VendorsFedora Projectfedora39
Vulnerabilities

Fedora Project Fedora 39

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

493CVEs
CVE-2023-5380
Xorg-x11-server: use-after-free bug in destroywindow
Published 2023-10-25 · Modified
4.7EPSS 0.007
CVE-2023-48706
Vim has heap-use-after-free at /src/charset.c:1770:12 in skipwhite
Published 2023-11-22 · Analyzed
4.7EPSS 0.005
CVE-2023-42756
Kernel: netfilter: race condition between ipset_cmd_add and ipset_cmd_swap
Published 2023-09-28 · Modified
4.7EPSS 0.003
CVE-2024-3843
Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-04-17 · Analyzed
4.6EPSS 0.006
CVE-2023-4535
Opensc: out-of-bounds read in myeid driver handling encryption using symmetric keys
Published 2023-11-06 · Modified
4.5EPSS 0.005
CVE-2023-22058
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published 2023-07-18 · Modified
4.4EPSS 0.017
CVE-2023-21947
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published 2023-04-18 · Modified
4.4EPSS 0.014
CVE-2023-21940
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Components Services). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published 2023-04-18 · Modified
4.4EPSS 0.013
CVE-2023-22005
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published 2023-07-18 · Modified
4.4EPSS 0.013
CVE-2023-22033
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published 2023-07-18 · Modified
4.4EPSS 0.012
CVE-2023-5850
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
Published 2023-11-01 · Modified
4.3EPSS 0.009
CVE-2023-5851
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-11-01 · Modified
4.3EPSS 0.009
CVE-2023-6511
Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2023-12-06 · Modified
4.3EPSS 0.009
CVE-2023-48237
overflow in shift_line in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-48233
overflow with count for :s command in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-48234
overflow in nv_z_get_count in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-48235
overflow in ex address parsing in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-4901
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2024-30260
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Published 2024-04-04 · Modified
4.3EPSS 0.007
CVE-2024-2629
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2024-2631
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2024-3844
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Published 2024-04-17 · Analyzed
4.3EPSS 0.007
CVE-2023-4905
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-48236
overflow in get_number in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2023-4907
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4900
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4902
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4903
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-48232
Floating point Exception in adjust_plines_for_skipcol() in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2023-48231
Use-After-Free in win_close() in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2023-4906
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2024-2628
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2023-5853
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-11-01 · Modified
4.3EPSS 0.007
CVE-2023-5858
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-11-01 · Modified
4.3EPSS 0.007
CVE-2023-4908
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2023-4909
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2023-4904
Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2023-5859
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
Published 2023-11-01 · Modified
4.3EPSS 0.006
CVE-2024-0811
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
Published 2024-01-23 · Modified
4.3EPSS 0.006
CVE-2024-0809
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2024-01-23 · Modified
4.3EPSS 0.004
← Prev12 / 13Next →