cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 73 of 264
CVE-2014-6394P3HIGHCVSS 7.5v19v20+1 more2014-10-08
CVE-2014-6394 [HIGH] CWE-22 CVE-2014-6394: visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a director visionmedia send before 0.8.4 for Node.js uses a partial comparison for verifying whether a directory is within the document root, which allows remote attackers to access restricted directories, as demonstrated using "public-restricted" under a "public" directory.
nvd
CVE-2020-16043P3HIGHCVSS 8.8v32v332021-01-08
CVE-2020-16043 [HIGH] CVE-2020-16043: Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote Insufficient data validation in networking in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to bypass discretionary access control via malicious network traffic.
nvd
CVE-2022-3640P3HIGHCVSS 8.8v35v36+1 more2022-10-21
CVE-2022-3640 [HIGH] CWE-119 CVE-2022-3640: A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the functi A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211944.
nvd
CVE-2015-8106P3HIGHCVSS 7.8v22v23+1 more2016-04-18
CVE-2015-8106 [HIGH] CWE-134 CVE-2015-8106: Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allow Format string vulnerability in the CmdKeywords function in funct1.c in latex2rtf before 2.3.10 allows remote attackers to execute arbitrary code via format string specifiers in the \keywords command in a crafted TeX file.
nvd
CVE-2023-25358P3HIGHCVSS 8.8v382023-03-02
CVE-2023-25358 [HIGH] CWE-416 CVE-2023-25358: A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows a A use-after-free vulnerability in WebCore::RenderLayer::addChild in WebKitGTK before 2.36.8 allows attackers to execute code remotely.
nvd
CVE-2022-3195P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3195 [HIGH] CWE-787 CVE-2022-3195: Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to Out of bounds write in Storage in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-6510P3HIGHCVSS 8.8v38v392023-12-06
CVE-2023-6510 [HIGH] CWE-416 CVE-2023-6510: Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker wh Use after free in Media Capture in Google Chrome prior to 120.0.6099.62 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
nvd
CVE-2022-2158P3HIGHCVSS 8.8v35v362022-07-28
CVE-2022-2158 [HIGH] CWE-416 CVE-2022-2158: Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentiall Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-1820P3HIGHCVSS 8.8v36v372023-04-04
CVE-2023-1820 [HIGH] CWE-787 CVE-2023-1820: Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote att Heap buffer overflow in Browser History in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-2008P3HIGHCVSS 8.8v372022-07-28
CVE-2022-2008 [HIGH] CWE-415 CVE-2022-2008: Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potential Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2157P3HIGHCVSS 8.8v35v362022-07-28
CVE-2022-2157 [HIGH] CWE-416 CVE-2022-2157: Use after free in Interest groups in Google Chrome prior to 103.0.5060.53 allowed a remote attacker Use after free in Interest groups in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-1811P3HIGHCVSS 8.8v36v372023-04-04
CVE-2023-1811 [HIGH] CWE-416 CVE-2023-1811: Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convi Use after free in Frames in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2022-3045P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3045 [HIGH] CWE-787 CVE-2022-3045: Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0.5195.52 allowed a r Insufficient validation of untrusted input in V8 in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30627P3HIGHCVSS 8.8v33v352021-10-08
CVE-2021-30627 [HIGH] CWE-843 CVE-2021-30627: Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to p Type confusion in Blink layout in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-5187P3HIGHCVSS 8.8v37v38+1 more2023-09-28
CVE-2023-5187 [HIGH] CWE-416 CVE-2023-5187: Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convin Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2023-4356P3HIGHCVSS 8.8v382023-08-15
CVE-2023-4356 [HIGH] CWE-416 CVE-2023-4356: Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has co Use after free in Audio in Google Chrome prior to 116.0.5845.96 allowed a remote attacker who has convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-2859P3HIGHCVSS 8.8v372022-09-26
CVE-2022-2859 [HIGH] CWE-416 CVE-2022-2859: Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker Use after free in Chrome OS Shell in Google Chrome prior to 104.0.5112.101 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2022-2613P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2613 [HIGH] CWE-416 CVE-2022-2613: Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attack Use after free in Input in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2010-2008P4LOWCVSS 3.5PoCv132010-07-13
CVE-2010-2008 [LOW] CWE-77 CVE-2010-2008: MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a deni MySQL before 5.1.48 allows remote authenticated users with alter database privileges to cause a denial of service (server crash and database loss) via an ALTER DATABASE command with a #mysql50# string followed by a . (dot), .. (dot dot), ../ (dot dot slash) or similar sequence, and an UPGRADE DATA DIRECTORY NAME command, which causes MySQL to move certain
nvd
CVE-2022-3200P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3200 [HIGH] CWE-787 CVE-2022-3200: Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker Heap buffer overflow in Internals in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
nvd
Fedoraproject Fedora vulnerabilities | cvebase