cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 67 of 264
CVE-2021-44731P3HIGHCVSS 7.8v34v352022-02-17
CVE-2021-44731 [HIGH] CWE-362 CVE-2021-44731: A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount name A race condition existed in the snapd 2.54.2 snap-confine binary when preparing a private mount namespace for a snap. This could allow a local attacker to gain root privileges by bind-mounting their own contents inside the snap's private mount namespace and causing snap-confine to execute arbitrary code and hence gain privilege escalation. Fixed in sn
nvd
CVE-2011-2726P3HIGHCVSS 7.5v14v15+1 more2019-11-15
CVE-2011-2726 [HIGH] CWE-863 CVE-2011-2726: An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability An access bypass issue was found in Drupal 7.x before version 7.5. If a Drupal site has the ability to attach File upload fields to any entity type in the system or has the ability to point individual File upload fields to the private file directory in comments, and the parent node is denied access, non-privileged users can still download the file attach
nvd
CVE-2021-39926P3HIGHCVSS 7.5v34v352021-11-19
CVE-2021-39926 [HIGH] CWE-120 CVE-2021-39926: Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of serv Buffer overflow in the Bluetooth HCI_ISO dissector in Wireshark 3.4.0 to 3.4.9 allows denial of service via packet injection or crafted capture file
nvd
CVE-2014-8485P3HIGHCVSS 7.5v19v20+1 more2014-12-09
CVE-2014-8485 [HIGH] CWE-94 CVE-2014-8485: The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attac The setup_group function in bfd/elf.c in libbfd in GNU binutils 2.24 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted section group headers in an ELF file.
nvd
CVE-2022-27649P3HIGHCVSS 7.5v34v35+1 more2022-04-04
CVE-2022-27649 [HIGH] CWE-276 CVE-2022-27649: A flaw was found in Podman, where containers were started incorrectly with non-empty default permiss A flaw was found in Podman, where containers were started incorrectly with non-empty default permissions. A vulnerability was found in Moby (Docker Engine), where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate
nvd
CVE-2021-30609P3HIGHCVSS 8.8v352021-09-03
CVE-2021-30609 [HIGH] CWE-416 CVE-2021-30609: Chromium: CVE-2021-30609 Use after free in Sign-In Chromium: CVE-2021-30609 Use after free in Sign-In
nvd
CVE-2022-24051P3HIGHCVSS 7.8v34v35+1 more2022-02-18
CVE-2022-24051 [HIGH] CWE-134 CVE-2022-24051: MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability MariaDB CONNECT Storage Engine Format String Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of MariaDB. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of SQL queries. The issue results from the lack of proper validat
nvd
CVE-2021-32919P3HIGHCVSS 7.5v32v33+1 more2021-05-13
CVE-2021-32919 [HIGH] CWE-295 CVE-2021-32919: An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to impersonate another server (when this option is enabled).
nvd
CVE-2021-30613P3HIGHCVSS 8.8v352021-09-03
CVE-2021-30613 [HIGH] CWE-416 CVE-2021-30613: Chromium: CVE-2021-30613 Use after free in Base internals Chromium: CVE-2021-30613 Use after free in Base internals
nvd
CVE-2021-30624P3HIGHCVSS 8.8v352021-09-03
CVE-2021-30624 [HIGH] CWE-416 CVE-2021-30624: Chromium: CVE-2021-30624 Use after free in Autofill Chromium: CVE-2021-30624 Use after free in Autofill
nvd
CVE-2021-31556P3CRITICALCVSS 9.8v33v34+1 more2021-08-12
CVE-2021-31556 [CRITICAL] CWE-1284 CVE-2021-31556: An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitCo An issue was discovered in the Oauth extension for MediaWiki through 1.35.2. MWOAuthConsumerSubmitControl.php does not ensure that the length of an RSA key will fit in a MySQL blob.
nvd
CVE-2021-30622P3HIGHCVSS 8.8v352021-09-03
CVE-2021-30622 [HIGH] CWE-416 CVE-2021-30622: Chromium: CVE-2021-30622 Use after free in WebApp Installs Chromium: CVE-2021-30622 Use after free in WebApp Installs
nvd
CVE-2021-30623P3HIGHCVSS 8.8v352021-09-03
CVE-2021-30623 [HIGH] CWE-416 CVE-2021-30623: Chromium: CVE-2021-30623 Use after free in Bookmarks Chromium: CVE-2021-30623 Use after free in Bookmarks
nvd
CVE-2022-1586P3CRITICALCVSS 9.1v35v362022-05-16
CVE-2022-1586 [CRITICAL] CWE-125 CVE-2022-1586: An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchi An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was not fully read in case-less matching within JIT.
nvd
CVE-2021-27023P3CRITICALCVSS 9.8v352021-11-18
CVE-2021-27023 [CRITICAL] CVE-2021-27023: A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credential A flaw was discovered in Puppet Agent and Puppet Server that may result in a leak of HTTP credentials when following HTTP redirects to a different host. This is similar to CVE-2018-1000007
nvd
CVE-2014-1529P3HIGHCVSS 8.8v19v202014-04-30
CVE-2014-1529 [HIGH] CWE-269 CVE-2014-1529: The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird b The Web Notification API in Mozilla Firefox before 29.0, Firefox ESR 24.x before 24.5, Thunderbird before 24.5, and SeaMonkey before 2.26 allows remote attackers to bypass intended source-component restrictions and execute arbitrary JavaScript code in a privileged context via a crafted web page for which Notification.permission is granted.
nvd
CVE-2022-39958P3HIGHCVSS 7.5v35v36+1 more2022-09-20
CVE-2022-39958 [HIGH] CWE-863 CVE-2022-39958: The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfi The OWASP ModSecurity Core Rule Set (CRS) is affected by a response body bypass to sequentially exfiltrate small and undetectable sections of data by repeatedly submitting an HTTP Range header field with a small byte range. A restricted resource, access to which would ordinarily be detected, may be exfiltrated from the backend, despite being protected
nvd
CVE-2015-1860P3MEDIUMCVSS 6.8v20v21+1 more2015-05-12
CVE-2015-1860 [MEDIUM] CWE-119 CVE-2015-1860: Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5 Multiple buffer overflows in gui/image/qgifhandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault) and possibly execute arbitrary code via a crafted GIF image.
nvd
CVE-2023-6879P3CRITICALCVSS 9.8v38v392023-12-27
CVE-2023-6879 [CRITICAL] CWE-20 CVE-2023-6879: Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a Increasing the resolution of video frames, while performing a multi-threaded encode, can result in a heap overflow in av1_loop_restoration_dealloc().
nvd
CVE-2026-54230P3HIGHCVSS 7.8v43v442026-06-13
CVE-2026-54230 [HIGH] CWE-59 CVE-2026-54230: A symlink following vulnerability was found in the ABRT post-create event handler scripts in librepo A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is replaced with a symlink, the shell process running as root follows the symlink and writes content to the symlink target, allowing arbitrary f
nvd
Fedoraproject Fedora vulnerabilities | cvebase