Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 70 of 264
CVE-2020-16004P3HIGHCVSS 8.8v32v332020-11-03
CVE-2020-16004 [HIGH] CWE-416 CVE-2020-16004: Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker t
Use after free in user interface in Google Chrome prior to 86.0.4240.183 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15978P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15978 [HIGH] CWE-20 CVE-2020-15978: Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed
Insufficient data validation in navigation in Google Chrome on Android prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2019-5774P3HIGHCVSS 8.8v29v302019-02-19
CVE-2019-5774 [HIGH] CWE-862 CVE-2019-5774: Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome
Omission of the .desktop filetype from the Safe Browsing checklist in SafeBrowsing in Google Chrome on Linux prior to 72.0.3626.81 allowed an attacker who convinced a user to download a .desktop file to execute arbitrary code via a downloaded .desktop file.
nvd
CVE-2020-6540P3HIGHCVSS 8.8v332020-09-21
CVE-2020-6540 [HIGH] CWE-787 CVE-2020-6540: Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potenti
Buffer overflow in Skia in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-16003P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-16003 [HIGH] CWE-416 CVE-2020-16003: Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to pote
Use after free in printing in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21192P3HIGHCVSS 8.8v322021-03-16
CVE-2021-21192 [HIGH] CWE-787 CVE-2021-21192: Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker
Heap buffer overflow in tab groups in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21113P3HIGHCVSS 8.8v32v332021-01-08
CVE-2021-21113 [HIGH] CWE-787 CVE-2021-21113: Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to po
Heap buffer overflow in Skia in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21195P3HIGHCVSS 8.8v32v33+1 more2021-04-09
CVE-2021-21195 [HIGH] CWE-416 CVE-2021-21195: Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentiall
Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-30556P3HIGHCVSS 7.5v35v362022-06-09
CVE-2022-30556 [HIGH] CWE-200 CVE-2022-30556: Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that poi
Apache HTTP Server 2.4.53 and earlier may return lengths to applications calling r:wsread() that point past the end of the storage allocated for the buffer.
nvd
CVE-2021-21116P3HIGHCVSS 8.8v32v332021-01-08
CVE-2021-21116 [HIGH] CWE-787 CVE-2021-21116: Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to p
Heap buffer overflow in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30522P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30522 [HIGH] CWE-416 CVE-2021-30522: Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to poten
Use after free in WebAudio in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-4062P3HIGHCVSS 8.8v342021-12-23
CVE-2021-4062 [HIGH] CWE-787 CVE-2021-4062: Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who
Heap buffer overflow in BFCache in Google Chrome prior to 96.0.4664.93 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2008-0599P3CRITICALCVSS 9.8v8v92008-05-05
CVE-2008-0599 [CRITICAL] CWE-131 CVE-2008-0599: The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider
The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.
nvd
CVE-2021-21169P3HIGHCVSS 8.8v32v33+1 more2021-03-09
CVE-2021-21169 [HIGH] CWE-787 CVE-2021-21169: Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker t
Out of bounds memory access in V8 in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2021-21179P3HIGHCVSS 8.8v32v33+1 more2021-03-09
CVE-2021-21179 [HIGH] CWE-416 CVE-2021-21179: Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote
Use after free in Network Internals in Google Chrome on Linux prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-15990P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15990 [HIGH] CWE-416 CVE-2020-15990: Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had
Use after free in autofill in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-15970P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15970 [HIGH] CWE-416 CVE-2020-15970: Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compr
Use after free in NFC in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2020-15971P3HIGHCVSS 8.8v31v32+1 more2020-11-03
CVE-2020-15971 [HIGH] CWE-416 CVE-2020-15971: Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had
Use after free in printing in Google Chrome prior to 86.0.4240.75 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2021-4058P3HIGHCVSS 8.8v342021-12-23
CVE-2021-4058 [HIGH] CWE-787 CVE-2021-4058: Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to po
Heap buffer overflow in ANGLE in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21167P3HIGHCVSS 8.8v32v33+1 more2021-03-09
CVE-2021-21167 [HIGH] CWE-416 CVE-2021-21167: Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to pote
Use after free in bookmarks in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd