VendorsFedora Projectfedora38
Vulnerabilities

Fedora Project Fedora 38

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

640CVEs
CVE-2024-2626
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
6.5EPSS 0.008
CVE-2024-3515
Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-04-10 · Analyzed
6.5EPSS 0.008
CVE-2023-43279
Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.
Published 2024-03-12 · Modified
6.5EPSS 0.007
CVE-2023-4367
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
6.5EPSS 0.006
CVE-2023-42822
Unchecked access to font glyph info in xrdp
Published 2023-09-27 · Modified
6.5EPSS 0.006
CVE-2023-43785
Libx11: out-of-bounds memory access in _xkbreadkeysyms()
Published 2023-10-10 · Modified
6.5EPSS 0.006
CVE-2023-5487
Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2023-10-11 · Modified
6.5EPSS 0.006
CVE-2022-36351
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access.
Published 2023-08-11 · Modified
6.5EPSS 0.006
CVE-2023-5475
Inappropriate implementation in DevTools in Google Chrome prior to 118.0.5993.70 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2023-10-11 · Modified
6.5EPSS 0.006
CVE-2023-5455
Ipa: invalid csrf protection
Published 2024-01-10 · Modified
6.5EPSS 0.006
CVE-2022-4926
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-07-28 · Modified
6.5EPSS 0.006
CVE-2023-5544
Moodle: stored xss and potential idor risk in wiki comments
Published 2023-11-09 · Modified
6.5EPSS 0.005
CVE-2023-38201
Keylime: challenge-response protocol bypass during agent registration
Published 2023-08-25 · Modified
6.5EPSS 0.005
CVE-2023-4135
Out-of-bounds read information disclosure vulnerability
Published 2023-08-04 · Modified
6.5EPSS 0.004
CVE-2024-0814
Incorrect security UI in Payments in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-01-23 · Modified
6.5EPSS 0.003
CVE-2022-42334
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would otherwise be put in place. While not exposed to the affected guests themselves, the interface specifically exists for domains controlling such guests. This interface may therefore be used by not fully privileged entities, e.g. qemu running deprivileged in Dom0 or qemu running in a so called stub-domain. With this exposure it is an issue that - the number of the such controlled regions was unbounded (CVE-2022-42333), - installation and removal of such regions was not properly serialized (CVE-2022-42334).
Published 2023-03-21 · Modified
6.5EPSS 0.003
CVE-2023-3180
Heap buffer overflow in virtio_crypto_sym_op_helper()
Published 2023-08-03 · Modified
6.5EPSS 0.002
CVE-2023-31130
Buffer Underwrite in ares_inet_net_pton()
Published 2023-05-25 · Modified
6.4EPSS 0.004
CVE-2023-45866
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Published 2023-12-08 · Modified
6.3EPSS 0.079
CVE-2024-24795
Apache HTTP Server: HTTP Response Splitting in multiple modules
Published 2024-04-04 · Analyzed
6.3EPSS 0.029
CVE-2023-39365
Unchecked regular expressions can lead to SQL Injection and data leakage in Cacti
Published 2023-09-05 · Modified
6.3EPSS 0.009
CVE-2023-5341
Imagemagick: heap use-after-free in coders/bmp.c
Published 2023-11-19 · Modified
6.2EPSS 0.004
CVE-2023-5441
NULL Pointer Dereference in vim/vim
Published 2023-10-05 · Modified
6.2EPSS 0.004
CVE-2023-32627
Floating point exception in src/voc.c
Published 2023-07-10 · Modified
6.2EPSS 0.003
CVE-2023-26590
Floating point exception in src/aiff.c
Published 2023-07-10 · Modified
6.2EPSS 0.002
CVE-2023-5480
Inappropriate implementation in Payments in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to bypass XSS preventions via a malicious file. (Chromium security severity: High)
Published 2023-11-01 · Modified
6.1EPSS 0.011
CVE-2024-27285
YARD's default template vulnerable to Cross-site Scripting in generated frames.html
Published 2024-02-28 · Analyzed
6.1EPSS 0.011
CVE-2023-39513
Stored Cross-site Scripting on host.php verbose data-query debug view in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.009
CVE-2023-39360
Reflected Cross-site Scripting in graphs_new.php in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.009
CVE-2023-39366
Stored Cross-site Scripting in data_sources.php through Device-Name in 'select' input in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.009
CVE-2023-39514
Stored Cross-site Scripting on graphs.php data template formated name view in Cacti
Published 2023-09-05 · Analyzed
6.1EPSS 0.009
CVE-2023-39516
Stored Cross-Site-Scripting on data_sources.php debug html-block in Cacti
Published 2023-09-05 · Analyzed
6.1EPSS 0.008
CVE-2023-39515
Stored Cross-site Scripting on data_debug.php datasource path view in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.008
CVE-2023-39510
Stored Cross-site Scripting in reports_admin.php through Device-Name in 'select' input in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.008
CVE-2023-39512
Stored Cross-site Scripting on data_sources.php device name view in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.008
CVE-2023-39511
Stored Cross-Site-Scripting on reports_admin.php device name in Cacti
Published 2023-09-06 · Analyzed
6.1EPSS 0.008
CVE-2023-28439
ckeditor4 plugins vulnerable to cross-site scripting caused by the editor instance destroying process
Published 2023-03-22 · Modified
6.1EPSS 0.007
CVE-2024-27306
aiohttp vulnerable to XSS on index pages for static file handling
Published 2024-04-18 · Modified
6.1EPSS 0.007
CVE-2023-47272
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
Published 2023-11-05 · Modified
6.1EPSS 0.006
CVE-2023-5547
Moodle: xss risk when previewing data in course upload tool
Published 2023-11-09 · Modified
6.1EPSS 0.005
← Prev11 / 16Next →