Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 96 of 264
CVE-2021-30542P3HIGHCVSS 8.8v33v34+1 more2021-06-07
CVE-2021-30542 [HIGH] CWE-416 CVE-2021-30542: Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced
Use after free in Tab Strip in Google Chrome prior to 91.0.4472.77 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
nvd
CVE-2021-40153P3HIGHCVSS 8.1v34v332021-08-27
CVE-2021-40153 [HIGH] CWE-22 CVE-2021-40153: squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; t
squashfs_opendir in unsquash-1.c in Squashfs-Tools 4.5 stores the filename in the directory entry; this is then used by unsquashfs to create the new file during the unsquash. The filename is not validated for traversal outside of the destination directory, and thus allows writing to locations outside of the destination.
nvd
CVE-2023-36664P3HIGHCVSS 7.8v37v382023-06-25
CVE-2023-36664 [HIGH] CWE-552 CVE-2023-36664: Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pip
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
nvd
CVE-2019-15538P3HIGHCVSS 7.5v29v302019-08-25
CVE-2019-15538 [HIGH] CWE-400 CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.
An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local DoS attack vector, but it might result as well
nvd
CVE-2020-7238P3HIGHCVSS 7.5v332020-01-27
CVE-2020-7238 [HIGH] CVE-2020-7238: Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace
Netty 4.1.43.Final allows HTTP Request Smuggling because it mishandles Transfer-Encoding whitespace (such as a [space]Transfer-Encoding:chunked line) and a later Content-Length header. This issue exists because of an incomplete fix for CVE-2019-16869.
nvd
CVE-2020-29481P3HIGHCVSS 8.8v32v332020-12-15
CVE-2020-29481 [HIGH] CWE-269 CVE-2020-29481: An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfort
An issue was discovered in Xen through 4.14.x. Access rights of Xenstore nodes are per domid. Unfortunately, existing granted access rights are not removed when a domain is being destroyed. This means that a new domain created with the same domid will inherit the access rights to Xenstore nodes from the previous domain(s) with the same domid. Because
nvd
CVE-2020-14303P3HIGHCVSS 7.5v312020-07-06
CVE-2020-14303 [HIGH] CWE-834 CVE-2020-14303: A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and be
A flaw was found in the AD DC NBT server in all Samba versions before 4.10.17, before 4.11.11 and before 4.12.4. A samba user could send an empty UDP packet to cause the samba server to crash.
nvd
CVE-2021-28710P3HIGHCVSS 8.8v352021-11-21
CVE-2021-28710 [HIGH] CWE-269 CVE-2021-28710: certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translati
certain VT-d IOMMUs may not work in shared page table mode For efficiency reasons, address translation control structures (page tables) may (and, on suitable hardware, by default will) be shared between CPUs, for second-level translation (EPT), and IOMMUs. These page tables are presently set up to always be 4 levels deep. However, an IOMMU may require
nvd
CVE-2022-1616P3HIGHCVSS 7.8v34v35+1 more2022-05-07
CVE-2022-1616 [HIGH] CWE-416 CVE-2022-1616: Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability
Use after free in append_command in GitHub repository vim/vim prior to 8.2.4895. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
nvd
CVE-2020-10704P3HIGHCVSS 7.5v30v312020-05-06
CVE-2020-10704 [HIGH] CWE-674 CVE-2020-10704: A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba han
A flaw was found when using samba as an Active Directory Domain Controller. Due to the way samba handles certain requests as an Active Directory Domain Controller LDAP server, an unauthorized user can cause a stack overflow leading to a denial of service. The highest threat from this vulnerability is to system availability. This issue affects all samb
nvd
CVE-2020-24584P3HIGHCVSS 7.5v31v32+1 more2020-09-01
CVE-2020-24584 [HIGH] CWE-276 CVE-2020-24584: An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when P
An issue was discovered in Django 2.2 before 2.2.16, 3.0 before 3.0.10, and 3.1 before 3.1.1 (when Python 3.7+ is used). The intermediate-level directories of the filesystem cache had the system's standard umask rather than 0o077.
nvd
CVE-2020-12662P3HIGHCVSS 7.5v31v322020-05-19
CVE-2020-12662 [HIGH] CWE-400 CVE-2020-12662: Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue.
Unbound before 1.10.1 has Insufficient Control of Network Message Volume, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.
nvd
CVE-2022-1621P3HIGHCVSS 7.8v34v352022-05-10
CVE-2022-1621 [HIGH] CWE-122 CVE-2022-1621: Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This v
Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
nvd
CVE-2022-24735P3HIGHCVSS 7.8v34v35+1 more2022-04-27
CVE-2022-24735 [HIGH] CWE-94 CVE-2022-24735: Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script exe
Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another Redis user. The Lua script execution environment in Redis provides some measure
nvd
CVE-2017-5884P3HIGHCVSS 7.8v252017-02-28
CVE-2017-5884 [HIGH] CWE-118 CVE-2017-5884: gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allo
gtk-vnc before 0.7.0 does not properly check boundaries of subrectangle-containing tiles, which allows remote servers to execute arbitrary code via the src x, y coordinates in a crafted (1) rre, (2) hextile, or (3) copyrect tile.
nvd
CVE-2020-26890P3HIGHCVSS 7.5v32v332020-11-24
CVE-2020-26890 [HIGH] CWE-20 CVE-2020-26890: Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON valu
Matrix Synapse before 1.20.0 erroneously permits non-standard NaN, Infinity, and -Infinity JSON values in fields of m.room.member events, allowing remote attackers to execute a denial of service attack against the federation and common Matrix clients. If such a malformed event is accepted into the room's state, the impact is long-lasting and is not fix
nvd
CVE-2013-4751P3HIGHCVSS 8.1v18v192019-11-01
CVE-2013-4751 [HIGH] CWE-20 CVE-2013-4751: php-symfony2-Validator has loss of information during serialization
php-symfony2-Validator has loss of information during serialization
nvd
CVE-2021-29457P3HIGHCVSS 7.8v33v342021-04-19
CVE-2021-29457 [HIGH] CWE-122 CVE-2021-29457: Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the me
Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and modifying the metadata of image files. A heap buffer overflow was found in Exiv2 versions v0.27.3 and earlier. The heap overflow is triggered when Exiv2 is used to write metadata into a crafted image file. An attacker could potentially exploit the vulnerability to gain
nvd
CVE-2020-0181P3HIGHCVSS 7.5v32v332020-06-11
CVE-2020-0181 [HIGH] CWE-190 CVE-2020-0181: In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an int
In exif_data_load_data_thumbnail of exif-data.c, there is a possible denial of service due to an integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-145075076
nvd
CVE-2022-21680P3HIGHCVSS 7.5v362022-01-14
CVE-2022-21680 [HIGH] CWE-400 CVE-2022-21680: Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected.
nvd