cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 95 of 264
CVE-2021-30507P3HIGHCVSS 8.8v33v342021-06-04
CVE-2021-30507 [HIGH] CWE-829 CVE-2021-30507: Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a Inappropriate implementation in Offline in Google Chrome on Android prior to 90.0.4430.212 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
nvd
CVE-2021-41771P3HIGHCVSS 7.5v34v352021-11-08
CVE-2021-41771 [HIGH] CWE-119 CVE-2021-41771: ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 A ImportedSymbols in debug/macho (for Open or OpenFat) in Go before 1.16.10 and 1.17.x before 1.17.3 Accesses a Memory Location After the End of a Buffer, aka an out-of-bounds slice situation.
nvd
CVE-2015-8393P3HIGHCVSS 7.5v222015-12-02
CVE-2015-8393 [HIGH] CWE-200 CVE-2015-8393: pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote att pcregrep in PCRE before 8.38 mishandles the -q option for binary files, which might allow remote attackers to obtain sensitive information via a crafted file, as demonstrated by a CGI script that sends stdout data to a client.
nvd
CVE-2020-28196P3HIGHCVSS 7.5v312020-11-06
CVE-2020-28196 [HIGH] CWE-674 CVE-2020-28196: MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an A MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.
nvd
CVE-2021-30529P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30529 [HIGH] CWE-416 CVE-2021-30529: Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced Use after free in Bookmarks in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2012-5645P3HIGHCVSS 7.5v16v17+1 more2019-12-30
CVE-2012-5645 [HIGH] CWE-400 CVE-2012-5645: A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed A denial of service flaw was found in the way the server component of Freeciv before 2.3.4 processed certain packets. A remote attacker could send a specially-crafted packet that, when processed would lead to memory exhaustion or excessive CPU consumption.
nvd
CVE-2021-30526P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30526 [HIGH] CWE-787 CVE-2021-30526: Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convi Out of bounds write in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
nvd
CVE-2021-30552P3HIGHCVSS 8.8v33v342021-06-15
CVE-2021-30552 [HIGH] CWE-416 CVE-2021-30552: Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinc Use after free in Extensions in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30527P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30527 [HIGH] CWE-416 CVE-2021-30527: Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a u Use after free in WebUI in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30524P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30524 [HIGH] CWE-416 CVE-2021-30524: Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced Use after free in TabStrip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-4052P3HIGHCVSS 8.8v342021-12-23
CVE-2021-4052 [HIGH] CWE-416 CVE-2021-4052: Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced Use after free in web apps in Google Chrome prior to 96.0.4664.93 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
nvd
CVE-2022-28327P3HIGHCVSS 7.5v34v35+1 more2022-04-20
CVE-2022-28327 [HIGH] CVE-2022-28327: The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a p The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.
nvd
CVE-2021-30525P3HIGHCVSS 8.8v33v342021-06-07
CVE-2021-30525 [HIGH] CWE-416 CVE-2021-30525: Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced Use after free in TabGroups in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30550P3HIGHCVSS 8.8v33v342021-06-15
CVE-2021-30550 [HIGH] CWE-416 CVE-2021-30550: Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who conv Use after free in Accessibility in Google Chrome prior to 91.0.4472.101 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30509P3HIGHCVSS 8.8v33v342021-06-04
CVE-2021-30509 [HIGH] CWE-787 CVE-2021-30509: Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who con Out of bounds write in Tab Strip in Google Chrome prior to 90.0.4430.212 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page and a crafted Chrome extension.
nvd
CVE-2022-3046P3HIGHCVSS 8.8v372022-09-26
CVE-2022-3046 [HIGH] CWE-416 CVE-2022-3046: Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convin Use after free in Browser Tag in Google Chrome prior to 105.0.5195.52 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-38016P3HIGHCVSS 8.8v342021-12-23
CVE-2021-38016 [HIGH] CWE-863 CVE-2021-38016: Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a Insufficient policy enforcement in background fetch in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass same origin policy via a crafted HTML page.
nvd
CVE-2021-38017P3HIGHCVSS 8.8v342021-12-23
CVE-2021-38017 [HIGH] CWE-863 CVE-2021-38017: Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a r Insufficient policy enforcement in iframe sandbox in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
nvd
CVE-2021-30543P3HIGHCVSS 8.8v33v34+1 more2021-06-07
CVE-2021-30543 [HIGH] CWE-416 CVE-2021-30543: Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-30542P3HIGHCVSS 8.8v33v34+1 more2021-06-07
CVE-2021-30542 [HIGH] CWE-416 CVE-2021-30542: Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
Fedoraproject Fedora vulnerabilities | cvebase