VendorsFedora Projectfedora39
Vulnerabilities

Fedora Project Fedora 39

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

493CVEs
CVE-2023-21929
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 5.5 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
Published 2023-04-18 · Modified
5.5EPSS 0.013
CVE-2023-31489
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_capability_llgr() function.
Published 2023-05-09 · Modified
5.5EPSS 0.010
CVE-2022-48065
GNU Binutils before 2.40 was discovered to contain a memory leak vulnerability var the function find_abstract_instance in dwarf2.c.
Published 2023-08-22 · Modified
5.5EPSS 0.006
CVE-2024-24246
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
Published 2024-02-29 · Modified
5.5EPSS 0.004
CVE-2023-22840
Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable denial of service via local access.
Published 2023-08-11 · Modified
5.5EPSS 0.004
CVE-2024-4853
Mismatched Memory Management Routines in editcap
Published 2024-05-14 · Modified
5.5EPSS 0.004
CVE-2023-42754
Kernel: ipv4: null pointer dereference in ipv4_send_dest_unreach()
Published 2023-10-05 · Modified
5.5EPSS 0.004
CVE-2023-40550
Shim: out-of-bound read in verify_buffer_sbat()
Published 2024-01-29 · Modified
5.5EPSS 0.004
CVE-2024-0232
Sqlite: use-after-free bug in jsonparseaddnodearray
Published 2024-01-16 · Modified
5.5EPSS 0.004
CVE-2024-4855
Use After Free in editcap
Published 2024-05-14 · Analyzed
5.5EPSS 0.004
CVE-2023-43788
Libxpm: out of bounds read in xpmcreatexpmimagefrombuffer()
Published 2023-10-10 · Modified
5.5EPSS 0.004
CVE-2024-25629
c-ares out of bounds read in ares__read_line()
Published 2024-02-23 · Analyzed
5.5EPSS 0.004
CVE-2023-4256
Tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c
Published 2023-12-21 · Modified
5.5EPSS 0.003
CVE-2023-4255
W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223)
Published 2023-12-21 · Modified
5.5EPSS 0.003
CVE-2024-0408
Xorg-x11-server: selinux unlabeled glx pbuffer
Published 2024-01-18 · Modified
5.5EPSS 0.003
CVE-2023-6622
Kernel: null pointer dereference vulnerability in nft_dynset_init()
Published 2023-12-08 · Analyzed
5.5EPSS 0.003
CVE-2024-1062
389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)
Published 2024-02-12 · Modified
5.5EPSS 0.003
CVE-2024-0690
Ansible-core: possible information leak in tasks that ignore ansible_no_log configuration
Published 2024-02-06 · Modified
5.5EPSS 0.003
CVE-2024-27399
Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout
Published 2024-05-13 · Analyzed
5.5EPSS 0.003
CVE-2024-23301
Relax-and-Recover (aka ReaR) through 2.7 creates a world-readable initrd when using GRUB_RESCUE=y. This allows local attackers to gain access to system secrets otherwise only readable by root.
Published 2024-01-12 · Modified
5.5EPSS 0.003
CVE-2024-27001
comedi: vmk80xx: fix incomplete endpoint checking
Published 2024-05-01 · Analyzed
5.5EPSS 0.003
CVE-2024-27013
tun: limit printing rate when illegal packet received by tun dev
Published 2024-05-01 · Modified
5.5EPSS 0.003
CVE-2024-1151
Kernel: stack overflow problem in open vswitch kernel module leading to dos
Published 2024-02-11 · Modified
5.5EPSS 0.003
CVE-2023-40032
Potential segfault due to NULL pointer dereference in libvips
Published 2023-09-11 · Analyzed
5.5EPSS 0.003
CVE-2023-22338
Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable information disclosure via local access.
Published 2023-08-11 · Modified
5.5EPSS 0.003
CVE-2024-0443
Kernel: blkio memory leakage due to blkcg and some blkgs are not freed after they are made offline.
Published 2024-01-11 · Modified
5.5EPSS 0.002
CVE-2023-52429
dm_table_create in drivers/md/dm-table.c in the Linux kernel through 6.7.4 can attempt to (in alloc_targets) allocate more than INT_MAX bytes, and crash, because of a missing check for struct dm_ioctl.target_count.
Published 2024-02-12 · Modified
5.5EPSS 0.002
CVE-2024-26986
drm/amdkfd: Fix memory leak in create_process failure
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-27015
netfilter: flowtable: incorrect pppoe tuple
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2023-42811
AEADs/aes-gcm: Plaintext exposed in decrypt_in_place_detached even on tag verification failure
Published 2023-09-22 · Modified
5.5EPSS 0.002
CVE-2024-27004
clk: Get runtime PM before walking tree during disable_unused
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-27014
net/mlx5e: Prevent deadlock while disabling aRFS
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-26987
mm/memory-failure: fix deadlock when hugetlb_optimize_vmemmap is enabled
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-31444
Cacti XSS vulnerability in lib/html.php by reading dirty data stored in database
Published 2024-05-13 · Modified
5.4EPSS 0.147
CVE-2024-29133
Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
Published 2024-03-21 · Analyzed
5.4EPSS 0.017
CVE-2023-5546
Moodle: stored xss in quiz grading report via user id number
Published 2023-11-09 · Modified
5.4EPSS 0.012
CVE-2024-34064
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Published 2024-05-06 · Modified
5.4EPSS 0.010
CVE-2024-3846
Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published 2024-04-17 · Analyzed
5.4EPSS 0.009
CVE-2024-29894
Cacti Cross-site Scripting vulnerability when using JavaScript based messaging API
Published 2024-05-13 · Analyzed
5.4EPSS 0.009
CVE-2024-38273
moodle: BigBlueButton web service leaks meeting joining information to users who should not have access
Published 2024-06-18 · Analyzed
5.4EPSS 0.004
← Prev10 / 13Next →