cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 85 of 264
CVE-2023-29141P3CRITICALCVSS 9.8v372023-03-31
CVE-2023-29141 [CRITICAL] CWE-444 CVE-2023-29141: An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.
nvd
CVE-2022-46393P3CRITICALCVSS 9.8v36v372022-12-15
CVE-2022-46393 [CRITICAL] CWE-125 CVE-2022-46393: An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-ba An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.
nvd
CVE-2023-20197P3HIGHCVSS 7.5v382023-08-16
CVE-2023-20197 [HIGH] CWE-835 CVE-2023-20197: A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV co A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could
nvd
CVE-2015-0848P3MEDIUMCVSS 6.8v212015-07-01
CVE-2015-0848 [MEDIUM] CWE-119 CVE-2015-0848: Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (c Heap-based buffer overflow in libwmf 0.2.8.4 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image.
nvd
CVE-2021-3756P3CRITICALCVSS 9.8v34v352021-10-29
CVE-2021-3756 [CRITICAL] CWE-122 CVE-2021-3756: libmysofa is vulnerable to Heap-based Buffer Overflow libmysofa is vulnerable to Heap-based Buffer Overflow
nvd
CVE-2023-2454P3HIGHCVSS 7.2v382023-06-09
CVE-2023-2454 [HIGH] CWE-20 CVE-2023-2454: schema_element defeats protective search_path changes; It was found that certain database calls in P schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
nvd
CVE-2020-6469P3CRITICALCVSS 9.6v31v322020-05-21
CVE-2020-6469 [CRITICAL] CWE-276 CVE-2020-6469: Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.
nvd
CVE-2019-7576P3HIGHCVSS 8.8v312019-02-07
CVE-2019-7576 [HIGH] CWE-125 CVE-2019-7576: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in InitMS_ADPCM in audio/SDL_wave.c (outside the wNumCoef loop).
nvd
CVE-2020-12674P3HIGHCVSS 7.5v31v32+1 more2020-08-12
CVE-2020-12674 [HIGH] CWE-125 CVE-2020-12674: In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service be In Dovecot before 2.3.11.3, sending a specially formatted RPA request will crash the auth service because a length of zero is mishandled.
nvd
CVE-2019-13619P3HIGHCVSS 7.5v29v302019-07-17
CVE-2019-13619 [HIGH] CWE-119 CVE-2019-13619: In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and relate In Wireshark 3.0.0 to 3.0.2, 2.6.0 to 2.6.9, and 2.4.0 to 2.4.15, the ASN.1 BER dissector and related dissectors could crash. This was addressed in epan/asn1.c by properly restricting buffer increments.
nvd
CVE-2020-11793P3HIGHCVSS 8.8v30v31+1 more2020-04-17
CVE-2020-11793 [HIGH] CWE-416 CVE-2020-11793: A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted we A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).
nvd
CVE-2022-23308P3HIGHCVSS 7.5v342022-02-26
CVE-2022-23308 [HIGH] CWE-416 CVE-2022-23308: valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes. valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.
nvd
CVE-2016-4540P3CRITICALCVSS 9.8v242016-05-22
CVE-2016-4540 [CRITICAL] CVE-2016-4540: The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x bef The grapheme_stripos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a negative offset.
nvd
CVE-2016-4541P3CRITICALCVSS 9.8v242016-05-22
CVE-2016-4541 [CRITICAL] CVE-2016-4541: The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x befo The grapheme_strpos function in ext/intl/grapheme/grapheme_string.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a negative offset.
nvd
CVE-2020-12723P3HIGHCVSS 7.5v312020-06-05
CVE-2020-12723 [HIGH] CWE-120 CVE-2020-12723: regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of regcomp.c in Perl before 5.30.3 allows a buffer overflow via a crafted regular expression because of recursive S_study_chunk calls.
nvd
CVE-2010-3441P3HIGHCVSS 7.5v142011-02-18
CVE-2010-3441 [HIGH] CWE-120 CVE-2010-3441: Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary Multiple buffer overflows in abcm2ps before 5.9.12 might allow remote attackers to execute arbitrary code via (1) a crafted input file, related to the PUT0 and PUT1 output macros; (2) a crafted input file, related to the trim_title function; and possibly (3) a long -O option on a command line.
nvd
CVE-2015-8383P3CRITICALCVSS 9.8v222015-12-02
CVE-2015-8383 [CRITICAL] CWE-119 CVE-2015-8383: PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to ca PCRE before 8.38 mishandles certain repeated conditional groups, which allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
nvd
CVE-2016-4542P3CRITICALCVSS 9.8v242016-05-22
CVE-2016-4542 [CRITICAL] CWE-119 CVE-2016-4542: The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and The exif_process_IFD_TAG function in ext/exif/exif.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 does not properly construct spprintf arguments, which allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via crafted header data.
nvd
CVE-2016-4537P3CRITICALCVSS 9.8v242016-05-22
CVE-2016-4537 [CRITICAL] CWE-20 CVE-2016-4537: The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x befo The bcpowmod function in ext/bcmath/bcmath.c in PHP before 5.5.35, 5.6.x before 5.6.21, and 7.x before 7.0.6 accepts a negative integer for the scale argument, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted call.
nvd
CVE-2018-19296P3HIGHCVSS 8.8v33v342018-11-16
CVE-2018-19296 [HIGH] CWE-502 CVE-2018-19296: PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack. PHPMailer before 5.2.27 and 6.x before 6.0.6 is vulnerable to an object injection attack.
nvd
Fedoraproject Fedora vulnerabilities | cvebase