Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 71 of 264
CVE-2021-21162P3HIGHCVSS 8.8v32v33+1 more2021-03-09
CVE-2021-21162 [HIGH] CWE-416 CVE-2021-21162: Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potenti
Use after free in WebRTC in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21191P3HIGHCVSS 8.8v322021-03-16
CVE-2021-21191 [HIGH] CWE-416 CVE-2021-21191: Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potenti
Use after free in WebRTC in Google Chrome prior to 89.0.4389.90 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-38008P3HIGHCVSS 8.8v342021-12-23
CVE-2021-38008 [HIGH] CWE-416 CVE-2021-38008: Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentia
Use after free in media in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21197P3HIGHCVSS 8.8v32v33+1 more2021-04-09
CVE-2021-21197 [HIGH] CWE-787 CVE-2021-21197: Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.114 allowed a remote attacker t
Heap buffer overflow in TabStrip in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-10222P3HIGHCVSS 7.5v30v312019-11-08
CVE-2019-10222 [HIGH] CWE-755 CVE-2019-10222: A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests.
A flaw was found in the Ceph RGW configuration with Beast as the front end handling client requests. An unauthenticated attacker could crash the Ceph RGW server by sending valid HTTP headers and terminating the connection, resulting in a remote denial of service for Ceph RGW clients.
nvd
CVE-2021-30585P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30585 [HIGH] CWE-416 CVE-2021-30585: Use after free in sensor handling in Google Chrome on Windows prior to 92.0.4515.107 allowed a remot
Use after free in sensor handling in Google Chrome on Windows prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30569P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30569 [HIGH] CWE-416 CVE-2021-30569: Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potent
Use after free in sqlite in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21114P3HIGHCVSS 8.8v32v332021-01-08
CVE-2021-21114 [HIGH] CWE-416 CVE-2021-21114: Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potenti
Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-21112P3HIGHCVSS 8.8v32v332021-01-08
CVE-2021-21112 [HIGH] CWE-416 CVE-2021-21112: Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potenti
Use after free in Blink in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37970P3HIGHCVSS 8.8v33v352021-10-08
CVE-2021-37970 [HIGH] CWE-416 CVE-2021-37970: Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker t
Use after free in File System API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2024-27319P3CRITICALCVSS 9.1v39v402024-02-23
CVE-2024-27319 [CRITICAL] CWE-125 CVE-2024-27319: Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
nvd
CVE-2022-0104P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0104 [HIGH] CWE-787 CVE-2022-0104: Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to po
Heap buffer overflow in ANGLE in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30518P3HIGHCVSS 8.8v33v342021-06-04
CVE-2021-30518 [HIGH] CWE-787 CVE-2021-30518: Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacke
Heap buffer overflow in Reader Mode in Google Chrome prior to 90.0.4430.212 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30516P3HIGHCVSS 8.8v33v342021-06-04
CVE-2021-30516 [HIGH] CWE-787 CVE-2021-30516: Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker wh
Heap buffer overflow in History in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30521P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30521 [HIGH] CWE-787 CVE-2021-30521: Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote
Heap buffer overflow in Autofill in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
nvd
CVE-2021-4063P3HIGHCVSS 8.8v342021-12-23
CVE-2021-4063 [HIGH] CWE-416 CVE-2021-4063: Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker t
Use after free in developer tools in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0106P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0106 [HIGH] CWE-416 CVE-2022-0106: Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who conv
Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-1532P3HIGHCVSS 8.8v36v37+1 more2023-03-21
CVE-2023-1532 [HIGH] CWE-125 CVE-2023-1532: Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker t
Out of bounds read in GPU Video in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-0105P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0105 [HIGH] CWE-416 CVE-2022-0105: Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker
Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-4064P3HIGHCVSS 8.8v342021-12-23
CVE-2021-4064 [HIGH] CWE-416 CVE-2021-4064: Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote
Use after free in screen capture in Google Chrome on ChromeOS prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd