cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 83 of 264
CVE-2022-39369P3HIGHCVSS 8.0v35v36+1 more2022-11-01
CVE-2022-39369 [HIGH] CWE-99 CVE-2022-39369: phpCAS is an authentication library that allows PHP applications to easily authenticate users via a phpCAS is an authentication library that allows PHP applications to easily authenticate users via a Central Authentication Service (CAS) server. The phpCAS library uses HTTP headers to determine the service URL used to validate tickets. This allows an attacker to control the host header and use a valid ticket granted for any authorized service in the sa
nvd
CVE-2023-35001P3HIGHCVSS 7.8v37v382023-07-05
CVE-2023-35001 [HIGH] CWE-787 CVE-2023-35001: Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm regist Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace
nvd
CVE-2015-4454P3HIGHCVSS 7.5v22v23+1 more2015-06-17
CVE-2015-4454 [HIGH] CWE-89 CVE-2015-4454: SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti be SQL injection vulnerability in the get_hash_graph_template function in lib/functions.php in Cacti before 0.8.8d allows remote attackers to execute arbitrary SQL commands via the graph_template_id parameter to graph_templates.php.
nvd
CVE-2023-4236P3HIGHCVSS 7.5v37v38+1 more2023-09-20
CVE-2023-4236 [HIGH] CWE-617 CVE-2023-4236: A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpecte A flaw in the networking code handling DNS-over-TLS queries may cause `named` to terminate unexpectedly due to an assertion failure. This happens when internal data structures are incorrectly reused under significant DNS-over-TLS query load. This issue affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1.
nvd
CVE-2020-14386P3HIGHCVSS 7.8v332020-09-16
CVE-2020-14386 [HIGH] CWE-250 CVE-2020-14386: A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root A flaw was found in the Linux kernel before 5.9-rc4. Memory corruption can be exploited to gain root privileges from unprivileged processes. The highest threat from this vulnerability is to data confidentiality and integrity.
nvd
CVE-2021-42380P3HIGHCVSS 7.2v33v342021-11-15
CVE-2021-42380 [HIGH] CWE-416 CVE-2021-42380: A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the clrvar function
nvd
CVE-2021-21367P3HIGHCVSS 8.1v32v332021-03-12
CVE-2021-21367 [HIGH] CWE-863 CVE-2021-21367: Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has Switchboard Bluetooth Plug for elementary OS from version 2.3.0 and before version version 2.3.5 has an incorrect authorization vulnerability. When the Bluetooth plug is running (in discoverable mode), Bluetooth service requests and pairing requests are automatically accepted, allowing physically proximate attackers to pair with a device running an af
nvd
CVE-2012-2130P3HIGHCVSS 7.4v172019-12-06
CVE-2012-2130 [HIGH] CWE-326 CVE-2012-2130: A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption e A Security Bypass vulnerability exists in PolarSSL 0.99pre4 through 1.1.1 due to a weak encryption error when generating Diffie-Hellman values and RSA keys.
nvd
CVE-2020-25698P3HIGHCVSS 7.5v32v332020-11-19
CVE-2020-25698 [HIGH] CWE-284 CVE-2020-25698: Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored Users' enrollment capabilities were not being sufficiently checked in Moodle when they are restored into an existing course. This could lead to them unenrolling users without having permission to do so. Versions affected: 3.5 to 3.5.14, 3.7 to 3.7.8, 3.8 to 3.8.5, 3.9 to 3.9.2 and earlier unsupported versions. Fixed in 3.9.3, 3.8.6, 3.7.9, 3.5.15, and
nvd
CVE-2019-14532P3CRITICALCVSS 9.8v30v31+1 more2019-08-02
CVE-2019-14532 [CRITICAL] CWE-193 CVE-2019-14532: An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an un An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table.
nvd
CVE-2021-42381P3HIGHCVSS 7.2v33v342021-11-15
CVE-2021-42381 [HIGH] CWE-416 CVE-2021-42381: A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the hash_init function
nvd
CVE-2021-42379P3HIGHCVSS 7.2v33v342021-11-15
CVE-2021-42379 [HIGH] CWE-416 CVE-2021-42379: A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the next_input_file function
nvd
CVE-2021-42385P3HIGHCVSS 7.2v33v342021-11-15
CVE-2021-42385 [HIGH] CWE-416 CVE-2021-42385: A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the evaluate function
nvd
CVE-2015-2155P3HIGHCVSS 7.5v212015-03-24
CVE-2015-2155 [HIGH] CVE-2015-2155: The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (cras The force printer in tcpdump before 4.7.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
nvd
CVE-2021-30473P3CRITICALCVSS 9.8v342021-05-06
CVE-2021-30473 [CRITICAL] CWE-763 CVE-2021-30473: aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap. aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
nvd
CVE-2021-42386P3HIGHCVSS 7.2v33v342021-11-15
CVE-2021-42386 [HIGH] CWE-416 CVE-2021-42386: A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the nvalloc function
nvd
CVE-2021-42378P3HIGHCVSS 7.2v33v342021-11-15
CVE-2021-42378 [HIGH] CWE-416 CVE-2021-42378: A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_i function
nvd
CVE-2021-42384P3HIGHCVSS 7.2v33v342021-11-15
CVE-2021-42384 [HIGH] CWE-416 CVE-2021-42384: A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the handle_special function
nvd
CVE-2021-42382P3HIGHCVSS 7.2v33v342021-11-15
CVE-2021-42382 [HIGH] CWE-416 CVE-2021-42382: A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when A use-after-free in Busybox's awk applet leads to denial of service and possibly code execution when processing a crafted awk pattern in the getvar_s function
nvd
CVE-2020-14372P3HIGHCVSS 7.5v33v342021-03-03
CVE-2020-14372 [HIGH] CWE-184 CVE-2020-14372: A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the A A flaw was found in grub2 in versions prior to 2.06, where it incorrectly enables the usage of the ACPI command when Secure Boot is enabled. This flaw allows an attacker with privileged access to craft a Secondary System Description Table (SSDT) containing code to overwrite the Linux kernel lockdown variable content directly into memory. The table is
nvd
Fedoraproject Fedora vulnerabilities | cvebase