cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 52 of 264
CVE-2024-5834P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5834 [HIGH] CWE-94 CVE-2024-5834: Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attack Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6291P3HIGHCVSS 8.8v39v402024-06-24
CVE-2024-6291 [HIGH] CWE-416 CVE-2024-6291: Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-29923P3HIGHCVSS 7.5v362021-08-07
CVE-2021-29923 [HIGH] CVE-2021-29923: Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP addre Go before 1.17 does not properly consider extraneous zero characters at the beginning of an IP address octet, which (in some situations) allows attackers to bypass access control that is based on IP addresses, because of unexpected octal interpretation. This affects net.ParseIP and net.ParseCIDR.
nvd
CVE-2024-5838P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5838 [HIGH] CWE-843 CVE-2024-5838: Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform ou Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6293P3HIGHCVSS 8.8v39v402024-06-24
CVE-2024-6293 [HIGH] CWE-416 CVE-2024-6293: Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-6290P3HIGHCVSS 8.8v39v402024-06-24
CVE-2024-6290 [HIGH] CWE-416 CVE-2024-6290: Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-3603P3HIGHCVSS 8.1v33v342021-06-17
CVE-2021-3603 [HIGH] CWE-829 CVE-2021-3603: PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called ( PHPMailer 6.4.1 and earlier contain a vulnerability that can result in untrusted code being called (if such code is injected into the host project's scope by other means). If the $patternselect parameter to validateAddress() is set to 'php' (the default, defined by PHPMailer::$validator), and the global namespace contains a function called php, it will
nvd
CVE-2024-6292P3HIGHCVSS 8.8v39v402024-06-24
CVE-2024-6292 [HIGH] CWE-416 CVE-2024-6292: Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potenti Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5831P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5831 [HIGH] CWE-416 CVE-2024-5831: Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentia Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5832P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5832 [HIGH] CWE-416 CVE-2024-5832: Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentia Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2019-9498P3HIGHCVSS 8.1v28v29+1 more2019-04-17
CVE-2019-9498 [HIGH] CWE-346 CVE-2019-9498: The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing ex The implementations of EAP-PWD in hostapd EAP Server, when built against a crypto library missing explicit validation on imported elements, do not validate the scalar and element values in EAP-pwd-Commit. An attacker may be able to use invalid scalar/element values to complete authentication, gaining session key and network access without needing or lea
nvd
CVE-2015-8540P3HIGHCVSS 8.8v232016-04-14
CVE-2015-8540 [HIGH] CWE-189 CVE-2015-8540: Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x Integer underflow in the png_check_keyword function in pngwutil.c in libpng 0.90 through 0.99, 1.0.x before 1.0.66, 1.1.x and 1.2.x before 1.2.56, 1.3.x and 1.4.x before 1.4.19, and 1.5.x before 1.5.26 allows remote attackers to have unspecified impact via a space character as a keyword in a PNG image, which triggers an out-of-bounds read.
nvd
CVE-2022-32250P3HIGHCVSS 7.8v35v362022-06-02
CVE-2022-32250 [HIGH] CWE-416 CVE-2022-32250: net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free.
nvd
CVE-2016-5421P3HIGHCVSS 8.1v23v242016-08-10
CVE-2016-5421 [HIGH] CWE-416 CVE-2016-5421: Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection i Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
nvd
CVE-2023-38709P3HIGHCVSS 7.3v38v39+1 more2024-04-04
CVE-2023-38709 [HIGH] CWE-1284 CVE-2023-38709: Faulty input validation in the core of Apache allows malicious or exploitable backend/content genera Faulty input validation in the core of Apache allows malicious or exploitable backend/content generators to split HTTP responses. This issue affects Apache HTTP Server: through 2.4.58.
nvd
CVE-2015-8869P3CRITICALCVSS 9.1v242016-06-13
CVE-2015-8869 [CRITICAL] CWE-119 CVE-2015-8869: OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to condu OCaml before 4.03.0 does not properly handle sign extensions, which allows remote attackers to conduct buffer overflow attacks or obtain sensitive information as demonstrated by a long string to the String.copy function.
nvd
CVE-2022-24070P3HIGHCVSS 7.5v35v362022-04-12
CVE-2022-24070 [HIGH] CWE-416 CVE-2022-24070: Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorizati Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do not use mod_dav_svn are not affected.
nvd
CVE-2016-7953P3CRITICALCVSS 9.8v24v252016-12-13
CVE-2016-7953 [CRITICAL] CWE-119 CVE-2016-7953: Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact v Buffer underflow in X.org libXvMC before 1.0.10 allows remote X servers to have unspecified impact via an empty string.
nvd
CVE-2019-17042P3CRITICALCVSS 9.8v30v312019-10-07
CVE-2019-17042 [CRITICAL] CWE-20 CVE-2019-17042: An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflo An issue was discovered in Rsyslog v8.1908.0. contrib/pmcisconames/pmcisconames.c has a heap overflow in the parser for Cisco log messages. The parser tries to locate a log message delimiter (in this case, a space or a colon), but fails to account for strings that do not satisfy this constraint. If the string does not match, then the variable lenMs
nvd
CVE-2023-1194P3HIGHCVSS 8.1v372023-11-03
CVE-2023-1194 [HIGH] CWE-416 CVE-2023-1194: An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation o An out-of-bounds (OOB) memory read flaw was found in parse_lease_state in the KSMBD implementation of the in-kernel samba server and CIFS in the Linux kernel. When an attacker sends the CREATE command with a malformed payload to KSMBD, due to a missing check of `NameOffset` in the `parse_lease_state()` function, the `create_context` object can access in
nvd
Fedoraproject Fedora vulnerabilities | cvebase