cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 88 of 264
CVE-2020-25219P3HIGHCVSS 7.5v31v32+1 more2020-09-09
CVE-2020-25219 [HIGH] CWE-674 CVE-2020-25219: url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger unc url::recvline in url.cpp in libproxy 0.4.x through 0.4.15 allows a remote HTTP server to trigger uncontrolled recursion via a response composed of an infinite stream that lacks a newline character. This leads to stack exhaustion.
nvd
CVE-2020-26797P3HIGHCVSS 7.5v332021-03-18
CVE-2020-26797 [HIGH] CWE-787 CVE-2020-26797: Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf:: Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.
nvd
CVE-2021-38005P3HIGHCVSS 8.8v342021-12-23
CVE-2021-38005 [HIGH] CWE-416 CVE-2021-38005: Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potenti Use after free in loader in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-38006P3HIGHCVSS 8.8v342021-12-23
CVE-2021-38006 [HIGH] CWE-416 CVE-2021-38006: Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacke Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6539P3HIGHCVSS 8.8v332020-09-21
CVE-2020-6539 [HIGH] CWE-416 CVE-2020-6539: Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potential Use after free in CSS in Google Chrome prior to 84.0.4147.105 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30508P3HIGHCVSS 8.8v33v342021-06-04
CVE-2021-30508 [HIGH] CWE-787 CVE-2021-30508: Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who Heap buffer overflow in Media Feeds in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to enable certain features in Chrome to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-37997P3HIGHCVSS 8.8v342021-11-23
CVE-2021-37997 [HIGH] CWE-416 CVE-2021-37997: Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convi Use after free in Sign-In in Google Chrome prior to 95.0.4638.69 allowed a remote attacker who convinced a user to sign into Chrome to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30549P3HIGHCVSS 8.8v33v342021-06-15
CVE-2021-30549 [HIGH] CWE-416 CVE-2021-30549: Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convin Use after free in Spell check in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2019-18837P3HIGHCVSS 8.6v30v312019-11-13
CVE-2019-18837 [HIGH] CWE-59 CVE-2019-18837: An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whet An issue was discovered in crun before 0.10.5. With a crafted image, it doesn't correctly check whether a target is a symlink, resulting in access to files outside of the container. This occurs in libcrun/linux.c and libcrun/chroot_realpath.c.
nvd
CVE-2015-1779P3HIGHCVSS 8.6v21v222016-01-12
CVE-2015-1779 [HIGH] CWE-400 CVE-2015-1779: The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory The VNC websocket frame decoder in QEMU allows remote attackers to cause a denial of service (memory and CPU consumption) via a large (1) websocket payload or (2) HTTP headers section.
nvd
CVE-2016-9961P3CRITICALCVSS 9.8v24v252017-06-06
CVE-2016-9961 [CRITICAL] CWE-189 CVE-2016-9961: game-music-emu before 0.6.1 mishandles unspecified integer values. game-music-emu before 0.6.1 mishandles unspecified integer values.
nvd
CVE-2021-43860P3HIGHCVSS 8.6v352022-01-12
CVE-2021-43860 [HIGH] CWE-269 CVE-2021-43860: Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1 Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the case that there's a null byte in the metadata file of an app. Therefore app
nvd
CVE-2021-40401P3HIGHCVSS 8.6v362022-02-04
CVE-2021-40401 [HIGH] CWE-252 CVE-2021-40401: A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality A use-after-free vulnerability exists in the RS-274X aperture definition tokenization functionality of Gerbv 2.7.0 and dev (commit b5f1eacd) and Gerbv forked 2.7.1. A specially-crafted gerber file can lead to code execution. An attacker can provide a malicious file to trigger this vulnerability.
nvd
CVE-2021-38011P3HIGHCVSS 8.8v342021-12-23
CVE-2021-38011 [HIGH] CWE-416 CVE-2021-38011: Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacke Use after free in storage foundation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2022-2163P3HIGHCVSS 8.8v35v362022-07-28
CVE-2022-2163 [HIGH] CWE-416 CVE-2022-2163: Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker w Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction.
nvd
CVE-2020-11538P3HIGHCVSS 8.1v31v322020-06-25
CVE-2020-11538 [HIGH] CWE-125 CVE-2020-11538: In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the p In libImaging/SgiRleDecode.c in Pillow through 7.0.0, a number of out-of-bounds reads exist in the parsing of SGI image files, a different issue than CVE-2020-5311.
nvd
CVE-2023-2726P3HIGHCVSS 8.8v37v382023-05-16
CVE-2023-2726 [HIGH] CVE-2023-2726: Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2022-27191P3HIGHCVSS 7.5v34v35+1 more2022-03-18
CVE-2022-27191 [HIGH] CVE-2022-27191: The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attack The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.
nvd
CVE-2023-34153P3HIGHCVSS 7.8v37v382023-05-30
CVE-2023-34153 [HIGH] CWE-77 CVE-2023-34153: A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulner A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
nvd
CVE-2020-10745P3HIGHCVSS 7.5v312020-07-07
CVE-2020-10745 [HIGH] CWE-400 CVE-2020-10745: A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way i A flaw was found in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4 in the way it processed NetBios over TCP/IP. This flaw allows a remote attacker could to cause the Samba server to consume excessive CPU use, resulting in a denial of service. This highest threat from this vulnerability is to system availability.
nvd
Fedoraproject Fedora vulnerabilities | cvebase