cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 90 of 264
CVE-2023-31122P3HIGHCVSS 7.5v382023-10-23
CVE-2023-31122 [HIGH] CWE-125 CVE-2023-31122: Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP S Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.
nvd
CVE-2020-12066P3HIGHCVSS 7.5v302020-04-22
CVE-2020-12066 [HIGH] CWE-20 CVE-2020-12066: CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers CServer::SendMsg in engine/server/server.cpp in Teeworlds 0.7.x before 0.7.5 allows remote attackers to shut down the server.
nvd
CVE-2019-3994P3HIGHCVSS 7.5v30v312019-12-17
CVE-2019-3994 [HIGH] CWE-416 CVE-2019-3994: ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after fre ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a use after free. A remote unauthenticated attacker can crash the ELOG server by sending multiple HTTP POST requests which causes the ELOG function retrieve_url() to use a freed variable.
nvd
CVE-2022-0114P3HIGHCVSS 8.1v34v35+1 more2022-02-12
CVE-2022-0114 [HIGH] CWE-125 CVE-2022-0114: Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a rem Out of bounds memory access in Blink Serial API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page and virtual serial port driver.
nvd
CVE-2023-35934P3HIGHCVSS 8.2v37v382023-07-06
CVE-2023-35934 [HIGH] CWE-200 CVE-2023-35934: yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp yt-dlp is a command-line program to download videos from video sites. During file downloads, yt-dlp or the external downloaders that yt-dlp employs may leak cookies on HTTP redirects to a different host, or leak them when the host for download fragments differs from their parent manifest's host. This vulnerable behavior is present in yt-dlp prior to 20
nvd
CVE-2023-4761P3HIGHCVSS 8.1v37v38+1 more2023-09-05
CVE-2023-4761 [HIGH] CWE-125 CVE-2023-4761: Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attac Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
nvd
CVE-2021-3610P3HIGHCVSS 7.5v342022-02-24
CVE-2021-3610 [HIGH] CWE-125 CVE-2021-3610: A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 i A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.
nvd
CVE-2021-45444P3HIGHCVSS 7.8v34v352022-02-14
CVE-2021-45444 [HIGH] CVE-2021-45444: In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.
nvd
CVE-2020-25710P3HIGHCVSS 7.5v332021-05-28
CVE-2020-25710 [HIGH] CWE-617 CVE-2020-25710: A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a mal A flaw was found in OpenLDAP in versions before 2.4.56. This flaw allows an attacker who sends a malicious packet processed by OpenLDAP to force a failed assertion in csnNormalize23(). The highest threat from this vulnerability is to system availability.
nvd
CVE-2024-1931P3HIGHCVSS 7.5v38v39+1 more2024-03-07
CVE-2024-1931 [HIGH] CWE-835 CVE-2024-1931: NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that ca NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher than the client's advertised buffer size. Before removing all the EDE records
nvd
CVE-2022-45061P3HIGHCVSS 7.5v35v36+1 more2022-11-09
CVE-2022-45061 [HIGH] CWE-407 CVE-2022-45061: An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one pa An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote servers that could be controlled by a
nvd
CVE-2022-0725P3HIGHCVSS 7.5v352022-03-10
CVE-2022-0725 [HIGH] CWE-200 CVE-2022-0725: A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in sys A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.
nvd
CVE-2022-24729P3HIGHCVSS 7.5v36v372022-03-16
CVE-2022-24729 [HIGH] CWE-400 CVE-2022-24729: CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.1 CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop resulting in a browser tab freeze. A patch is available in version 4.18.0.
nvd
CVE-2015-7827P3HIGHCVSS 7.5v242016-05-13
CVE-2015-7827 [HIGH] CWE-200 CVE-2015-7827: Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct millio Botan before 1.10.13 and 1.11.x before 1.11.22 make it easier for remote attackers to conduct million-message attacks by measuring time differences, related to decoding of PKCS#1 padding.
nvd
CVE-2022-20001P3HIGHCVSS 7.8v35v362022-03-14
CVE-2022-20001 [HIGH] CWE-74 CVE-2022-20001: fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary co fish is a command line shell. fish version 3.1.0 through version 3.3.1 is vulnerable to arbitrary code execution. git repositories can contain per-repository configuration that change the behavior of git, including running arbitrary commands. When using the default configuration of fish, changing to a directory automatically runs `git` commands in orde
nvd
CVE-2013-4572P3HIGHCVSS 7.5v18v192020-02-06
CVE-2013-4572 [HIGH] CWE-384 CVE-2013-4572: The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.2 The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows remote attackers to authenticate as the created user.
nvd
CVE-2015-1854P3HIGHCVSS 7.5v222017-09-19
CVE-2015-1854 [HIGH] CWE-284 CVE-2015-1854: 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and mod 389 Directory Server before 1.3.3.10 allows attackers to bypass intended access restrictions and modify directory entries via a crafted ldapmodrdn call.
nvd
CVE-2021-3347P3HIGHCVSS 7.8v32v332021-01-29
CVE-2021-3347 [HIGH] CWE-416 CVE-2021-3347: An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-afte An issue was discovered in the Linux kernel through 5.10.11. PI futexes have a kernel stack use-after-free during fault handling, allowing local users to execute code in the kernel, aka CID-34b1a1ce1458.
nvd
CVE-2020-27918P3HIGHCVSS 7.8v32v33+1 more2020-12-08
CVE-2020-27918 [HIGH] CWE-416 CVE-2020-27918: A use after free issue was addressed with improved memory management. This issue is fixed in macOS B A use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 14.2 and iPadOS 14.2, iCloud for Windows 11.5, Safari 14.0.1, tvOS 14.2, iTunes 12.11 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
nvd
CVE-2024-32004P3HIGHCVSS 7.8v402024-05-14
CVE-2024-32004 [HIGH] CWE-114 CVE-2024-32004: Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, Git is a revision control system. Prior to versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4, an attacker can prepare a local repository in such a way that, when cloned, will execute arbitrary code during the operation. The problem has been patched in versions 2.45.1, 2.44.1, 2.43.4, 2.42.2, 2.41.1, 2.40.2, and 2.39.4. As a workaround
nvd
Fedoraproject Fedora vulnerabilities | cvebase