VendorsFedora Projectfedora40
Vulnerabilities

Fedora Project Fedora 40

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

244CVEs
CVE-2024-24576
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
Published 2024-04-09 · Analyzed
10.0EPSS 0.203
CVE-2024-1597
pgjdbc SQL Injection via line comment generation
Published 2024-02-19 · Modified
10.0EPSS 0.048
CVE-2024-2044
Unsafe Deserialisation and Remote Code Execution by an Authenticated user in pgAdmin 4
Published 2024-03-07 · Analyzed
9.9EPSS 0.795
CVE-2012-1823
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not properly handle query strings that lack an = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the 'd' case.
Published 2012-05-11 · Analyzed
9.8KEV4 PoCEPSS 1.000
CVE-2024-4577
Argument Injection in PHP-CGI
Published 2024-06-09 · Analyzed
9.8KEV1 PoCEPSS 1.000
CVE-2024-32459
FreeRDP Out-Of-Bounds Read in ncrush_decompress
Published 2024-04-22 · Modified
9.8EPSS 0.037
CVE-2024-32039
FreeRDP Integer overflow & OutOfBound Write in clear_decompress_residual_data
Published 2024-04-22 · Modified
9.8EPSS 0.023
CVE-2024-32458
FreeRDP Out-Of-Bounds Read in planar_skip_plane_rle
Published 2024-04-22 · Modified
9.8EPSS 0.019
CVE-2024-32041
FreeRDP OutOfBound Read in zgfx_decompress_segment
Published 2024-04-22 · Analyzed
9.8EPSS 0.019
CVE-2024-32040
FreeRDP vulnerable to integer underflow in nsc_rle_decode
Published 2024-04-22 · Modified
9.8EPSS 0.019
CVE-2024-32460
FreeRDP Out-Of-Bounds Read in interleaved_decompress
Published 2024-04-22 · Modified
9.8EPSS 0.019
CVE-2024-23313
An integer underflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-20 · Modified
9.8EPSS 0.018
CVE-2024-21795
A heap-based buffer overflow vulnerability exists in the .egi parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .egi file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-20 · Modified
9.8EPSS 0.018
CVE-2024-21812
An integer overflow vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to an out-of-bounds write which in turn can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-20 · Modified
9.8EPSS 0.018
CVE-2024-23310
A use-after-free vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-20 · Modified
9.8EPSS 0.017
CVE-2024-23305
An out-of-bounds write vulnerability exists in the BrainVisionMarker Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vmrk file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-20 · Modified
9.8EPSS 0.017
CVE-2024-23809
A double-free vulnerability exists in the BrainVision ASCII Header Parsing functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-20 · Modified
9.8EPSS 0.017
CVE-2024-23606
An out-of-bounds write vulnerability exists in the sopen_FAMOS_read functionality of The Biosig Project libbiosig 2.5.0 and Master Branch (ab0ee111). A specially crafted .famos file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-20 · Modified
9.8EPSS 0.017
CVE-2024-22373
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-04-25 · Modified
9.8EPSS 0.017
CVE-2024-22097
A double-free vulnerability exists in the BrainVision Header Parsing functionality of The Biosig Project libbiosig Master Branch (ab0ee111) and 2.5.0. A specially crafted .vdhr file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-02-20 · Modified
9.8EPSS 0.016
CVE-2023-47212
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-05-01 · Modified
9.8EPSS 0.014
CVE-2024-22391
A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-04-25 · Analyzed
9.8EPSS 0.014
CVE-2024-32658
FreeRDP ExtractRunLengthRegular* out of bound read
Published 2024-04-23 · Modified
9.8EPSS 0.014
CVE-2024-3209
UPX bele.h get_ne64 heap-based overflow
Published 2024-04-02 · Analyzed
9.8EPSS 0.012
CVE-2024-32659
freerdp_image_copy out of bound read
Published 2024-04-23 · Modified
9.8EPSS 0.012
CVE-2024-31581
FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application.
Published 2024-04-17 · Modified
9.8EPSS 0.011
CVE-2024-36048
QAbstractOAuth in Qt Network Authorization in Qt before 5.15.17, 6.x before 6.2.13, 6.3.x through 6.5.x before 6.5.6, and 6.6.x through 6.7.x before 6.7.1 uses only the time to seed the PRNG, which may result in guessable values.
Published 2024-05-18 · Modified
9.8EPSS 0.010
CVE-2024-3847
Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Published 2024-04-17 · Analyzed
9.8EPSS 0.009
CVE-2024-3845
Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)
Published 2024-04-17 · Analyzed
9.8EPSS 0.009
CVE-2024-32662
FreeRDP rdp_redirection_read_base64_wchar out of bound read
Published 2024-04-23 · Analyzed
9.8EPSS 0.008
CVE-2024-34502
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an edit token.
Published 2024-05-05 · Modified
9.8EPSS 0.004
CVE-2024-4947
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-15 · Analyzed
9.6KEVEPSS 0.152
CVE-2024-4671
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-09 · Analyzed
9.6KEVEPSS 0.083
CVE-2024-5274
Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-28 · Analyzed
9.6KEVEPSS 0.075
CVE-2024-4558
Use after free in ANGLE in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-07 · Modified
9.6EPSS 0.015
CVE-2024-4949
Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-05-15 · Analyzed
9.6EPSS 0.009
CVE-2024-3157
Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)
Published 2024-04-10 · Modified
9.6EPSS 0.008
CVE-2024-1874
Command injection via array-ish $command parameter of proc_open()
Published 2024-04-29 · Modified
9.4EPSS 0.326
CVE-2024-27319
Versions of the package onnx before and including 1.15.0 are vulnerable to Out-of-bounds Read as the ONNX_ASSERT and ONNX_ASSERTM functions have an off by one string copy.
Published 2024-02-23 · Modified
9.1EPSS 0.006
CVE-2024-4058
Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2024-05-01 · Modified
9.0EPSS 0.090
1 / 7Next →