Fedoraproject Fedora vulnerabilities
5,279 known vulnerabilities affecting fedoraproject/fedora.
Total CVEs
5,279
CISA KEV
85
actively exploited
Public exploits
169
Exploited in wild
139
Severity breakdown
CRITICAL515HIGH2326MEDIUM2265LOW173
Vulnerabilities
Page 99 of 264
CVE-2023-20900P3HIGHCVSS 7.5v37v38+1 more2023-08-31
CVE-2023-20900 [HIGH] CWE-294 CVE-2023-20900: A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMwar
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.co
nvd
CVE-2021-4120P3HIGHCVSS 7.8v34v352022-02-17
CVE-2021-4120 [HIGH] CWE-20 CVE-2021-4120: snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resu
snapd 2.54.2 fails to perform sufficient validation of snap content interface and layout paths, resulting in the ability for snaps to inject arbitrary AppArmor policy rules via malformed content interface and layout declarations and hence escape strict snap confinement. Fixed in snapd versions 2.54.3+18.04, 2.54.3+20.04 and 2.54.3+21.10.1
nvd
CVE-2024-32660P3HIGHCVSS 7.5v38v39+1 more2024-04-23
CVE-2024-32660 [HIGH] CWE-770 CVE-2024-32660: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending invalid huge allocation size. Version 3.5.1 contains a patch for the issue. No known workarounds are available.
nvd
CVE-2023-46838P3HIGHCVSS 7.5v38v392024-01-29
CVE-2023-46838 [HIGH] CWE-476 CVE-2023-46838: Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really
Transmit requests in Xen's virtual network protocol can consist of
multiple parts. While not really useful, except for the initial part
any of them may be of zero length, i.e. carry no data at all. Besides a
certain initial portion of the to be transferred data, these parts are
directly translated into what Linux calls SKB fragments. Such converted
req
nvd
CVE-2022-0330P3HIGHCVSS 7.8v34v352022-03-25
CVE-2022-0330 [HIGH] CWE-281 CVE-2022-0330: A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in
A random memory access flaw was found in the Linux kernel's GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system.
nvd
CVE-2023-50008P3HIGHCVSS 7.8v38v39+1 more2024-04-19
CVE-2023-50008 [HIGH] CWE-120 CVE-2023-50008: FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_
FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.
nvd
CVE-2021-33200P3HIGHCVSS 7.8v33v342021-05-27
CVE-2021-33200 [HIGH] CWE-787 CVE-2021-33200: kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arith
kernel/bpf/verifier.c in the Linux kernel through 5.12.7 enforces incorrect limits for pointer arithmetic operations, aka CID-bb01a1bba579. This can be abused to perform out-of-bounds reads and writes in kernel memory, leading to local privilege escalation to root. In particular, there is a corner case where the off reg causes a masking direction chan
nvd
CVE-2022-1998P3HIGHCVSS 7.8v352022-06-09
CVE-2022-1998 [HIGH] CWE-416 CVE-2022-1998: A use after free in the Linux kernel File System notify functionality was found in the way user trig
A use after free in the Linux kernel File System notify functionality was found in the way user triggers copy_info_records_to_user() call to fail in copy_event_to_user(). A local user could use this flaw to crash the system or potentially escalate their privileges on the system.
nvd
CVE-2022-42335P3HIGHCVSS 7.8v382023-04-25
CVE-2022-42335 [HIGH] CWE-476 CVE-2022-42335: x86 shadow paging arbitrary pointer dereference In environments where host assisted address translat
x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the hypervisor routines used for shadow page handling it is possible for a guest with a PCI device passed
nvd
CVE-2023-39197P3HIGHCVSS 7.5v382024-01-23
CVE-2023-39197 [HIGH] CWE-125 CVE-2023-39197: An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Li
An out-of-bounds read vulnerability was found in Netfilter Connection Tracking (conntrack) in the Linux kernel. This flaw allows a remote user to disclose sensitive information via the DCCP protocol.
nvd
CVE-2023-27320P3HIGHCVSS 7.2v36v37+1 more2023-02-28
CVE-2023-27320 [HIGH] CWE-415 CVE-2023-27320: Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
nvd
CVE-2019-19204P3HIGHCVSS 7.5v30v312019-11-21
CVE-2019-19204 [HIGH] CWE-125 CVE-2019-19204: An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier
An issue was discovered in Oniguruma 6.x before 6.9.4_rc2. In the function fetch_interval_quantifier (formerly known as fetch_range_quantifier) in regparse.c, PFETCH is called without checking PEND. This leads to a heap-based buffer over-read.
nvd
CVE-2019-16775P3MEDIUMCVSS 6.5v312019-12-13
CVE-2019-16775 [MEDIUM] CWE-61 CVE-2019-16775: Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible fo
Versions of the npm CLI prior to 6.13.3 are vulnerable to an Arbitrary File Write. It is possible for packages to create symlinks to files outside of thenode_modules folder through the bin field upon installation. A properly constructed entry in the package.json bin field would allow a package publisher to create a symlink pointing to arbitrary files
nvd
CVE-2018-16227P3HIGHCVSS 7.5v29v30+1 more2019-10-03
CVE-2018-16227 [HIGH] CWE-125 CVE-2018-16227: The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh
The IEEE 802.11 parser in tcpdump before 4.9.3 has a buffer over-read in print-802_11.c for the Mesh Flags subfield.
nvd
CVE-2019-5759P3CRITICALCVSS 9.6v29v302019-02-19
CVE-2019-5759 [CRITICAL] CWE-416 CVE-2019-5759: Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.
Incorrect lifetime handling in HTML select elements in Google Chrome on Android and Mac prior to 72.0.3626.81 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
nvd
CVE-2023-34058P3HIGHCVSS 7.5v37v38+1 more2023-10-27
CVE-2023-34058 [HIGH] CWE-347 CVE-2023-34058: VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been g
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been a
nvd
CVE-2023-29483P3HIGHCVSS 7.0v38v39+1 more2024-04-11
CVE-2023-29483 [HIGH] CWE-292 CVE-2023-29483: eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, withi
nvd
CVE-2024-0804P3HIGHCVSS 7.5v38v392024-01-24
CVE-2024-0804 [HIGH] CWE-693 CVE-2024-0804: Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
nvd
CVE-2019-7638P3HIGHCVSS 8.8v312019-02-08
CVE-2019-7638 [HIGH] CWE-125 CVE-2019-7638: SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-rea
SDL (Simple DirectMedia Layer) through 1.2.15 and 2.x through 2.0.9 has a heap-based buffer over-read in Map1toN in video/SDL_pixels.c.
nvd
CVE-2015-8391P3CRITICALCVSS 9.8v222015-12-02
CVE-2015-8391 [CRITICAL] CWE-119 CVE-2015-8391: The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which
The pcre_compile function in pcre_compile.c in PCRE before 8.38 mishandles certain [: nesting, which allows remote attackers to cause a denial of service (CPU consumption) or possibly have unspecified other impact via a crafted regular expression, as demonstrated by a JavaScript RegExp object encountered by Konqueror.
nvd