VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2024-4855
Use After Free in editcap
Published 2024-05-14 · Analyzed
5.5EPSS 0.004
CVE-2021-3505
A flaw was found in libtpms in versions before 0.8.0. The TPM 2 implementation returns 2048 bit keys with ~1984 bit strength due to a bug in the TCG specification. The bug is in the key creation algorithm in RsaAdjustPrimeCandidate(), which is called before the prime number check. The highest threat from this vulnerability is to data confidentiality.
Published 2021-04-19 · Modified
5.5EPSS 0.004
CVE-2021-46661
MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).
Published 2022-02-01 · Modified
5.5EPSS 0.004
CVE-2021-46663
MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
Published 2022-02-01 · Modified
5.5EPSS 0.004
CVE-2020-26571
The gemsafe GPK smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in sc_pkcs15emu_gemsafeGPK_init.
Published 2020-10-06 · Modified
5.5EPSS 0.004
CVE-2010-4178
MySQL-GUI-tools (mysql-administrator) leaks passwords into process list after with launch of mysql text console
Published 2019-11-06 · Modified
5.5EPSS 0.004
CVE-2022-1204
A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25 protocol functionality in the way a user connects with the protocol. This flaw allows a local user to crash the system.
Published 2022-08-29 · Modified
5.5EPSS 0.004
CVE-2021-46664
MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.
Published 2022-02-01 · Modified
5.5EPSS 0.004
CVE-2021-46665
MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.
Published 2022-02-01 · Modified
5.5EPSS 0.004
CVE-2021-46668
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
Published 2022-02-01 · Modified
5.5EPSS 0.004
CVE-2020-15304
An issue was discovered in OpenEXR before 2.5.2. An invalid tiled input file could cause invalid memory access in TiledInputFile::TiledInputFile() in IlmImf/ImfTiledInputFile.cpp, as demonstrated by a NULL pointer dereference.
Published 2020-06-26 · Modified
5.5EPSS 0.004
CVE-2020-26570
The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.
Published 2020-10-06 · Modified
5.5EPSS 0.004
CVE-2020-26572
The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.
Published 2020-10-06 · Modified
5.5EPSS 0.004
CVE-2019-19479
An issue was discovered in OpenSC through 0.19.0 and 0.20.x through 0.20.0-rc3. libopensc/card-setcos.c has an incorrect read operation during parsing of a SETCOS file attribute.
Published 2019-12-01 · Modified
5.5EPSS 0.004
CVE-2023-40550
Shim: out-of-bound read in verify_buffer_sbat()
Published 2024-01-29 · Modified
5.5EPSS 0.004
CVE-2022-28388
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
Published 2022-04-03 · Modified
5.5EPSS 0.004
CVE-2019-18811
A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
Published 2019-11-07 · Modified
5.5EPSS 0.004
CVE-2023-23456
Upx: heap-buffer-overflow in packtmt::pack()
Published 2023-01-12 · Modified
5.5EPSS 0.004
CVE-2021-4095
A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a denial of service by issuing a KVM_XEN_HVM_SET_ATTR ioctl. This flaw affects Linux kernel versions prior to 5.17-rc1.
Published 2022-03-08 · Modified
5.5EPSS 0.004
CVE-2014-5118
Trusted Boot (tboot) before 1.8.2 has a 'loader.c' Security Bypass Vulnerability
Published 2019-11-18 · Modified
5.5EPSS 0.004
CVE-2023-1981
A vulnerability was found in the avahi library. This flaw allows an unprivileged user to make a dbus call, causing the avahi daemon to crash.
Published 2023-05-26 · Modified
5.5EPSS 0.004
CVE-2021-28971
In intel_pmu_drain_pebs_nhm in arch/x86/events/intel/ds.c in the Linux kernel through 5.11.8 on some Haswell CPUs, userspace applications (such as perf-fuzzer) can cause a system crash because the PEBS status in a PEBS record is mishandled, aka CID-d88d05a9e0b6.
Published 2021-03-22 · Modified
5.5EPSS 0.004
CVE-2020-16150
A Lucky 13 timing side channel in mbedtls_ssl_decrypt_buf in library/ssl_msg.c in Trusted Firmware Mbed TLS through 2.23.0 allows an attacker to recover secret key information. This affects CBC mode because of a computed time difference based on a padding length.
Published 2020-09-02 · Modified
5.5EPSS 0.004
CVE-2024-0232
Sqlite: use-after-free bug in jsonparseaddnodearray
Published 2024-01-16 · Modified
5.5EPSS 0.004
CVE-2022-31030
containerd CRI plugin: Host memory exhaustion through ExecSync
Published 2022-06-06 · Modified
5.5EPSS 0.004
CVE-2013-1820
tuned before 2.x allows local users to kill running processes due to insecure permissions with tuned's ktune service.
Published 2019-11-08 · Modified
5.5EPSS 0.004
CVE-2022-2476
A null pointer dereference bug was found in wavpack-5.4.0 The results from the ASAN log: AddressSanitizer:DEADLYSIGNAL ===================================================================84257==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x561b47a970c6 bp 0x7fff13952fb0 sp 0x7fff1394fca0 T0) ==84257==The signal is caused by a WRITE memory access. ==84257==Hint: address points to the zero page. #0 0x561b47a970c5 in main cli/wvunpack.c:834 #1 0x7efc4f5c0082 in __libc_start_main (/lib/x86_64-linux-gnu/libc.so.6+0x24082) #2 0x561b47a945ed in _start (/usr/local/bin/wvunpack+0xa5ed) AddressSanitizer can not provide additional info. SUMMARY: AddressSanitizer: SEGV cli/wvunpack.c:834 in main ==84257==ABORTING
Published 2022-07-19 · Modified
5.5EPSS 0.004
CVE-2023-34474
A heap-based buffer overflow issue was discovered in ImageMagick's ReadTIM2ImageData() function in coders/tim2.c. A local attacker could trick the user in opening specially crafted file, triggering an out-of-bounds read error, allowing an application to crash, resulting in a denial of service.
Published 2023-06-16 · Modified
5.5EPSS 0.004
CVE-2019-19451
When GNOME Dia before 2019-11-27 is launched with a filename argument that is not a valid codepoint in the current encoding, it enters an endless loop, thus endlessly writing text to stdout. If this launch is from a thumbnailer service, this output will usually be written to disk via the system's logging facility (potentially with elevated privileges), thus filling up the disk and eventually rendering the system unusable. (The filename can be for a nonexistent file.) NOTE: this does not affect an upstream release, but affects certain Linux distribution packages with version numbers such as 0.97.3.
Published 2019-11-29 · Modified
5.5EPSS 0.004
CVE-2023-43788
Libxpm: out of bounds read in xpmcreatexpmimagefrombuffer()
Published 2023-10-10 · Modified
5.5EPSS 0.004
CVE-2021-43056
An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation bug in the handling of the SRR1 register values.
Published 2021-10-28 · Modified
5.5EPSS 0.004
CVE-2016-6494
The client in MongoDB uses world-readable permissions on .dbshell history files, which might allow local users to obtain sensitive information by reading these files.
Published 2016-10-03 · Modified
5.5EPSS 0.004
CVE-2021-29647
An issue was discovered in the Linux kernel before 5.11.11. qrtr_recvmsg in net/qrtr/qrtr.c allows attackers to obtain sensitive information from kernel memory because of a partially uninitialized data structure, aka CID-50535249f624.
Published 2021-03-30 · Modified
5.5EPSS 0.004
CVE-2021-28950
An issue was discovered in fs/fuse/fuse_i.h in the Linux kernel before 5.11.8. A "stall on CPU" can occur because a retry loop continually finds the same bad inode, aka CID-775c5033a0d1.
Published 2021-03-20 · Modified
5.5EPSS 0.004
CVE-2023-38253
W3m: out of bounds read in growbuf_to_str() at w3m/indep.c
Published 2023-07-14 · Modified
5.5EPSS 0.004
CVE-2023-38252
W3m: out of bounds read in strnew_size() at w3m/str.c
Published 2023-07-14 · Modified
5.5EPSS 0.004
CVE-2019-9705
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.
Published 2019-03-12 · Modified
5.5EPSS 0.004
CVE-2021-28699
inadequate grant-v2 status frames array bounds check The v2 grant table interface separates grant attributes from grant status. That is, when operating in this mode, a guest has two tables. As a result, guests also need to be able to retrieve the addresses that the new status tracking table can be accessed through. For 32-bit guests on x86, translation of requests has to occur because the interface structure layouts commonly differ between 32- and 64-bit. The translation of the request to obtain the frame numbers of the grant status table involves translating the resulting array of frame numbers. Since the space used to carry out the translation is limited, the translation layer tells the core function the capacity of the array within translation space. Unfortunately the core function then only enforces array bounds to be below 8 times the specified value, and would write past the available space if enough frame numbers needed storing.
Published 2021-08-27 · Modified
5.5EPSS 0.004
CVE-2016-3696
The pulp-qpid-ssl-cfg script in Pulp before 2.8.5 allows local users to obtain the CA key.
Published 2017-06-13 · Modified
5.5EPSS 0.004
CVE-2023-43789
Libxpm: out of bounds read on xpm with corrupted colormap
Published 2023-10-12 · Modified
5.5EPSS 0.004
← Prev108 / 135Next →