Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 75 of 264
CVE-2013-7087P3CRITICALCVSS 9.8v17v182019-11-15
CVE-2013-7087 [CRITICAL] CWE-119 CVE-2013-7087: ClamAV before 0.97.7 has WWPack corrupt heap memory
ClamAV before 0.97.7 has WWPack corrupt heap memory
nvd
CVE-2023-0179P3HIGHCVSS 7.8v36v372023-03-27
CVE-2023-0179 [HIGH] CWE-190 CVE-2023-0179: A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
nvd
CVE-2019-5419P3HIGHCVSS 7.5v302019-03-27
CVE-2019-5419 [HIGH] CWE-400 CVE-2019-5419: There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.
There is a possible denial of service vulnerability in Action View (Rails) <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 where specially crafted accept headers can cause action view to consume 100% cpu and make the server unresponsive.
nvd
CVE-2016-2041P3HIGHCVSS 7.5v22v232016-02-20
CVE-2016-2041 [HIGH] CWE-254 CVE-2016-2041: libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x befo
libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restrictions by measuring time differences.
nvd
CVE-2021-31162P3CRITICALCVSS 9.8v32v33+1 more2021-04-14
CVE-2021-31162 [CRITICAL] CWE-415 CVE-2021-31162: In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter functio
In the standard library in Rust before 1.52.0, a double free can occur in the Vec::from_iter function if freeing the element panics.
nvd
CVE-2014-2581P3HIGHCVSS 7.5v19v202020-01-28
CVE-2014-2581 [HIGH] CWE-522 CVE-2014-2581: Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid opt
Smb4K before 1.1.1 allows remote attackers to obtain credentials via vectors related to the cuid option in the "Additional options" line edit.
nvd
CVE-2023-41915P3HIGHCVSS 8.1v37v38+1 more2023-09-09
CVE-2023-41915 [HIGH] CWE-362 CVE-2023-41915: OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
nvd
CVE-2022-47318P3HIGHCVSS 8.0v372023-01-17
CVE-2022-47318 [HIGH] CVE-2022-47318: ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ru
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.
nvd
CVE-2016-3720P3CRITICALCVSS 9.8v242016-06-10
CVE-2016-3720 [CRITICAL] CWE-611 CVE-2016-3720: XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka j
XML external entity (XXE) vulnerability in XmlMapper in the Data format extension for Jackson (aka jackson-dataformat-xml) allows attackers to have unspecified impact via unknown vectors.
nvd
CVE-2020-12244P3HIGHCVSS 7.5v31v322020-05-19
CVE-2020-12244 [HIGH] CWE-347 CVE-2020-12244: An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section
An issue has been found in PowerDNS Recursor 4.1.0 through 4.3.0 where records in the answer section of a NXDOMAIN response lacking an SOA were not properly validated in SyncRes::processAnswer, allowing an attacker to bypass DNSSEC validation.
nvd
CVE-2019-5885P3HIGHCVSS 7.5v28v292019-03-21
CVE-2019-5885 [HIGH] CWE-330 CVE-2019-5885: Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, us
Matrix Synapse before 0.34.0.1, when the macaroon_secret_key authentication parameter is not set, uses a predictable value to derive a secret key and other secrets which could allow remote attackers to impersonate users.
nvd
CVE-2023-39191P3HIGHCVSS 8.2v382023-10-04
CVE-2023-39191 [HIGH] CWE-20 CVE-2023-39191: An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occ
An improper input validation flaw was found in the eBPF subsystem in the Linux kernel. The issue occurs due to a lack of proper validation of dynamic pointers within user-supplied eBPF programs prior to executing them. This may allow an attacker with CAP_BPF privileges to escalate privileges and execute arbitrary code in the context of the kernel.
nvd
CVE-2019-18888P3HIGHCVSS 7.5v30v312019-11-21
CVE-2019-18888 [HIGH] CWE-88 CVE-2019-18888: An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11,
An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIME type validation should occur, then arbitrary arguments are passed to the underlying file command. This is related to symfony/http-foundation (and symfony
nvd
CVE-2020-28366P3HIGHCVSS 7.5v32v332020-11-18
CVE-2020-28366 [HIGH] CWE-94 CVE-2020-28366: Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code exec
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.
nvd
CVE-2021-30954P3HIGHCVSS 7.8v34v352021-08-24
CVE-2021-30954 [HIGH] CWE-843 CVE-2021-30954: A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2
A type confusion issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2024-5158P3HIGHCVSS 8.1v39v402024-05-22
CVE-2024-5158 [HIGH] CWE-843 CVE-2024-5158: Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentiall
Type Confusion in V8 in Google Chrome prior to 125.0.6422.76 allowed a remote attacker to potentially perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2020-1695P3HIGHCVSS 7.5v32v332020-05-19
CVE-2020-1695 [HIGH] CWE-20 CVE-2020-1695: A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x version
A flaw was found in all resteasy 3.x.x versions prior to 3.12.0.Final and all resteasy 4.x.x versions prior to 4.6.0.Final, where an improper input validation results in returning an illegal header that integrates into the server's response. This flaw may result in an injection, which leads to unexpected behavior when the HTTP response is constructed.
nvd
CVE-2023-30631P3HIGHCVSS 7.5v37v382023-06-14
CVE-2023-30631 [HIGH] CWE-20 CVE-2023-30631: Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The co
Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server. The configuration option proxy.config.http.push_method_enabled didn't function. However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects Apache Traffic Server: from 8.0.0 through 9.2.0.
8.x users should upgrade to 8.1
nvd
CVE-2019-9687P3CRITICALCVSS 9.8v292019-03-11
CVE-2019-9687 [CRITICAL] CWE-787 CVE-2019-9687: PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp
PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.
nvd
CVE-2022-28129P3HIGHCVSS 7.5v35v362022-08-10
CVE-2022-28129 [HIGH] CWE-20 CVE-2022-28129: Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows a
Improper Input Validation vulnerability in HTTP/1.1 header parsing of Apache Traffic Server allows an attacker to send invalid headers. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.
nvd