cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 63 of 264
CVE-2020-15967P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15967 [HIGH] CWE-416 CVE-2020-15967: Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to poten Use after free in payments in Google Chrome prior to 86.0.4240.75 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-4061P3HIGHCVSS 8.8v342021-12-23
CVE-2021-4061 [HIGH] CWE-843 CVE-2021-4061: Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially Type confusion in V8 in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-4056P3HIGHCVSS 8.8v342021-12-23
CVE-2021-4056 [HIGH] CWE-843 CVE-2021-4056: Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potenti Type confusion in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-32679P3HIGHCVSS 8.8v33v342021-07-12
CVE-2021-32679 [HIGH] CWE-116 CVE-2021-32679: Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20. Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized into a `DownloadResponse`, this could be used to trick users into downloading malicious files with a b
nvd
CVE-2022-0096P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0096 [HIGH] CWE-416 CVE-2022-0096: Use after free in Storage in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potent Use after free in Storage in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-41159P3HIGHCVSS 8.8v352021-10-21
CVE-2021-41159 [HIGH] CWE-787 CVE-2021-41159: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (`/gt:rpc`) fail to validate input data. A malicious gateway might allow client memory to be written out of bounds. This issue has been resolved in version 2.4.1. If you are unab
nvd
CVE-2021-30528P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30528 [HIGH] CWE-416 CVE-2021-30528: Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remo Use after free in WebAuthentication in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker who had compromised the renderer process of a user who had saved a credit card in their Google account to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-13692P3HIGHCVSS 7.7v322020-06-04
CVE-2020-13692 [HIGH] CWE-611 CVE-2020-13692: PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE. PostgreSQL JDBC Driver (aka PgJDBC) before 42.2.13 allows XXE.
nvd
CVE-2023-1534P3HIGHCVSS 8.8v36v37+1 more2023-03-21
CVE-2023-1534 [HIGH] CWE-125 CVE-2023-1534: Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who h Out of bounds read in ANGLE in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-28660P3HIGHCVSS 8.8v332021-03-17
CVE-2021-28660 [HIGH] CWE-787 CVE-2021-28660: rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 rtw_wx_set_scan in drivers/staging/rtl8188eu/os_dep/ioctl_linux.c in the Linux kernel through 5.11.6 allows writing beyond the end of the ->ssid[] array. NOTE: from the perspective of kernel.org releases, CVE IDs are not normally used for drivers/staging/* (unfinished work); however, system integrators may have situations in which a drivers/staging is
nvd
CVE-2022-0102P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0102 [HIGH] CWE-843 CVE-2022-0102: Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially Type confusion in V8 in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37974P3HIGHCVSS 8.8v33v34+1 more2021-10-08
CVE-2021-37974 [HIGH] CWE-416 CVE-2021-37974: Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who Use after free in Safebrowsing in Google Chrome prior to 94.0.4606.71 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21153P3HIGHCVSS 8.8v32v332021-02-22
CVE-2021-21153 [HIGH] CWE-787 CVE-2021-21153: Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remo Stack buffer overflow in GPU Process in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2019-14811P3HIGHCVSS 7.8v29v30+1 more2019-09-03
CVE-2019-14811 [HIGH] CWE-648 CVE-2019-14811: A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure wher A flaw was found in, ghostscript versions prior to 9.50, in the .pdf_hook_DSC_Creator procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
nvd
CVE-2022-2162P3HIGHCVSS 8.8v35v362022-07-28
CVE-2022-2162 [HIGH] CVE-2022-2162: Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.5 Insufficient policy enforcement in File System API in Google Chrome on Windows prior to 103.0.5060.53 allowed a remote attacker to bypass file system access via a crafted HTML page.
nvd
CVE-2021-30512P3HIGHCVSS 8.8v33v342021-06-04
CVE-2021-30512 [HIGH] CWE-416 CVE-2021-30512: Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker wh Use after free in Notifications in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37962P3HIGHCVSS 8.8v33v352021-10-08
CVE-2021-37962 [HIGH] CWE-416 CVE-2021-37962: Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attack Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30530P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30530 [HIGH] CWE-119 CVE-2021-30530: Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote atta Out of bounds memory access in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2023-5854P3HIGHCVSS 8.8v37v38+1 more2023-11-01
CVE-2023-5854 [HIGH] CWE-416 CVE-2023-5854: Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who co Use after free in Profiles in Google Chrome prior to 119.0.6045.105 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
nvd
CVE-2023-2137P3HIGHCVSS 8.8v36v37+1 more2023-04-19
CVE-2023-2137 [HIGH] CWE-787 CVE-2023-2137: Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to Heap buffer overflow in sqlite in Google Chrome prior to 112.0.5615.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
Fedoraproject Fedora vulnerabilities | cvebase