS 8.8v232016-04-14
CVE-2015-8540 [HIGH] CWE-189 CVE-2015-8540: Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x
Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
nvd
CVE-2022-32250P3HIGHCVSS 7.8v35v362022-06-02
CVE-2022-32250 [HIGH] CWE-416 CVE-2022-32250: net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create
net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
nvd
CVE-2016-5421P3HIGHCVSS 8.1v23v242016-08-10
CVE-2016-5421 [HIGH] CWE-416 CVE-2016-5421: Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection i
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2023-38709P3HIGHCVSS 7.3v38v39+1 more2024-04-04
CVE-2023-38709 [HIGH] CWE-1284 CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content genera
Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses.
This issue affects Apache HTTP Server: through 2.4.58.
nvd
CVE-2015-8869P3CRITICALCVSS 9.1v242016-06-13
CVE-2015-8869 [CRITICAL] CWE-119 CVE-2015-8869: OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to condu
OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
nvd
CVE-2022-24070P3HIGHCVSS 7.5v35v362022-04-12
CVE-2022-24070 [HIGH] CWE-416 CVE-2022-24070: Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorizati
Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.
nvd
CVE-2016-7953P3CRITICALCVSS 9.8v24v252016-12-13
CVE-2016-7953 [CRITICAL] CWE-119 CVE-2016-7953: Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact v
Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
nvd
CVE-2019-17042P3CRITICALCVSS 9.8v30v312019-10-07
CVE-2019-17042 [CRITICAL] CWE-20 CVE-2019-17042: An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflo
An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMs
nvd
CVE-2023-1194P3HIGHCVSS 8.1v372023-11-03
CVE-2023-1194 [HIGH] CWE-416 CVE-2023-1194: An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation o
An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access in
nvd