cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 79 of 264
CVE-2020-6532P3HIGHCVSS 8.8v332020-09-21
CVE-2020-6532 [HIGH] CWE-416 CVE-2020-6532: Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentia Use after free in SCTP in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-9496P3HIGHCVSS 7.5v28v29+1 more2019-04-17
CVE-2019-9496 [HIGH] CWE-642 CVE-2019-9496: An invalid authentication sequence could result in the hostapd process terminating due to missing st An invalid authentication sequence could result in the hostapd process terminating due to missing state validation steps when processing the SAE confirm message when in hostapd/AP mode. All version of hostapd with SAE support are vulnerable. An attacker may force the hostapd process to terminate, performing a denial of service attack. Both hostapd with
nvd
CVE-2021-21152P3HIGHCVSS 8.8v32v332021-02-22
CVE-2021-21152 [HIGH] CWE-787 CVE-2021-21152: Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote atta Heap buffer overflow in Media in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37956P3HIGHCVSS 8.8v33v352021-10-08
CVE-2021-37956 [HIGH] CWE-416 CVE-2021-37956: Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote att Use after free in Offline use in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30567P3HIGHCVSS 8.8v33v34+1 more2021-08-03
CVE-2021-30567 [HIGH] CWE-416 CVE-2021-30567: Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to open DevTools to potentially exploit heap corruption via specific user gesture.
nvd
CVE-2021-30535P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30535 [HIGH] CWE-415 CVE-2021-30535: Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially e Double free in ICU in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30514P3HIGHCVSS 8.8v33v342021-06-04
CVE-2021-30514 [HIGH] CWE-416 CVE-2021-30514: Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had Use after free in Autofill in Google Chrome prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30523P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30523 [HIGH] CWE-416 CVE-2021-30523: Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potenti Use after free in WebRTC in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to potentially exploit heap corruption via a crafted SCTP packet.
nvd
CVE-2021-30545P3HIGHCVSS 8.8v33v342021-06-15
CVE-2021-30545 [HIGH] CWE-416 CVE-2021-30545: Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who h Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-0198P3HIGHCVSS 7.5v32v332020-06-11
CVE-2020-0198 [HIGH] CWE-190 CVE-2020-0198: In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer ove In exif_data_load_data_content of exif-data.c, there is a possible UBSAN abort due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146428941
nvd
CVE-2022-2011P3HIGHCVSS 8.8v372022-07-28
CVE-2022-2011 [HIGH] CWE-416 CVE-2022-2011: Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potent Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37978P3HIGHCVSS 8.8v332021-11-02
CVE-2021-37978 [HIGH] CWE-787 CVE-2021-37978: Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to po Heap buffer overflow in Blink in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30626P3HIGHCVSS 8.8v33v352021-10-08
CVE-2021-30626 [HIGH] CWE-787 CVE-2021-30626: Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacke Out of bounds memory access in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2161P3HIGHCVSS 8.8v35v362022-07-28
CVE-2022-2161 [HIGH] CWE-416 CVE-2022-2161: Use after free in WebApp Provider in Google Chrome prior to 103.0.5060.53 allowed a remote attacker Use after free in WebApp Provider in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who convinced the user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2021-30628P3HIGHCVSS 8.8v33v352021-10-08
CVE-2021-30628 [HIGH] CWE-787 CVE-2021-30628: Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to p Stack buffer overflow in ANGLE in Google Chrome prior to 93.0.4577.82 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page.
nvd
CVE-2022-2007P3HIGHCVSS 8.8v372022-07-28
CVE-2022-2007 [HIGH] CWE-416 CVE-2022-2007: Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to poten Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37998P3HIGHCVSS 8.8v342021-11-23
CVE-2021-37998 [HIGH] CWE-416 CVE-2021-37998: Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacke Use after free in Garbage Collection in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0107P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0107 [HIGH] CWE-416 CVE-2022-0107: Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an at Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-0098P3HIGHCVSS 8.8v34v35+1 more2022-02-12
CVE-2022-0098 [HIGH] CWE-416 CVE-2022-0098: Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an atta Use after free in Screen Capture in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to perform specific user gestures to potentially exploit heap corruption via specific user gestures.
nvd
CVE-2023-1815P3HIGHCVSS 8.8v36v372023-04-04
CVE-2023-1815 [HIGH] CWE-416 CVE-2023-1815: Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker Use after free in Networking APIs in Google Chrome prior to 112.0.5615.49 allowed a remote attacker who convinced a user to engage in specific UI interaction to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
Fedoraproject Fedora vulnerabilities | cvebase