Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 62 of 264
CVE-2020-8793P4MEDIUMCVSS 4.7PoCv322020-02-25
CVE-2020-8793 [MEDIUM] CWE-367 CVE-2020-8793: OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions
OpenSMTPD before 6.6.4 allows local users to read arbitrary files (e.g., on some Linux distributions) because of a combination of an untrusted search path in makemap.c and race conditions in the offline functionality in smtpd.c.
nvd
CVE-2020-6576P3HIGHCVSS 8.8v31v332020-09-21
CVE-2020-6576 [HIGH] CWE-416 CVE-2020-6576: Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker
Use after free in offscreen canvas in Google Chrome prior to 85.0.4183.102 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21188P3HIGHCVSS 8.8v32v33+1 more2021-03-09
CVE-2021-21188 [HIGH] CWE-416 CVE-2021-21188: Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentia
Use after free in Blink in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21180P3HIGHCVSS 8.8v32v33+1 more2021-03-09
CVE-2021-21180 [HIGH] CWE-416 CVE-2021-21180: Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to pot
Use after free in tab search in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15979P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15979 [HIGH] CWE-787 CVE-2020-15979: Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker
Inappropriate implementation in V8 in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30574P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30574 [HIGH] CWE-416 CVE-2021-30574: Use after free in protocol handling in Google Chrome prior to 92.0.4515.107 allowed a remote attacke
Use after free in protocol handling in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16000P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-16000 [HIGH] CWE-787 CVE-2020-16000: Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attac
Inappropriate implementation in Blink in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30579P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30579 [HIGH] CWE-416 CVE-2021-30579: Use after free in UI framework in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to
Use after free in UI framework in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30572P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30572 [HIGH] CWE-416 CVE-2021-30572: Use after free in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to pote
Use after free in Autofill in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16001P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-16001 [HIGH] CWE-416 CVE-2020-16001: Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potenti
Use after free in media in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21204P3HIGHCVSS 8.8v32v33+1 more2021-04-26
CVE-2021-21204 [HIGH] CWE-416 CVE-2021-21204: Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to
Use after free in Blink in Google Chrome on OS X prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15968P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15968 [HIGH] CWE-416 CVE-2020-15968: Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentia
Use after free in Blink in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21161P3HIGHCVSS 8.8v32v33+1 more2021-03-09
CVE-2021-21161 [HIGH] CWE-787 CVE-2021-21161: Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to
Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21213P3HIGHCVSS 8.8v32v33+1 more2021-04-26
CVE-2021-21213 [HIGH] CWE-416 CVE-2021-21213: Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potent
Use after free in WebMIDI in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30568P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30568 [HIGH] CWE-787 CVE-2021-30568: Heap buffer overflow in WebGL in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to p
Heap buffer overflow in WebGL in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0115P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0115 [HIGH] CWE-908 CVE-2022-0115: Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to po
Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2021-21149P3HIGHCVSS 8.8v32v332021-02-22
CVE-2021-21149 [HIGH] CWE-787 CVE-2021-21149: Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a re
Stack buffer overflow in Data Transfer in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2022-22728P3HIGHCVSS 7.5v35v36+1 more2022-08-25
CVE-2022-22728 [HIGH] CWE-120 CVE-2022-22728: A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing
A flaw in Apache libapreq2 versions 2.16 and earlier could cause a buffer overflow while processing multipart form uploads. A remote attacker could send a request causing a process crash which could lead to a denial of service attack.
nvd
CVE-2022-44638P3HIGHCVSS 8.8v35v36+1 more2022-11-03
CVE-2022-44638 [HIGH] CWE-190 CVE-2022-44638: In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflo
In libpixman in Pixman before 0.42.2, there is an out-of-bounds write (aka heap-based buffer overflow) in rasterize_edges_8 due to an integer overflow in pixman_sample_floor_y.
nvd
CVE-2022-2156P3HIGHCVSS 8.8v35v362022-07-28
CVE-2022-2156 [HIGH] CWE-416 CVE-2022-2156: Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentia
Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd