Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 81 of 264
CVE-2022-3058P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3058 [HIGH] CWE-416 CVE-2022-3058: Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who
Use after free in Sign-In Flow in Google Chrome prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.
nvd
CVE-2022-2603P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2603 [HIGH] CWE-416 CVE-2022-2603: Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to poten
Use after free in Omnibox in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-25648P3HIGHCVSS 7.5v31v32+1 more2020-10-20
CVE-2020-25648 [HIGH] CWE-770 CVE-2020-25648: A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows
A flaw was found in the way NSS handled CCS (ChangeCipherSpec) messages in TLS 1.3. This flaw allows a remote attacker to send multiple CCS messages, causing a denial of service for servers compiled with the NSS library. The highest threat from this vulnerability is to system availability. This flaw affects NSS versions before 3.58.
nvd
CVE-2023-4366P3HIGHCVSS 8.8v382023-08-15
CVE-2023-4366 [HIGH] CWE-416 CVE-2023-4366: Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinc
Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-2614P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2614 [HIGH] CWE-416 CVE-2022-2614: Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to
Use after free in Sign-In Flow in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2008-0062P3CRITICALCVSS 9.8v7v82008-03-19
CVE-2008-0062 [CRITICAL] CWE-665 CVE-2008-0062: KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which al
KDC in MIT Kerberos 5 (krb5kdc) does not set a global variable for some krb4 message types, which allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted messages that trigger a NULL pointer dereference or double-free.
nvd
CVE-2022-2604P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2604 [HIGH] CWE-416 CVE-2022-2604: Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to
Use after free in Safe Browsing in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2017-5330P3HIGHCVSS 7.8v252017-03-27
CVE-2017-5330 [HIGH] CWE-78 CVE-2017-5330: ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an ar
ark before 16.12.1 might allow remote attackers to execute arbitrary code via an executable in an archive, related to associated applications.
nvd
CVE-2022-2623P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2623 [HIGH] CWE-362 CVE-2022-2623: Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attack
Use after free in Offline in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2022-3559P3HIGHCVSS 7.5v35v36+1 more2022-10-17
CVE-2022-3559 [HIGH] CWE-119 CVE-2022-3559: A vulnerability was found in Exim and classified as problematic. This issue affects some unknown pro
A vulnerability was found in Exim and classified as problematic. This issue affects some unknown processing of the component Regex Handler. The manipulation leads to use after free. The name of the patch is 4e9ed49f8f12eb331b29bd5b6dc3693c520fddc2. It is recommended to apply a patch to fix this issue. The identifier VDB-211073 was assigned to this vulne
nvd
CVE-2022-3049P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3049 [HIGH] CWE-362 CVE-2022-3049: Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a
Use after free in SplitScreen in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-14352P3HIGHCVSS 8.0v31v32+1 more2020-08-30
CVE-2020-14352 [HIGH] CWE-22 CVE-2020-14352: A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found
A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the targeted system via path traversal. This flaw could potentially result in
nvd
CVE-2022-3042P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3042 [HIGH] CWE-362 CVE-2022-3042: Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote att
Use after free in PhoneHub in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-37967P3HIGHCVSS 7.2v36v372022-11-09
CVE-2022-37967 [HIGH] CVE-2022-37967: Windows Kerberos Elevation of Privilege Vulnerability
Windows Kerberos Elevation of Privilege Vulnerability
nvd
CVE-2022-3071P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3071 [HIGH] CWE-362 CVE-2022-3071: Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a r
Use after free in Tab Strip in Google Chrome on Chrome OS, Lacros prior to 105.0.5195.52 allowed a remote attacker who convinced a user to engage in specific UI interactions to potentially exploit heap corruption via crafted UI interaction.
nvd
CVE-2022-2609P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2609 [HIGH] CWE-362 CVE-2022-2609: Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote
Use after free in Nearby Share in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2022-2607P3HIGHCVSS 8.8v372022-08-12
CVE-2022-2607 [HIGH] CWE-362 CVE-2022-2607: Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote at
Use after free in Tab Strip in Google Chrome on Chrome OS prior to 104.0.5112.79 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via specific UI interactions.
nvd
CVE-2024-0813P3HIGHCVSS 8.8v38v392024-01-24
CVE-2024-0813 [HIGH] CWE-416 CVE-2024-0813: Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convi
Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
nvd
CVE-2016-7545P3HIGHCVSS 8.8v252017-01-19
CVE-2016-7545 [HIGH] CWE-284 CVE-2016-7545: SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
nvd
CVE-2020-14593P3HIGHCVSS 7.4v31v322020-07-15
CVE-2020-14593 [HIGH] CVE-2020-14593: Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported
Vulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: 2D). Supported versions that are affected are Java SE: 7u261, 8u251, 11.0.7 and 14.0.1; Java SE Embedded: 8u251. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful atta
nvd