cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 55 of 264
CVE-2015-8779P3CRITICALCVSS 9.8v232016-04-19
CVE-2015-8779 [CRITICAL] CWE-119 CVE-2015-8779: Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before Stack-based buffer overflow in the catopen function in the GNU C Library (aka glibc or libc6) before 2.23 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long catalog name.
nvd
CVE-2019-12854P3HIGHCVSS 7.5v292019-08-15
CVE-2019-12854 [HIGH] CVE-2019-12854: Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memor Due to incorrect string termination, Squid cachemgr.cgi 4.0 through 4.7 may access unallocated memory. On systems with memory access protections, this can cause the CGI process to terminate unexpectedly, resulting in a denial of service for all clients using it.
nvd
CVE-2022-2010P3CRITICALCVSS 9.3v372022-07-28
CVE-2022-2010 [CRITICAL] CWE-125 CVE-2022-2010: Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2019-16276P3HIGHCVSS 7.5v29v30+1 more2019-09-30
CVE-2019-16276 [HIGH] CWE-444 CVE-2019-16276: Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling. Go before 1.12.10 and 1.13.x before 1.13.1 allow HTTP Request Smuggling.
nvd
CVE-2018-14647P3HIGHCVSS 7.5v302018-09-25
CVE-2018-14647 [HIGH] CWE-335 CVE-2018-14647: Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. Thi Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in P
nvd
CVE-2020-6542P3HIGHCVSS 8.8v332020-09-21
CVE-2020-6542 [HIGH] CWE-416 CVE-2020-6542: Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti Use after free in ANGLE in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6533P3HIGHCVSS 8.8v31v322020-07-22
CVE-2020-6533 [HIGH] CWE-787 CVE-2020-6533: Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21160P3HIGHCVSS 8.8v32v33+1 more2021-03-09
CVE-2021-21160 [HIGH] CWE-787 CVE-2021-21160: Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to Heap buffer overflow in WebAudio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6430P3HIGHCVSS 8.8v30v31+1 more2020-04-13
CVE-2020-6430 [HIGH] CWE-843 CVE-2020-6430: Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially Type Confusion in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-44648P3HIGHCVSS 8.8v34v352022-01-12
CVE-2021-44648 [HIGH] CWE-787 CVE-2021-44648: GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.
nvd
CVE-2020-15960P3HIGHCVSS 8.8v31v32+1 more2020-09-21
CVE-2020-15960 [HIGH] CWE-787 CVE-2020-15960: Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to Heap buffer overflow in storage in Google Chrome prior to 85.0.4183.121 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2022-2853P3HIGHCVSS 8.8v372022-09-26
CVE-2022-2853 [HIGH] CWE-787 CVE-2022-2853: Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remo Heap buffer overflow in Downloads in Google Chrome on Android prior to 104.0.5112.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6443P3HIGHCVSS 8.8v30v31+1 more2020-04-13
CVE-2020-6443 [HIGH] CWE-345 CVE-2020-6443: Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a rem Insufficient data validation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to execute arbitrary code via a crafted HTML page.
nvd
CVE-2020-28243P3HIGHCVSS 7.8v32v33+1 more2021-02-27
CVE-2020-28243 [HIGH] CWE-77 CVE-2020-28243: An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to An issue was discovered in SaltStack Salt before 3002.5. The minion's restartcheck is vulnerable to command injection via a crafted process name. This allows for a local privilege escalation by any user able to create a files on the minion in a non-blacklisted directory.
nvd
CVE-2020-35654P3HIGHCVSS 8.8v32v332021-01-12
CVE-2020-35654 [HIGH] CWE-787 CVE-2020-35654: In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr file In Pillow before 8.1.0, TiffDecode has a heap-based buffer overflow when decoding crafted YCbCr files because of certain interpretation conflicts with LibTIFF in RGBA mode.
nvd
CVE-2021-21203P3HIGHCVSS 8.8v32v33+1 more2021-04-26
CVE-2021-21203 [HIGH] CWE-416 CVE-2021-21203: Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentia Use after free in Blink in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30556P3HIGHCVSS 8.8v33v342021-07-02
CVE-2021-30556 [HIGH] CWE-416 CVE-2021-30556: Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to pote Use after free in WebAudio in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21159P3HIGHCVSS 8.8v32v33+1 more2021-03-09
CVE-2021-21159 [HIGH] CWE-416 CVE-2021-21159: Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37979P3HIGHCVSS 8.8v332021-11-02
CVE-2021-37979 [HIGH] CWE-787 CVE-2021-37979: heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who heap buffer overflow in WebRTC in Google Chrome prior to 94.0.4606.81 allowed a remote attacker who convinced a user to browse to a malicious website to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16005P3HIGHCVSS 8.8v32v332020-11-03
CVE-2020-16005 [HIGH] CWE-755 CVE-2020-16005: Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote at Insufficient policy enforcement in ANGLE in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
Fedoraproject Fedora vulnerabilities | cvebase