VendorsFedora Projectfedora39
Vulnerabilities

Fedora Project Fedora 39

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

493CVEs
CVE-2024-0805
Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
Published 2024-01-23 · Modified
4.3EPSS 0.004
CVE-2023-46840
VT-d: Failure to quarantine devices in !HVM builds
Published 2024-03-20 · Analyzed
4.1EPSS 0.003
CVE-2023-50007
FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.
Published 2024-04-19 · Modified
4.0EPSS 0.004
CVE-2023-20867
VMware Tools Authentication Bypass Vulnerability
Published 2023-06-13 · Analyzed
3.9KEVEPSS 0.135
CVE-2023-45143
Undici's cookie header not cleared on cross-origin redirect in fetch
Published 2023-10-12 · Modified
3.9EPSS 0.012
CVE-2023-45145
Redis Unix-domain socket may have be exposed with the wrong permissions for a short time window.
Published 2023-10-18 · Modified
3.6EPSS 0.004
CVE-2023-51796
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.
Published 2024-04-19 · Analyzed
3.6EPSS 0.002
CVE-2024-2004
Usage of disabled protocol
Published 2024-03-27 · Analyzed
3.5EPSS 0.017
CVE-2024-30261
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Published 2024-04-04 · Modified
3.5EPSS 0.008
CVE-2024-1454
Opensc: memory use after free in authentic driver when updating token info
Published 2024-02-12 · Modified
3.4EPSS 0.004
CVE-2024-0217
Packagekitd: use-after-free in idle function callback
Published 2024-01-03 · Modified
3.3EPSS 0.002
CVE-2023-22048
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published 2023-07-18 · Modified
3.1EPSS 0.010
CVE-2023-22038
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
Published 2023-07-18 · Modified
2.7EPSS 0.009
← Prev13 / 13