cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 97 of 264
CVE-2021-21177P3MEDIUMCVSS 6.5v32v33+1 more2021-03-09
CVE-2021-21177 [MEDIUM] CWE-732 CVE-2021-21177: Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote Insufficient policy enforcement in Autofill in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page.
nvd
CVE-2019-16163P3HIGHCVSS 7.5v29v302019-09-09
CVE-2019-16163 [HIGH] CWE-674 CVE-2019-16163: Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c. Oniguruma before 6.9.3 allows Stack Exhaustion in regcomp.c because of recursion in regparse.c.
nvd
CVE-2020-10725P3HIGHCVSS 7.7v322020-05-20
CVE-2020-10725 [HIGH] CWE-665 CVE-2020-10725: A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentati A flaw was found in DPDK version 19.11 and above that allows a malicious guest to cause a segmentation fault of the vhost-user backend application running on the host, which could result in a loss of connectivity for the other guests running on that host. This is caused by a missing validity check of the descriptor address in the function `virtio_dev_
nvd
CVE-2020-14148P3HIGHCVSS 7.5v31v322020-06-15
CVE-2020-14148 [HIGH] CWE-125 CVE-2020-14148: The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as The Server-Server protocol implementation in ngIRCd before 26~rc2 allows an out-of-bounds access, as demonstrated by the IRC_NJOIN() function.
nvd
CVE-2020-35524P3HIGHCVSS 7.8v332021-03-09
CVE-2020-35524 [HIGH] CWE-787 CVE-2020-35524: A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's T A heap-based buffer overflow flaw was found in libtiff in the handling of TIFF images in libtiff's TIFF2PDF tool. A specially crafted TIFF file can lead to arbitrary code execution. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
nvd
CVE-2019-18218P3HIGHCVSS 7.8v29v30+1 more2019-10-21
CVE-2019-18218 [HIGH] CWE-787 CVE-2019-18218: cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elem cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).
nvd
CVE-2019-16786P3HIGHCVSS 7.5v30v312019-12-20
CVE-2019-16786 [HIGH] CWE-444 CVE-2019-16786: Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single s Waitress through version 1.3.1 would parse the Transfer-Encoding header and only look for a single string value, if that value was not chunked it would fall through and use the Content-Length header instead. According to the HTTP standard Transfer-Encoding should be a comma separated list, with the inner-most encoding first, followed by any further tr
nvd
CVE-2019-3839P3HIGHCVSS 7.8v29v302019-05-16
CVE-2019-3839 [HIGH] CWE-648 CVE-2019-3839: It was found that in ghostscript some privileged operators remained accessible from various places a It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by -dSAFER. Ghostscript versions before 9.27 are vulnerable.
nvd
CVE-2022-3140P3MEDIUMCVSS 6.3v352022-10-11
CVE-2022-3140 [MEDIUM] CWE-20 CVE-2022-3140: LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePo LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed to call internal macros with arbitrary arguments. Which when clicked on, or
nvd
CVE-2019-17545P3CRITICALCVSS 9.8v30v312019-10-14
CVE-2019-17545 [CRITICAL] CWE-415 CVE-2019-17545: GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10 GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
nvd
CVE-2021-39240P3HIGHCVSS 7.5v33v342021-08-17
CVE-2021-39240 [HIGH] CVE-2021-39240: An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It do An issue was discovered in HAProxy 2.2 before 2.2.16, 2.3 before 2.3.13, and 2.4 before 2.4.3. It does not ensure that the scheme and path portions of a URI have the expected characters. For example, the authority field (as observed on a target HTTP/2 server) might differ from what the routing rules were intended to achieve.
nvd
CVE-2022-31116P3HIGHCVSS 7.5v35v362022-07-05
CVE-2022-31116 [HIGH] CWE-670 CVE-2022-31116: UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affect UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Affected versions were found to improperly decode certain characters. JSON strings that contain escaped surrogate characters not part of a proper surrogate pair were decoded incorrectly. Besides corrupting strings, this allowed for potential key confusion and
nvd
CVE-2020-8151P3HIGHCVSS 7.5v332020-05-12
CVE-2020-8151 [HIGH] CWE-200 CVE-2020-8151: There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an atta There is a possible information disclosure issue in Active Resource <v5.1.1 that could allow an attacker to create specially crafted requests to access data in an unexpected way and possibly leak information.
nvd
CVE-2018-17825P3CRITICALCVSS 9.8v32v332018-10-01
CVE-2018-17825 [CRITICAL] CWE-415 CVE-2018-17825: An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuop An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE, and VIB_TABLE.
nvd
CVE-2014-8109P3MEDIUMCVSS 4.3v212014-12-29
CVE-2014-8109 [MEDIUM] CWE-863 CVE-2014-8109: mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not su mod_lua.c in the mod_lua module in the Apache HTTP Server 2.3.x and 2.4.x through 2.4.10 does not support an httpd configuration in which the same Lua authorization provider is used with different arguments within different contexts, which allows remote attackers to bypass intended access restrictions in opportunistic circumstances by leveraging multi
nvd
CVE-2023-38403P3HIGHCVSS 7.5v37v382023-07-17
CVE-2023-38403 [HIGH] CWE-190 CVE-2023-38403: iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted lengt iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
nvd
CVE-2018-17189P3MEDIUMCVSS 5.3v28v292019-01-30
CVE-2018-17189 [MEDIUM] CWE-400 CVE-2018-17189: In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to pl In Apache HTTP server versions 2.4.37 and prior, by sending request bodies in a slow loris way to plain resources, the h2 stream for that request unnecessarily occupied a server thread cleaning up that incoming data. This affects only HTTP/2 (mod_http2) connections.
nvd
CVE-2022-28131P3HIGHCVSS 7.5v352022-08-10
CVE-2022-28131 [HIGH] CWE-674 CVE-2022-28131: Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an att Uncontrolled recursion in Decoder.Skip in encoding/xml before Go 1.17.12 and Go 1.18.4 allows an attacker to cause a panic due to stack exhaustion via a deeply nested XML document.
nvd
CVE-2020-4067P3HIGHCVSS 7.5v31v322020-06-29
CVE-2020-4067 [HIGH] CWE-665 CVE-2020-4067: In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initial In coturn before version 4.5.1.3, there is an issue whereby STUN/TURN response buffer is not initialized properly. There is a leak of information between different client connections. One client (an attacker) could use their connection to intelligently query coturn to get interesting bytes in the padding bytes from the connection of another client. This
nvd
CVE-2022-39377P3HIGHCVSS 7.8v35v36+1 more2022-11-08
CVE-2022-39377 [HIGH] CWE-120 CVE-2022-39377: sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in v sysstat is a set of system performance tools for the Linux operating system. On 32 bit systems, in versions 9.1.16 and newer but prior to 12.7.1, allocate_structures contains a size_t overflow in sa_common.c. The allocate_structures function insufficiently checks bounds before arithmetic multiplication, allowing for an overflow in the size allocated f
nvd
Fedoraproject Fedora vulnerabilities | cvebase