cbcvebase.

Fedoraproject Fedora vulnerabilities

5,279 known vulnerabilities affecting fedoraproject/fedora.

Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173

Vulnerabilities

Page 98 of 264
CVE-2021-23240P3HIGHCVSS 7.8v32v332021-01-12
CVE-2021-23240 [HIGH] CWE-59 CVE-2021-23240: selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain f selinux_edit_copy_tfiles in sudoedit in Sudo before 1.9.5 allows a local unprivileged user to gain file ownership and escalate privileges by replacing a temporary file with a symlink to an arbitrary file target. This affects SELinux RBAC support in permissive mode. Machines without SELinux are not vulnerable.
nvd
CVE-2022-24122P3HIGHCVSS 7.8v34v352022-01-29
CVE-2022-24122 [HIGH] CWE-416 CVE-2022-24122: kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabl kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
nvd
CVE-2021-28089P3HIGHCVSS 7.5v332021-03-19
CVE-2021-28089 [HIGH] CWE-400 CVE-2021-28089: Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resource Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.
nvd
CVE-2023-3354P3HIGHCVSS 7.5v382023-07-11
CVE-2023-3354 [HIGH] CWE-476 CVE-2023-3354: A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU che A flaw was found in the QEMU built-in VNC server. When a client connects to the VNC server, QEMU checks whether the current number of connections crosses a certain threshold and if so, cleans up the previous connection. If the previous connection happens to be in the handshake phase and fails, QEMU cleans up the connection again, resulting in a NULL poi
nvd
CVE-2020-25699P3HIGHCVSS 7.5v32v332020-11-19
CVE-2020-25699 [HIGH] CWE-863 CVE-2020-25699: In moodle, insufficient capability checks could lead to users with the ability to course restore add In moodle, insufficient capability checks could lead to users with the ability to course restore adding additional capabilities to roles within that course. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.9.3, 3.8.6, 3.7.9, 3.5.15, and 3.10.
nvd
CVE-2022-42720P3HIGHCVSS 7.8v36v372022-10-14
CVE-2022-42720 [HIGH] CWE-416 CVE-2022-42720: Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 thr Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
nvd
CVE-2019-7221P3HIGHCVSS 7.8v28v292019-03-21
CVE-2019-7221 [HIGH] CWE-416 CVE-2019-7221: The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free. The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.
nvd
CVE-2024-27398P3HIGHCVSS 7.8v39v402024-05-14
CVE-2024-27398 [HIGH] CWE-416 CVE-2024-27398: In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free b In the Linux kernel, the following vulnerability has been resolved: Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout When the sco connection is established and then, the sco socket is releasing, timeout_work will be scheduled to judge whether the sco disconnection is timeout. The sock will be deallocated later, but it is dereferenced aga
nvd
CVE-2020-15115P3HIGHCVSS 7.5v322020-08-06
CVE-2020-15115 [HIGH] CWE-521 CVE-2020-15115: etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows etcd before versions 3.3.23 and 3.4.10 does not perform any password length validation, which allows for very short passwords, such as those with a length of one. This may allow an attacker to guess or brute-force users' passwords with little computational effort.
nvd
CVE-2022-45188P3HIGHCVSS 7.8v36v37+1 more2022-11-12
CVE-2022-45188 [HIGH] CWE-787 CVE-2022-45188: Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution vi Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
nvd
CVE-2023-39354P3HIGHCVSS 7.5v37v38+1 more2023-08-31
CVE-2023-39354 [HIGH] CWE-125 CVE-2023-39354: FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache lic FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. Affected versions are subject to an Out-Of-Bounds Read in the `nsc_rle_decompress_data` function. The Out-Of-Bounds Read occurs because it processes `context->Planes` without checking if it contains data of sufficient length. Should an attacker be
nvd
CVE-2016-1521P3HIGHCVSS 8.8v22v232016-02-13
CVE-2016-1521 [HIGH] CWE-119 CVE-2016-1521: The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla F The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application cras
nvd
CVE-2022-25271P3HIGHCVSS 7.5v35v362022-02-16
CVE-2022-25271 [HIGH] CWE-20 CVE-2022-25271: Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker could alter critical or sensitive data.
nvd
CVE-2019-20044P3HIGHCVSS 7.8v30v312020-02-24
CVE-2019-20044 [HIGH] CWE-273 CVE-2019-20044: In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIV In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls setuid().
nvd
CVE-2023-5679P3HIGHCVSS 7.5v38v392024-02-13
CVE-2023-5679 [HIGH] CWE-617 CVE-2023-5679: A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, 9.16.12-S1 through 9.16.45-S1, and 9.18.11-S1 through 9.18.21-S1.
nvd
CVE-2021-35269P3HIGHCVSS 7.8v33v352021-09-07
CVE-2021-35269 [HIGH] CWE-787 CVE-2021-35269: NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the f NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
nvd
CVE-2021-35268P3HIGHCVSS 7.8v33v352021-09-07
CVE-2021-35268 [HIGH] CWE-787 CVE-2021-35268: In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_ In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.
nvd
CVE-2021-3847P3HIGHCVSS 7.8v342022-04-01
CVE-2021-3847 [HIGH] CWE-281 CVE-2021-3847: An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kerne An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.
nvd
CVE-2022-1941P3HIGHCVSS 7.5v36v372022-09-22
CVE-2022-1941 [HIGH] CWE-1286 CVE-2022-1941: A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and includi A parsing vulnerability for the MessageSet type in the ProtocolBuffers versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 3.21.5 for protobuf-cpp, and versions prior to and including 3.16.1, 3.17.3, 3.18.2, 3.19.4, 3.20.1 and 4.21.5 for protobuf-python can lead to out of memory failures. A specially crafted message with multiple
nvd
CVE-2022-3705P3HIGHCVSS 7.5v35v362022-10-26
CVE-2022-3705 [HIGH] CWE-119 CVE-2022-3705: A vulnerability was found in vim and classified as problematic. Affected by this issue is the functi A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version 9.0.0805 is able to address this issue. The name of the patch is d0fab10ed2a86
nvd
Fedoraproject Fedora vulnerabilities | cvebase