cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 80 of 264
CVE-2021-38007P3HIGHCVSS 8.8v342021-12-23
CVE-2021-38007 [HIGH] CWE-843 CVE-2021-38007: Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-38012P3HIGHCVSS 8.8v342021-12-23
CVE-2021-38012 [HIGH] CWE-843 CVE-2021-38012: Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially Type confusion in V8 in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-3040P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3040 [HIGH] CWE-787 CVE-2022-3040: Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potent Use after free in Layout in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-3041P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3041 [HIGH] CWE-416 CVE-2022-3041: Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potent Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37959P3HIGHCVSS 8.8v33v352021-10-08
CVE-2021-37959 [HIGH] CWE-416 CVE-2021-37959: Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convin Use after free in Task Manager in Google Chrome prior to 94.0.4606.54 allowed an attacker who convinced a user to enage in a series of user gestures to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37977P3HIGHCVSS 8.8v332021-11-02
CVE-2021-37977 [HIGH] CWE-416 CVE-2021-37977: Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacke Use after free in Garbage Collection in Google Chrome prior to 94.0.4606.81 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30629P3HIGHCVSS 8.8v33v352021-10-08
CVE-2021-30629 [HIGH] CWE-416 CVE-2021-30629: Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who h Use after free in Permissions in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-38014P3HIGHCVSS 8.8v342021-12-23
CVE-2021-38014 [HIGH] CWE-787 CVE-2021-38014: Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker Out of bounds write in Swiftshader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2858P3HIGHCVSS 8.8v372022-09-26
CVE-2022-2858 [HIGH] CWE-416 CVE-2022-2858: Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction.
nvd
CVE-2022-3039P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3039 [HIGH] CWE-416 CVE-2022-3039: Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potent Use after free in WebSQL in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2855P3HIGHCVSS 8.8v372022-09-26
CVE-2022-2855 [HIGH] CWE-416 CVE-2022-2855: Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potent Use after free in ANGLE in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2624P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2624 [HIGH] CWE-787 CVE-2022-2624: Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who co Heap buffer overflow in PDF in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2022-3052P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3052 [HIGH] CWE-787 CVE-2022-3052: Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 Heap buffer overflow in Window Manager in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.
nvd
CVE-2022-3050P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3050 [HIGH] CWE-787 CVE-2022-3050: Heap buffer overflow in WebUI in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote Heap buffer overflow in WebUI in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.
nvd
CVE-2020-11076P3HIGHCVSS 7.5v332020-05-22
CVE-2020-11076 [HIGH] CWE-444 CVE-2020-11076: In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an i In Puma (RubyGem) before 4.3.4 and 3.12.5, an attacker could smuggle an HTTP response, by using an invalid transfer-encoding header. The problem has been fixed in Puma 3.12.5 and Puma 4.3.4.
nvd
CVE-2022-42333P3HIGHCVSS 8.6v37v382023-03-21
CVE-2022-42333 [HIGH] CWE-770 CVE-2022-42333: x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would otherwise be put in place. While not expose
nvd
CVE-2022-3055P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3055 [HIGH] CWE-416 CVE-2022-3055: Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who co Use after free in Passwords in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-3051P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3051 [HIGH] CWE-787 CVE-2022-3051: Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allow Heap buffer overflow in Exosphere in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interactions.
nvd
CVE-2022-2854P3HIGHCVSS 8.8v372022-09-26
CVE-2022-2854 [HIGH] CWE-362 CVE-2022-2854: Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to Use after free in SwiftShader in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2857P3HIGHCVSS 8.8v372022-09-26
CVE-2022-2857 [HIGH] CWE-362 CVE-2022-2857: Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potent Use after free in Blink in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
Fedoraproject Fedora vulnerabilities | cvebase