cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 69 of 264
CVE-2019-5808P3HIGHCVSS 8.8v29v302019-06-27
CVE-2019-5808 [HIGH] CWE-416 CVE-2019-5808: Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potenti Use after free in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6474P3HIGHCVSS 8.8v31v322020-05-21
CVE-2020-6474 [HIGH] CWE-416 CVE-2020-6474: Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentia Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6448P3HIGHCVSS 8.8v30v31+1 more2020-04-13
CVE-2020-6448 [HIGH] CWE-416 CVE-2020-6448: Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially Use after free in V8 in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6386P3HIGHCVSS 8.8v30v312020-02-27
CVE-2020-6386 [HIGH] CWE-416 CVE-2020-6386: Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potent Use after free in speech in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6423P3HIGHCVSS 8.8v30v31+1 more2020-04-13
CVE-2020-6423 [HIGH] CWE-416 CVE-2020-6423: Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentia Use after free in audio in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6384P3HIGHCVSS 8.8v30v312020-02-27
CVE-2020-6384 [HIGH] CWE-416 CVE-2020-6384: Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to pote Use after free in WebAudio in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-3900P3HIGHCVSS 7.7v29v30+1 more2019-04-25
CVE-2019-3900 [HIGH] CWE-835 CVE-2019-3900: An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including An infinite loop issue was found in the vhost_net kernel module in Linux Kernel up to and including v5.1-rc6, while handling incoming packets in handle_rx(). It could occur if one end sends packets faster than the other end can process them. A guest user, maybe remote one, could use this flaw to stall the vhost_net kernel thread, resulting in a DoS scena
nvd
CVE-2020-6467P3HIGHCVSS 8.8v31v322020-05-21
CVE-2020-6467 [HIGH] CWE-416 CVE-2020-6467: Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potenti Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-31129P3HIGHCVSS 7.5v35v36+1 more2022-07-06
CVE-2022-31129 [HIGH] CWE-400 CVE-2022-31129: moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Aff moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried by default) has quadratic (N^2) complexity on specific inputs. Users may
nvd
CVE-2020-6860P3HIGHCVSS 8.8v34v352020-01-13
CVE-2020-6860 [HIGH] CWE-787 CVE-2020-6860: libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the read libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.
nvd
CVE-2019-5758P3HIGHCVSS 8.8v29v302019-02-19
CVE-2019-5758 [HIGH] CWE-787 CVE-2019-5758: Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.3626.81 allowed a remo Incorrect object lifecycle management in Blink in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37972P3HIGHCVSS 8.8v33v34+1 more2021-10-08
CVE-2021-37972 [HIGH] CWE-125 CVE-2021-37972: Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker Out of bounds read in libjpeg-turbo in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6434P3HIGHCVSS 8.8v30v31+1 more2020-04-13
CVE-2020-6434 [HIGH] CWE-416 CVE-2020-6434: Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to poten Use after free in devtools in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0729P3HIGHCVSS 8.8v34v352022-02-23
CVE-2022-0729 [HIGH] CWE-823 CVE-2022-0729: Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440. Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.
nvd
CVE-2020-6436P3HIGHCVSS 8.8v30v31+1 more2020-04-13
CVE-2020-6436 [HIGH] CWE-416 CVE-2020-6436: Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker Use after free in window management in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-13728P3HIGHCVSS 8.8v30v312019-12-10
CVE-2019-13728 [HIGH] CWE-787 CVE-2019-13728: Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker t Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-49502P3HIGHCVSS 8.8v38v39+1 more2024-04-19
CVE-2023-49502 [HIGH] CWE-120 CVE-2023-49502: Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbi Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the ff_bwdif_filter_intra_c function in the libavfilter/bwdifdsp.c:125:5 component.
nvd
CVE-2019-5809P3HIGHCVSS 8.8v29v302019-06-27
CVE-2019-5809 [HIGH] CWE-416 CVE-2019-5809: Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who Use after free in file chooser in Google Chrome prior to 74.0.3729.108 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page.
nvd
CVE-2020-6553P3HIGHCVSS 8.8v332020-09-21
CVE-2020-6553 [HIGH] CWE-416 CVE-2020-6553: Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attac Use after free in offline mode in Google Chrome on iOS prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6552P3HIGHCVSS 8.8v332020-09-21
CVE-2020-6552 [HIGH] CWE-416 CVE-2020-6552: Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potenti Use after free in Blink in Google Chrome prior to 84.0.4147.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
Fedoraproject Fedora vulnerabilities | cvebase