Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 74 of 264
CVE-2022-3043P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3043 [HIGH] CWE-787 CVE-2022-3043: Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed
Heap buffer overflow in Screen Capture in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2023-30589P3HIGHCVSS 7.5v37v382023-07-01
CVE-2023-30589 [HIGH] CVE-2023-30589: The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to deli
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impa
nvd
CVE-2022-3198P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3198 [HIGH] CWE-416 CVE-2022-3198: Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentia
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
nvd
CVE-2022-2606P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2606 [HIGH] CWE-416 CVE-2022-2606: Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attac
Use after free in Managed devices API in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to enable a specific Enterprise policy to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2620P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2620 [HIGH] CWE-665 CVE-2022-2620: Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attack
Use after free in WebUI in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2024-0806P3HIGHCVSS 8.8v38v392024-01-24
CVE-2024-0806 [HIGH] CWE-416 CVE-2024-0806: Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to pot
Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
nvd
CVE-2019-19578P3HIGHCVSS 8.8v312019-12-11
CVE-2019-19578 [HIGH] CVE-2019-19578: An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of se
An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "Linear pagetables" is a technique which involves either pointing a pagetable at itself, or to another pagetable of the same or higher level. Xen has limited suppo
nvd
CVE-2020-15565P3HIGHCVSS 8.8v31v322020-07-07
CVE-2020-15565 [HIGH] CWE-400 CVE-2020-15565: An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host
An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require flushing of both TLBs. Furthermore, IOMMUs may be non-coherent, and hence p
nvd
CVE-2020-29479P3HIGHCVSS 8.8v32v332020-12-15
CVE-2020-29479 [HIGH] CWE-862 CVE-2020-29479: An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal r
An issue was discovered in Xen through 4.14.x. In the Ocaml xenstored implementation, the internal representation of the tree has special cases for the root node, because this node has no parent. Unfortunately, permissions were not checked for certain operations on the root node. Unprivileged guests can get and modify permissions, list, and delete the
nvd
CVE-2020-8955P3CRITICALCVSS 9.8v30v31+1 more2020-02-12
CVE-2020-8955 [CRITICAL] CWE-120 CVE-2020-8955: irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to
irc_mode_channel_update in plugins/irc/irc-mode.c in WeeChat through 2.7 allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a malformed IRC message 324 (channel mode).
nvd
CVE-2020-3341P3HIGHCVSS 7.5v30v31+1 more2020-05-13
CVE-2020-3341 [HIGH] CWE-20 CVE-2020-3341: A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101
A vulnerability in the PDF archive parsing module in Clam AntiVirus (ClamAV) Software versions 0.101 - 0.102.2 could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to a stack buffer overflow read. An attacker could exploit this vulnerability by sending a crafted PDF file to
nvd
CVE-2019-14812P3HIGHCVSS 7.8v312019-11-27
CVE-2019-14812 [HIGH] CWE-648 CVE-2019-14812: A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where
A flaw was found in all ghostscript versions 9.x before 9.50, in the .setuserparams2 procedure where it did not properly secure its privileged calls, enabling scripts to bypass `-dSAFER` restrictions. A specially crafted PostScript file could disable security protection and then have access to the file system, or execute arbitrary commands.
nvd
CVE-2009-0846P3CRITICALCVSS 10.0v9v102009-04-09
CVE-2009-0846 [CRITICAL] CWE-824 CVE-2009-0846: The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime de
The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer.
nvd
CVE-2020-11501P3HIGHCVSS 7.4v31v322020-04-03
CVE-2020-11501 [HIGH] CWE-330 CVE-2020-11501: GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.
GnuTLS 3.6.x before 3.6.13 uses incorrect cryptography for DTLS. The earliest affected version is 3.6.3 (2018-07-16) because of an error in a 2017-10-06 commit. The DTLS client always uses 32 '\0' bytes instead of a random value, and thus contributes no randomness to a DTLS negotiation. This breaks the security guarantees of the DTLS protocol.
nvd
CVE-2020-10802P3HIGHCVSS 8.0v30v31+1 more2020-03-22
CVE-2020-10802 [HIGH] CWE-89 CVE-2020-10802: In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discover
In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An attacker can generate a crafted database or table name. The attack can be perform
nvd
CVE-2007-6013P3CRITICALCVSS 9.8v7v82007-11-19
CVE-2007-6013 [CRITICAL] CWE-327 CVE-2007-6013: Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which a
Wordpress 1.5 through 2.3.1 uses cookie values based on the MD5 hash of a password MD5 hash, which allows attackers to bypass authentication by obtaining the MD5 hash from the user database, then generating the authentication cookie from that hash.
nvd
CVE-2012-4524P3HIGHCVSS 7.5v16v17+1 more2019-11-21
CVE-2012-4524 [HIGH] CWE-20 CVE-2012-4524: xlockmore before 5.43 'dclock' security bypass vulnerability
xlockmore before 5.43 'dclock' security bypass vulnerability
nvd
CVE-2015-8008P3HIGHCVSS 7.5v21v22+1 more2017-12-29
CVE-2015-8008 [HIGH] CWE-284 CVE-2015-8008: The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/i
The OAuth extension for MediaWiki improperly negotiates a new client token only over Special:OAuth/initiate, which allows attackers to bypass intended IP address access restrictions by making an API request with an existing token.
nvd
CVE-2022-1708P3HIGHCVSS 7.5v362022-06-07
CVE-2022-1708 [HIGH] CWE-400 CVE-2022-1708: A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyon
A vulnerability was found in CRI-O that causes memory or disk space exhaustion on the node for anyone with access to the Kube API. The ExecSync request runs commands in a container and logs the output of the command. This output is then read by CRI-O after command execution, and it is read in a manner where the entire file corresponding to the output of
nvd
CVE-2016-7543P3HIGHCVSS 8.4v23v24+1 more2017-01-19
CVE-2016-7543 [HIGH] CWE-20 CVE-2016-7543: Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SH
Bash before 4.4 allows local users to execute arbitrary commands with root privileges via crafted SHELLOPTS and PS4 environment variables.
nvd