Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 56 of 264
CVE-2020-16006P3HIGHCVSS 8.8v32v332020-11-03
CVE-2020-16006 [HIGH] CWE-787 CVE-2020-16006: Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16002P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-16002 [HIGH] CWE-416 CVE-2020-16002: Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potent
Use after free in PDFium in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2021-21230P3HIGHCVSS 8.8v32v33+1 more2021-04-30
CVE-2021-21230 [HIGH] CWE-843 CVE-2021-21230: Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially
Type confusion in V8 in Google Chrome prior to 90.0.4430.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-25718P3HIGHCVSS 8.8v352022-02-18
CVE-2020-25718 [HIGH] CWE-862 CVE-2020-25718: A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an R
A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.
nvd
CVE-2022-0100P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0100 [HIGH] CWE-787 CVE-2022-0100: Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote at
Heap buffer overflow in Media streams API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2016-5766P3HIGHCVSS 8.8v23v24+1 more2016-08-07
CVE-2016-5766 [HIGH] CWE-190 CVE-2016-5766: Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) be
Integer overflow in the _gd2GetHeader function in gd_gd2.c in the GD Graphics Library (aka libgd) before 2.2.3, as used in PHP before 5.5.37, 5.6.x before 5.6.23, and 7.x before 7.0.8, allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via crafted chunk dimens
nvd
CVE-2020-15991P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15991 [HIGH] CWE-416 CVE-2020-15991: Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker
Use after free in password manager in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2022-0101P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0101 [HIGH] CWE-787 CVE-2022-0101: Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker w
Heap buffer overflow in Bookmarks in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via specific user gesture.
nvd
CVE-2023-39928P3HIGHCVSS 8.8v372023-10-06
CVE-2023-39928 [HIGH] CWE-416 CVE-2023-39928: A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A special
A use-after-free vulnerability exists in the MediaRecorder API of Webkit WebKitGTK 2.40.5. A specially crafted web page can abuse this vulnerability to cause memory corruption and potentially arbitrary code execution. A user would need to to visit a malicious webpage to trigger this vulnerability.
nvd
CVE-2021-31607P3HIGHCVSS 7.8v33v34+1 more2021-04-23
CVE-2021-31607 [HIGH] CWE-78 CVE-2021-31607: In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper mod
In SaltStack Salt 2016.9 through 3002.6, a command injection vulnerability exists in the snapper module that allows for local privilege escalation on a minion. The attack requires that a file is created with a pathname that is backed up by snapper, and that the master calls the snapper.diff function (which executes popen unsafely).
nvd
CVE-2021-21214P3HIGHCVSS 8.8v32v33+1 more2021-04-26
CVE-2021-21214 [HIGH] CWE-416 CVE-2021-21214: Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to po
Use after free in Network API in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2022-42719P3HIGHCVSS 8.8v35v36+1 more2022-10-13
CVE-2022-42719 [HIGH] CWE-416 CVE-2022-42719: A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 th
A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.
nvd
CVE-2023-5849P3HIGHCVSS 8.8v37v38+1 more2023-11-01
CVE-2023-5849 [HIGH] CWE-190 CVE-2023-5849: Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potent
Integer overflow in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2019-14844P3HIGHCVSS 7.5v29v30+1 more2019-09-26
CVE-2019-14844 [HIGH] CWE-628 CVE-2019-14844: A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos
A flaw was found in, Fedora versions of krb5 from 1.16.1 to, including 1.17.x, in the way a Kerberos client could crash the KDC by sending one of the RFC 4556 "enctypes". A remote unauthenticated user could use this flaw to crash the KDC.
nvd
CVE-2023-5856P3HIGHCVSS 8.8v37v38+1 more2023-11-01
CVE-2023-5856 [HIGH] CWE-416 CVE-2023-5856: Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who
Use after free in Side Panel in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2019-16884P3HIGHCVSS 7.5v29v30+1 more2019-09-25
CVE-2019-16884 [HIGH] CWE-863 CVE-2019-16884: runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor res
runc through 1.0.0-rc8, as used in Docker through 19.03.2-ce and other products, allows AppArmor restriction bypass because libcontainer/rootfs_linux.go incorrectly checks mount targets, and thus a malicious Docker image can mount over a /proc directory.
nvd
CVE-2019-16789P3HIGHCVSS 8.2v30v312019-12-26
CVE-2019-16789 [HIGH] CWE-444 CVE-2019-16789: In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid reques
In Waitress through version 1.4.0, if a proxy server is used in front of waitress, an invalid request may be sent by an attacker that bypasses the front-end and is parsed differently by waitress leading to a potential for HTTP request smuggling. Specially crafted requests containing special whitespace characters in the Transfer-Encoding header would g
nvd
CVE-2023-6347P3HIGHCVSS 8.8v38v392023-11-29
CVE-2023-6347 [HIGH] CWE-416 CVE-2023-6347: Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potenti
Use after free in Mojo in Google Chrome prior to 119.0.6045.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-0222P3HIGHCVSS 8.8v38v392024-01-04
CVE-2024-0222 [HIGH] CWE-416 CVE-2024-0222: Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had c
Use after free in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6508P3HIGHCVSS 8.8v38v392023-12-06
CVE-2023-6508 [HIGH] CWE-416 CVE-2023-6508: Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to
Use after free in Media Stream in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd