VendorsFedora Projectfedora37
Vulnerabilities

Fedora Project Fedora 37

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

698CVEs
CVE-2023-41909
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
Published 2023-09-05 · Modified
7.5EPSS 0.011
CVE-2023-38552
When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.
Published 2023-10-18 · Modified
7.5EPSS 0.011
CVE-2022-39283
FreeRDP may read and display out of bounds data
Published 2022-10-12 · Modified
7.5EPSS 0.011
CVE-2022-45060
An HTTP Request Forgery issue was discovered in Varnish Cache 5.x and 6.x before 6.0.11, 7.x before 7.1.2, and 7.2.x before 7.2.1. An attacker may introduce characters through HTTP/2 pseudo-headers that are invalid in the context of an HTTP/1 request line, causing the Varnish server to produce invalid HTTP/1 requests to the backend. This could, in turn, be used to exploit vulnerabilities in a server behind the Varnish server. Note: the 6.0.x LTS series (before 6.0.11) is affected.
Published 2022-11-09 · Modified
7.5EPSS 0.010
CVE-2023-2135
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-04-19 · Modified
7.5EPSS 0.010
CVE-2022-39957
Response body bypass in OWASP ModSecurity Core Rule Set via a specialy crafted charset in the HTTP Accept header
Published 2022-09-20 · Modified
7.5EPSS 0.010
CVE-2021-45451
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Published 2021-12-21 · Modified
7.5EPSS 0.009
CVE-2022-39282
RDP client: Read of uninitialized memory with parallel port redirection
Published 2022-10-12 · Modified
7.5EPSS 0.009
CVE-2022-3725
Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file
Published 2022-10-27 · Modified
7.5EPSS 0.009
CVE-2023-43615
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
Published 2023-10-07 · Modified
7.5EPSS 0.008
CVE-2023-34058
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Published 2023-10-27 · Modified
7.5EPSS 0.007
CVE-2021-28861
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html documentation page states "Warning: http.server is not recommended for production. It only implements basic security checks."
Published 2022-08-23 · Modified
7.4EPSS 0.025
CVE-2023-0361
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
Published 2023-02-15 · Modified
7.4EPSS 0.014
CVE-2023-30944
Moodle: minor sql injection risk in external wiki method for listing pages
Published 2023-05-02 · Modified
7.3EPSS 0.011
CVE-2022-32323
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
Published 2022-07-14 · Modified
7.3EPSS 0.009
CVE-2023-1170
Heap-based Buffer Overflow in vim/vim
Published 2023-03-03 · Analyzed
7.3EPSS 0.005
CVE-2023-1175
Incorrect Calculation of Buffer Size in vim/vim
Published 2023-03-04 · Analyzed
7.3EPSS 0.004
CVE-2023-39362
Authenticated command injection in SNMP options of a Device
Published 2023-09-05 · Modified
7.21 PoCEPSS 0.854
CVE-2022-37967
Windows Kerberos Elevation of Privilege Vulnerability
Published 2022-11-09 · Modified
7.2EPSS 0.041
CVE-2023-27320
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Published 2023-02-28 · Modified
7.2EPSS 0.017
CVE-2023-34241
CUPS vulnerable to use-after-free in cupsdAcceptClient()
Published 2023-06-22 · Modified
7.1EPSS 0.014
CVE-2022-41742
NGINX ngx_http_mp4_module vulnerability CVE-2022-41742
Published 2022-10-19 · Modified
7.1EPSS 0.011
CVE-2023-28447
Cross site scripting vulnerability in Javascript escaping in smarty/smarty
Published 2023-03-28 · Modified
7.1EPSS 0.010
CVE-2021-29390
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
Published 2023-08-22 · Modified
7.1EPSS 0.008
CVE-2023-28686
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
Published 2023-03-24 · Modified
7.1EPSS 0.007
CVE-2023-2460
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
7.1EPSS 0.007
CVE-2022-42327
x86: unintended memory sharing between guests On Intel systems that support the "virtualize APIC accesses" feature, a guest can read and write the global shared xAPIC page by moving the local APIC out of xAPIC mode. Access to this shared page bypasses the expected isolation that should exist between two guests.
Published 2022-11-01 · Modified
7.1EPSS 0.002
CVE-2023-4504
OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow
Published 2023-09-21 · Modified
7.0EPSS 0.007
CVE-2022-42320
Xenstore: Guests can get access to Xenstore nodes of deleted domains Access rights of Xenstore nodes are per domid. When a domain is gone, there might be Xenstore nodes left with access rights containing the domid of the removed domain. This is normally no problem, as those access right entries will be corrected when such a node is written later. There is a small time window when a new domain is created, where the access rights of a past domain with the same domid as the new one will be regarded to be still valid, leading to the new domain being able to get access to a node which was meant to be accessible by the removed domain. For this to happen another domain needs to write the node before the newly created domain is being introduced to Xenstore by dom0.
Published 2022-11-01 · Modified
7.0EPSS 0.003
CVE-2022-3028
A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory by performing an out-of-bounds read and copying it into a socket.
Published 2022-08-31 · Modified
7.0EPSS 0.002
CVE-2022-3278
NULL Pointer Dereference in vim/vim
Published 2022-09-23 · Modified
6.8EPSS 0.010
CVE-2022-4645
LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.
Published 2023-03-03 · Modified
6.8EPSS 0.004
CVE-2023-2426
Use of Out-of-range Pointer Offset in vim/vim
Published 2023-04-29 · Analyzed
6.8EPSS 0.004
CVE-2022-3048
Inappropriate implementation in Chrome OS lockscreen in Google Chrome on Chrome OS prior to 105.0.5195.52 allowed a local attacker to bypass lockscreen navigation restrictions via physical access to the device.
Published 2022-09-26 · Modified
6.8EPSS 0.004
CVE-2023-4273
Kernel: exfat: stack overflow in exfat_get_uniname_from_ext_entry
Published 2023-08-09 · Modified
6.7EPSS 0.007
CVE-2022-35957
Authentication Bypass in Grafana via auth proxy allowing escalation from admin to server admin
Published 2022-09-20 · Modified
6.6EPSS 0.016
CVE-2023-1264
NULL Pointer Dereference in vim/vim
Published 2023-03-07 · Modified
6.6EPSS 0.004
CVE-2023-1073
A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Published 2023-03-27 · Modified
6.6EPSS 0.004
CVE-2023-25136
OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."
Published 2023-02-03 · Modified
6.5EPSS 0.897
CVE-2022-32215
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
Published 2022-07-14 · Modified
6.5EPSS 0.688
← Prev10 / 18Next →