VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2023-22909
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. SpecialMobileHistory allows remote attackers to cause a denial of service because database queries are slow.
Published 2023-01-10 · Modified
5.3EPSS 0.009
CVE-2024-34161
NGINX HTTP/3 QUIC vulnerability
Published 2024-05-29 · Analyzed
5.3EPSS 0.009
CVE-2023-3431
Improper Access Control in plantuml/plantuml
Published 2023-06-27 · Modified
5.3EPSS 0.009
CVE-2022-4122
A vulnerability was found in buildah. Incorrect following of symlinks while reading .containerignore and .dockerignore results in information disclosure.
Published 2022-12-08 · Modified
5.3EPSS 0.008
CVE-2022-46392
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. An adversary with access to precise enough information about memory accesses (typically, an untrusted operating system attacking a secure enclave) can recover an RSA private key after observing the victim performing a single private-key operation, if the window size (MBEDTLS_MPI_WINDOW_SIZE) used for the exponentiation is 3 or smaller.
Published 2022-12-15 · Modified
5.3EPSS 0.008
CVE-2023-46839
pci: phantom functions assigned to incorrect contexts
Published 2024-03-20 · Analyzed
5.3EPSS 0.008
CVE-2023-4361
Inappropriate implementation in Autofill in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
5.3EPSS 0.008
CVE-2023-4359
Inappropriate implementation in App Launcher in Google Chrome on iOS prior to 116.0.5845.96 allowed a remote attacker to potentially spoof elements of the security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
5.3EPSS 0.008
CVE-2023-40587
Pyramid static view path traversal up one directory
Published 2023-08-25 · Modified
5.3EPSS 0.008
CVE-2023-34410
An issue was discovered in Qt before 5.15.15, 6.x before 6.2.9, and 6.3.x through 6.5.x before 6.5.2. Certificate validation for TLS does not always consider whether the root of a chain is a configured CA certificate.
Published 2023-06-05 · Analyzed
5.3EPSS 0.007
CVE-2023-5349
Draw while calling getdrawinfo()
Published 2023-10-30 · Modified
5.3EPSS 0.007
CVE-2024-24568
Suricata http2: header handling evasion
Published 2024-02-26 · Analyzed
5.3EPSS 0.006
CVE-2021-42374
An out-of-bounds heap read in Busybox's unlzma applet leads to information leak and denial of service when crafted LZMA-compressed input is decompressed. This can be triggered by any applet/format that
Published 2021-11-15 · Modified
5.3EPSS 0.006
CVE-2024-25983
Msa-24-0006: idor on dashboard comments block
Published 2024-02-19 · Analyzed
5.3EPSS 0.006
CVE-2024-25979
Msa-24-0002: forum search accepted random parameters in its url
Published 2024-02-19 · Analyzed
5.3EPSS 0.006
CVE-2024-25981
Msa-24-0004: forum export did not respect activity group settings
Published 2024-02-19 · Analyzed
5.3EPSS 0.006
CVE-2023-1672
Race condition exists in the key generation and rotation functionality
Published 2023-07-11 · Modified
5.3EPSS 0.006
CVE-2023-5549
Moodle: insufficient capability checks when updating the parent of a course category
Published 2023-11-09 · Modified
5.3EPSS 0.006
CVE-2021-42762
BubblewrapLauncher.cpp in WebKitGTK and WPE WebKit before 2.34.1 allows a limited sandbox bypass that allows a sandboxed process to trick host processes into thinking the sandboxed process is not confined by the sandbox, by abusing VFS syscalls that manipulate its filesystem namespace. The impact is limited to host services that create UNIX sockets that WebKit mounts inside its sandbox, and the sandboxed process remains otherwise confined. NOTE: this is similar to CVE-2021-41133.
Published 2021-10-20 · Modified
5.3EPSS 0.005
CVE-2023-5545
Moodle: auto-populated h5p author name causes a potential information leak
Published 2023-11-09 · Modified
5.3EPSS 0.005
CVE-2024-25980
Msa-24-0003: h5p attempts report did not respect activity group settings
Published 2024-02-19 · Analyzed
5.3EPSS 0.005
CVE-2023-32732
Denial-of-Service in gRPC
Published 2023-06-09 · Modified
5.3EPSS 0.005
CVE-2024-0333
Insufficient data validation in Extensions in Google Chrome prior to 120.0.6099.216 allowed an attacker in a privileged network position to install a malicious extension via a crafted HTML page. (Chromium security severity: High)
Published 2024-01-10 · Modified
5.3EPSS 0.004
CVE-2015-1839
modules/chef.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
Published 2017-04-13 · Modified
5.3EPSS 0.004
CVE-2015-1838
modules/serverdensity_device.py in SaltStack before 2014.7.4 does not properly handle files in /tmp.
Published 2017-04-13 · Modified
5.3EPSS 0.004
CVE-2020-12888
The VFIO PCI driver in the Linux kernel through 5.6.13 mishandles attempts to access disabled memory space.
Published 2020-05-15 · Modified
5.3EPSS 0.004
CVE-2020-27674
An issue was discovered in Xen through 4.14.x allowing x86 PV guest OS users to gain guest OS privileges by modifying kernel memory contents, because invalidation of TLB entries is mishandled during use of an INVLPG-like attack technique.
Published 2020-10-22 · Modified
5.3EPSS 0.004
CVE-2023-6693
Qemu: virtio-net: stack buffer overflow in virtio_net_flush_tx()
Published 2024-01-02 · Modified
5.3EPSS 0.003
CVE-2018-1113
setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow access based on a user's shell being listed in /etc/shells. Under some circumstances, users which had their shell changed to /sbin/nologin could still access the system.
Published 2018-07-02 · Modified
5.3EPSS 0.003
CVE-2024-31585
FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2024-04-17 · Modified
5.3EPSS 0.003
CVE-2023-5548
Moodle: cache poisoning risk with endpoint revision numbers
Published 2023-11-09 · Modified
5.3EPSS 0.003
CVE-2022-27652
A flaw was found in cri-o, where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker with access to programs with inheritable file capabilities to elevate those capabilities to the permitted set when execve(2) runs.
Published 2022-04-18 · Modified
5.3EPSS 0.002
CVE-2020-15257
containerd-shim API Exposed to Host Network Containers
Published 2020-12-01 · Modified
5.2EPSS 0.032
CVE-2024-34397
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
Published 2024-05-07 · Modified
5.2EPSS 0.008
CVE-2019-3811
A vulnerability was found in sssd. If a user was configured with no home directory set, sssd would return '/' (the root directory) instead of '' (the empty string / no home directory). This could impact services that restrict the user's filesystem access to within their home directory through chroot() etc. All versions before 2.1 are vulnerable.
Published 2019-01-15 · Modified
5.2EPSS 0.007
CVE-2020-2934
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.19 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.0 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).
Published 2020-04-15 · Modified
5.1EPSS 0.033
CVE-2013-4550
Bip before 0.8.9, when running as a daemon, writes SSL handshake errors to an unexpected file descriptor that was previously associated with stderr before stderr has been closed, which allows remote attackers to write to other sockets and have an unspecified impact via a failed SSL handshake, a different vulnerability than CVE-2011-5268. NOTE: some sources originally mapped this CVE to two different types of issues; this CVE has since been SPLIT, producing CVE-2011-5268.
Published 2013-12-24 · Modified
5.1EPSS 0.022
CVE-2019-2739
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Security: Privileges). Supported versions that are affected are 5.6.44 and prior, 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 5.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H).
Published 2019-07-23 · Modified
5.1EPSS 0.008
CVE-2019-20386
An issue was discovered in button_open in login/logind-button.c in systemd before 243. When executing the udevadm trigger command, a memory leak may occur.
Published 2020-01-21 · Modified
5.1EPSS 0.004
CVE-2023-40551
Shim: out of bounds read when parsing mz binaries
Published 2024-01-29 · Modified
5.1EPSS 0.004
← Prev116 / 135Next →