Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 57 of 264
CVE-2022-37966P3HIGHCVSS 8.1v36v372022-11-09
CVE-2022-37966 [HIGH] CVE-2022-37966: Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability
nvd
CVE-2023-6348P3HIGHCVSS 8.8v392023-11-29
CVE-2023-6348 [HIGH] CWE-843 CVE-2023-6348: Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who
Type Confusion in Spellcheck in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-5186P3HIGHCVSS 8.8v37v38+1 more2023-09-28
CVE-2023-5186 [HIGH] CWE-416 CVE-2023-5186: Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who c
Use after free in Passwords in Google Chrome prior to 117.0.5938.132 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: High)
nvd
CVE-2023-4429P3HIGHCVSS 8.8v37v38+1 more2023-08-23
CVE-2023-4429 [HIGH] CWE-416 CVE-2023-4429: Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to poten
Use after free in Loader in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-3216P3HIGHCVSS 8.8v382023-06-13
CVE-2023-3216 [HIGH] CWE-843 CVE-2023-3216: Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potential
Type confusion in V8 in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-1059P3HIGHCVSS 8.8v38v392024-01-30
CVE-2024-1059 [HIGH] CWE-416 CVE-2024-1059: Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker
Use after free in Peer Connection in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-1077P3HIGHCVSS 8.8v38v392024-01-30
CVE-2024-1077 [HIGH] CWE-416 CVE-2024-1077: Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to pote
Use after free in Network in Google Chrome prior to 121.0.6167.139 allowed a remote attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
nvd
CVE-2024-5830P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5830 [HIGH] CWE-843 CVE-2024-5830: Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an
Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4572P3HIGHCVSS 8.8v37v38+1 more2023-08-29
CVE-2023-4572 [HIGH] CWE-416 CVE-2023-4572: Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to
Use after free in MediaStream in Google Chrome prior to 116.0.5845.140 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-1938P3HIGHCVSS 8.8v38v39+1 more2024-02-29
CVE-2024-1938 [HIGH] CWE-843 CVE-2024-1938: Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4351P3HIGHCVSS 8.8v382023-08-15
CVE-2023-4351 [HIGH] CWE-416 CVE-2023-4351: Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has
Use after free in Network in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has elicited a browser shutdown to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4349P3HIGHCVSS 8.8v382023-08-15
CVE-2023-4349 [HIGH] CWE-416 CVE-2023-4349: Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote a
Use after free in Device Trust Connectors in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4358P3HIGHCVSS 8.8v382023-08-15
CVE-2023-4358 [HIGH] CWE-416 CVE-2023-4358: Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potential
Use after free in DNS in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2024-1673P3HIGHCVSS 8.8v38v392024-02-21
CVE-2024-1673 [HIGH] CWE-416 CVE-2024-1673: Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker wh
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2024-5493P3HIGHCVSS 8.8v39v402024-05-30
CVE-2024-5493 [HIGH] CWE-787 CVE-2024-5493: Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to
Heap buffer overflow in WebRTC in Google Chrome prior to 125.0.6422.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-34402P3HIGHCVSS 8.6v38v39+1 more2024-05-03
CVE-2024-34402 [HIGH] CWE-190 CVE-2024-34402: An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
nvd
CVE-2024-5160P3HIGHCVSS 8.8v39v402024-05-22
CVE-2024-5160 [HIGH] CWE-787 CVE-2024-5160: Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to pe
Heap buffer overflow in Dawn in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2019-13224P3CRITICALCVSS 9.8v29v302019-07-10
CVE-2019-13224 [CRITICAL] CWE-416 CVE-2019-13224: A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially
A use-after-free in onig_new_deluxe() in regext.c in Oniguruma 6.9.2 allows attackers to potentially cause information disclosure, denial of service, or possibly code execution by providing a crafted regular expression. The attacker provides a pair of a regex pattern and a string, with a multi-byte encoding that gets handled by onig_new_deluxe().
nvd
CVE-2024-5837P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5837 [HIGH] CWE-843 CVE-2024-5837: Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2024-5833P3HIGHCVSS 8.8v39v402024-06-11
CVE-2024-5833 [HIGH] CWE-843 CVE-2024-5833: Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
nvd