cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 7 of 264
CVE-2024-1597P1CRITICALCVSS 9.8Exploitedv402024-02-19
CVE-2024-1597 [CRITICAL] CWE-89 CVE-2024-1597: pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. N pgjdbc, the PostgreSQL JDBC Driver, allows attacker to inject SQL if using PreferQueryMode=SIMPLE. Note this is not the default. In the default mode there is no vulnerability. A placeholder for a numeric value must be immediately preceded by a minus. There must be a second placeholder for a string value after the first placeholder; both must be on th
nvd
CVE-2020-10684P1HIGHCVSS 7.1Exploitedv30v31+1 more2020-03-24
CVE-2020-10684 [HIGH] CWE-94 CVE-2020-10684: A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2 A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansibl
nvd
CVE-2021-1801P1MEDIUMCVSS 6.5Exploitedv32v332021-04-02
CVE-2021-1801 [MEDIUM] CVE-2021-1801: This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Maliciously crafted web content may violate iframe sandboxing policy.
nvd
CVE-2021-1765P1MEDIUMCVSS 6.5Exploitedv32v332021-04-02
CVE-2021-1765 [MEDIUM] CVE-2021-1765: This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big This issue was addressed with improved iframe sandbox enforcement. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave. Maliciously crafted web content may violate iframe sandboxing policy.
nvd
CVE-2019-5782P2HIGHCVSS 8.8Exploitedv29v302019-02-19
CVE-2019-5782 [HIGH] CWE-125 CVE-2019-5782: Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote att Incorrect optimization assumptions in V8 in Google Chrome prior to 72.0.3626.81 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
nvd
CVE-2023-31248P2HIGHCVSS 7.8Exploitedv37v382023-07-05
CVE-2023-31248 [HIGH] CWE-416 CVE-2023-31248: Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byi Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
nvd
CVE-2024-2044P1CRITICALCVSS 9.9PoCv402024-03-07
CVE-2024-2044 [CRITICAL] CWE-31 CVE-2024-2044: pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in pgAdmin <= 8.3 is affected by a path-traversal vulnerability while deserializing users’ sessions in the session handling code. If the server is running on Windows, an unauthenticated attacker can load and deserialize remote pickle objects and gain code execution. If the server is running on POSIX/Linux, an authenticated attacker can upload pickle obje
nvd
CVE-2024-26987P2MEDIUMCVSS 5.5Exploitedv38v39+1 more2024-05-01
CVE-2024-26987 [MEDIUM] CWE-667 CVE-2024-26987: In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix deadlock In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix deadlock when hugetlb_optimize_vmemmap is enabled When I did hard offline test with hugetlb pages, below deadlock occurs: WARNING: possible circular locking dependency detected 6.8.0-11409-gf6cef5f8c37f #1 Not tainted bash/46904 is trying to acquire lock: ff
nvd
CVE-2022-24785P2HIGHCVSS 7.5Exploitedv35v362022-04-04
CVE-2022-24785 [HIGH] CWE-22 CVE-2022-24785: Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Moment.js is a JavaScript date library for parsing, validating, manipulating, and formatting dates. A path traversal vulnerability impacts npm (server) users of Moment.js between versions 1.0.1 and 2.29.1, especially if a user-provided locale string is directly used to switch moment locale. This problem is patched in 2.29.2, and the patch can be applied
nvd
CVE-2013-4854P2HIGHCVSS 7.8Exploitedv18v192013-07-29
CVE-2013-4854 [HIGH] CVE-2013-4854: The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x b The RFC 5011 implementation in rdata.c in ISC BIND 9.7.x and 9.8.x before 9.8.5-P2, 9.8.6b1, 9.9.x before 9.9.3-P2, and 9.9.4b1, and DNSco BIND 9.9.3-S1 before 9.9.3-S1-P1 and 9.9.4-S1b1, allows remote attackers to cause a denial of service (assertion failure and named daemon exit) via a query with a malformed RDATA section that is not properly handled during c
nvd
CVE-2020-28034P2MEDIUMCVSS 6.1Exploitedv31v32+1 more2020-11-02
CVE-2020-28034 [MEDIUM] CWE-79 CVE-2020-28034: WordPress before 5.5.2 allows XSS associated with global variables. WordPress before 5.5.2 allows XSS associated with global variables.
nvd
CVE-2023-25136P2MEDIUMCVSS 6.5Exploitedv37v382023-02-03
CVE-2023-25136 [MEDIUM] CWE-415 CVE-2023-25136: OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handl OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoret
nvd
CVE-2019-5420P1CRITICALCVSS 9.8PoCv302019-03-27
CVE-2019-5420 [CRITICAL] CWE-77 CVE-2019-5420: A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess the automatically generated development mode secret token. This secret token can be used in combination with other Rails internals to escalate to a remote code execution exploit.
nvd
CVE-2021-44790P1CRITICALCVSS 9.8PoCv34v35+1 more2021-12-20
CVE-2021-44790 [CRITICAL] CWE-787 CVE-2021-44790: A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:pars A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
nvd
CVE-2016-1000110P2MEDIUMCVSS 6.1Exploitedv232019-11-27
CVE-2016-1000110 [MEDIUM] CWE-601 CVE-2016-1000110: The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name c The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.
nvd
CVE-2022-31197P2HIGHCVSS 8.0Exploitedv35v362022-08-03
CVE-2022-31197 [HIGH] CWE-89 CVE-2022-31197: PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database u PostgreSQL JDBC Driver (PgJDBC for short) allows Java programs to connect to a PostgreSQL database using standard, database independent Java code. The PGJDBC implementation of the `java.sql.ResultRow.refreshRow()` method is not performing escaping of column names so a malicious column name that contains a statement terminator, e.g. `;`, could lead to S
nvd
CVE-2021-30538P2MEDIUMCVSS 4.3Exploitedv33v342021-06-07
CVE-2021-30538 [MEDIUM] CWE-863 CVE-2021-30538: Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 al Insufficient policy enforcement in content security policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.
nvd
CVE-2024-3116P1CRITICALCVSS 9.8PoCv392024-04-04
CVE-2024-3116 [CRITICAL] CWE-77 CVE-2024-3116: pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate bina pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on the server hosting PGAdmin, posing a severe risk to the database management system's integrity and the security of the underlying data.
nvd
CVE-2019-5840P2MEDIUMCVSS 4.3Exploitedv29v302019-06-27
CVE-2019-5840 [MEDIUM] CWE-362 CVE-2019-5840: Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remot Incorrect security UI in popup blocker in Google Chrome on iOS prior to 75.0.3770.80 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2015-2331P2HIGHCVSS 7.5Exploitedv222015-03-30
CVE-2015-2331 [HIGH] CWE-189 CVE-2015-2331: Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used Integer overflow in the _zip_cdir_new function in zip_dirent.c in libzip 0.11.2 and earlier, as used in the ZIP extension in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a ZIP archive that contains many en
nvd
Fedoraproject Fedora vulnerabilities | cvebase