cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 61 of 264
CVE-2020-6428P3HIGHCVSS 8.8v30v31+1 more2020-03-23
CVE-2020-6428 [HIGH] CWE-787 CVE-2020-6428: Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potenti Use after free in audio in Google Chrome prior to 80.0.3987.149 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-23169P3HIGHCVSS 8.8v33v342021-06-08
CVE-2021-23169 [HIGH] CWE-787 CVE-2021-23169: A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3 A heap-buffer overflow was found in the copyIntoFrameBuffer function of OpenEXR in versions before 3.0.1. An attacker could use this flaw to execute arbitrary code with the permissions of the user running the application compiled against OpenEXR.
nvd
CVE-2020-6382P3HIGHCVSS 8.8v30v312020-02-11
CVE-2020-6382 [HIGH] CWE-843 CVE-2020-6382: Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to pot Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-41674P3HIGHCVSS 8.1v35v36+1 more2022-10-14
CVE-2022-41674 [HIGH] CWE-787 CVE-2022-41674: An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames cou An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
nvd
CVE-2021-30602P3HIGHCVSS 8.8v33v34+1 more2021-08-26
CVE-2021-30602 [HIGH] CWE-416 CVE-2021-30602: Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30592P3HIGHCVSS 8.8v33v34+1 more2021-08-26
CVE-2021-30592 [HIGH] CWE-787 CVE-2021-30592: Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who co Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2020-6416P3HIGHCVSS 8.8v30v312020-02-11
CVE-2020-6416 [HIGH] CWE-20 CVE-2020-6416: Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote atta Insufficient data validation in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-5831P3HIGHCVSS 8.8v29v302019-06-27
CVE-2019-5831 [HIGH] CWE-787 CVE-2019-5831: Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to pot Object lifecycle issue in V8 in Google Chrome prior to 75.0.3770.80 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13730P3HIGHCVSS 8.8v30v312019-12-10
CVE-2019-13730 [HIGH] CWE-787 CVE-2019-13730: Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to pot Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2012-0037P3MEDIUMCVSS 6.5v16v172012-06-17
CVE-2012-0037 [MEDIUM] CWE-611 CVE-2012-0037: Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice bef Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
nvd
CVE-2020-6534P3HIGHCVSS 8.8v31v322020-07-22
CVE-2020-6534 [HIGH] CWE-787 CVE-2020-6534: Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to p Heap buffer overflow in WebRTC in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30565P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30565 [HIGH] CWE-787 CVE-2021-30565: Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allo Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2019-11044P3HIGHCVSS 7.5v30v312019-12-23
CVE-2019-11044 [HIGH] CWE-170 CVE-2019-11044: In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function acc In PHP versions 7.2.x below 7.2.26, 7.3.x below 7.3.13 and 7.4.0 on Windows, PHP link() function accepts filenames with embedded \0 byte and treats them as terminating at that byte. This could lead to security vulnerabilities, e.g. in applications checking paths that the code is allowed to access.
nvd
CVE-2020-6525P3HIGHCVSS 8.8v31v322020-07-22
CVE-2020-6525 [HIGH] CWE-787 CVE-2020-6525: Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to pot Heap buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6406P3HIGHCVSS 8.8v30v312020-02-11
CVE-2020-6406 [HIGH] CWE-416 CVE-2020-6406: Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentia Use after free in audio in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-9232P3HIGHCVSS 7.5v30v312019-09-27
CVE-2019-9232 [HIGH] CWE-125 CVE-2019-9232: In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to In libvpx, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-122675483
nvd
CVE-2020-6447P3HIGHCVSS 8.8v30v31+1 more2020-04-13
CVE-2020-6447 [HIGH] CWE-125 CVE-2020-6447: Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a rem Inappropriate implementation in developer tools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker who had convinced the user to use devtools to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6452P3HIGHCVSS 8.8v30v312020-04-13
CVE-2020-6452 [HIGH] CWE-787 CVE-2020-6452: Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to p Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-3327P3HIGHCVSS 7.5v30v31+1 more2020-05-13
CVE-2020-3327 [HIGH] CWE-20 CVE-2020-3327: A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102 A vulnerability in the ARJ archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a heap buffer overflow read. An attacker could exploit this vulnerability by sending a crafted ARJ file to an affec
nvd
CVE-2020-6439P3HIGHCVSS 8.8v30v31+1 more2020-04-13
CVE-2020-6439 [HIGH] CWE-276 CVE-2020-6439: Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remo Insufficient policy enforcement in navigations in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to bypass security UI via a crafted HTML page.
nvd
Fedoraproject Fedora vulnerabilities | cvebase