cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 94 of 264
CVE-2015-1858P3MEDIUMCVSS 6.8v20v21+1 more2015-05-12
CVE-2015-1858 [MEDIUM] CWE-119 CVE-2015-1858: Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5 Multiple buffer overflows in gui/image/qbmphandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted BMP image.
nvd
CVE-2015-1859P3MEDIUMCVSS 6.8v20v21+1 more2015-05-12
CVE-2015-1859 [MEDIUM] CWE-119 CVE-2015-1859: Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt bef Multiple buffer overflows in plugins/imageformats/ico/qicohandler.cpp in the QtBase module in Qt before 4.8.7 and 5.x before 5.4.2 allow remote attackers to cause a denial of service (segmentation fault and crash) and possibly execute arbitrary code via a crafted ICO image.
nvd
CVE-2019-18678P3MEDIUMCVSS 5.3v30v312019-11-26
CVE-2019-18678 [MEDIUM] CWE-444 CVE-2019-18678: An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP reques An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid) with attacker-controlled content at arbitrary URLs. Effects are isolated to
nvd
CVE-2020-11080P3HIGHCVSS 7.5v31v332020-06-03
CVE-2020-11080 [HIGH] CWE-707 CVE-2020-11080: In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of se In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a length of 14,400 bytes (2400 individual settings entries) over and over again. The attack causes the CPU to spike at 100%. nghttp2 v1.41.0 fixes this vul
nvd
CVE-2019-17498P3HIGHCVSS 8.1v30v312019-10-21
CVE-2019-17498 [HIGH] CWE-190 CVE-2019-17498: In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer over In libssh2 v1.9.0 and earlier versions, the SSH_MSG_DISCONNECT logic in packet.c has an integer overflow in a bounds check, enabling an attacker to specify an arbitrary (out-of-bounds) offset for a subsequent memory read. A crafted SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when
nvd
CVE-2021-39922P3HIGHCVSS 7.5v34v352021-11-19
CVE-2021-39922 [HIGH] CWE-120 CVE-2021-39922: Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denia Buffer overflow in the C12.22 dissector in Wireshark 3.4.0 to 3.4.9 and 3.2.0 to 3.2.17 allows denial of service via packet injection or crafted capture file
nvd
CVE-2020-24606P3HIGHCVSS 7.5v31v32+1 more2020-08-24
CVE-2020-24606 [HIGH] CWE-667 CVE-2020-24606: Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consumi Squid before 4.13 and 5.x before 5.0.4 allows a trusted peer to perform Denial of Service by consuming all available CPU cycles during handling of a crafted Cache Digest response message. This only occurs when cache_peer is used with the cache digests feature. The problem exists because peerDigestHandleReply() livelocking in peer_digest.cc mishandles
nvd
CVE-2012-6129P3HIGHCVSS 7.5v162013-04-03
CVE-2012-6129 [HIGH] CWE-119 CVE-2012-6129: Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly o Stack-based buffer overflow in utp.cpp in libutp, as used in Transmission before 2.74 and possibly other products, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted "micro transport protocol packets."
nvd
CVE-2022-28042P3HIGHCVSS 8.8v34v35+1 more2022-04-15
CVE-2022-28042 [HIGH] CWE-416 CVE-2022-28042: stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
nvd
CVE-2019-14744P3HIGHCVSS 7.8v29v302019-08-07
CVE-2019-14744 [HIGH] CWE-78 CVE-2019-14744: In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to cod In KDE Frameworks KConfig before 5.61.0, malicious desktop files and configuration files lead to code execution with minimal user interaction. This relates to libKF5ConfigCore.so, and the mishandling of .desktop and .directory files, as demonstrated by a shell command on an Icon line in a .desktop file.
nvd
CVE-2019-13736P3HIGHCVSS 8.8v30v312019-12-10
CVE-2019-13736 [HIGH] CWE-190 CVE-2019-13736: Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to poten Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
nvd
CVE-2019-13727P3HIGHCVSS 8.8v30v312019-12-10
CVE-2019-13727 [HIGH] CWE-281 CVE-2019-13727: Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remot Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2020-6454P3HIGHCVSS 8.8v30v31+1 more2020-04-13
CVE-2020-6454 [HIGH] CWE-416 CVE-2020-6454: Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convince Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2015-4047P3HIGHCVSS 7.8v20v212015-05-29
CVE-2015-4047 [HIGH] CWE-476 CVE-2015-4047: racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL poin racoon/gssapi.c in IPsec-Tools 0.8.2 allows remote attackers to cause a denial of service (NULL pointer dereference and IKE daemon crash) via a series of crafted UDP requests.
nvd
CVE-2019-5824P3HIGHCVSS 8.8v29v302019-06-27
CVE-2019-5824 [HIGH] CWE-787 CVE-2019-5824: Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker t Parameter passing error in media in Google Chrome prior to 74.0.3729.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2020-6420P3HIGHCVSS 8.8v302020-03-23
CVE-2020-6420 [HIGH] CVE-2020-6420: Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote at Insufficient policy enforcement in media in Google Chrome prior to 80.0.3987.132 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2019-11287P3HIGHCVSS 7.5v30v312019-11-23
CVE-2019-11287 [HIGH] CWE-400 CVE-2019-11287: Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Pivotal RabbitMQ, versions 3.7.x prior to 3.7.21 and 3.8.x prior to 3.8.1, and RabbitMQ for Pivotal Platform, 1.16.x versions prior to 1.16.7 and 1.17.x versions prior to 1.17.4, contain a web management plugin that is vulnerable to a denial of service attack. The "X-Reason" HTTP Header can be leveraged to insert a malicious Erlang format string that w
nvd
CVE-2018-1098P3HIGHCVSS 8.8v302018-04-03
CVE-2018-1098 [HIGH] CWE-352 CVE-2018-1098: A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a webs A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.
nvd
CVE-2021-22880P3HIGHCVSS 7.5v32v332021-02-11
CVE-2021-22880 [HIGH] CWE-400 CVE-2021-22880: The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expr The PostgreSQL adapter in Active Record before 6.1.2.1, 6.0.3.5, 5.2.4.5 suffers from a regular expression denial of service (REDoS) vulnerability. Carefully crafted input can cause the input validation in the `money` type of the PostgreSQL adapter in Active Record to spend too much time in a regular expression, resulting in the potential for a DoS at
nvd
CVE-2020-6379P3HIGHCVSS 8.8v302020-02-11
CVE-2020-6379 [HIGH] CWE-416 CVE-2020-6379: Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentiall Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
nvd
Fedoraproject Fedora vulnerabilities | cvebase