VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2023-2466
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-05-02 · Modified
4.3EPSS 0.008
CVE-2023-2468
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-05-02 · Modified
4.3EPSS 0.008
CVE-2021-37967
Inappropriate implementation in Background Fetch API in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
Published 2021-10-08 · Modified
4.3EPSS 0.008
CVE-2023-42453
Improper validation of receipts allows forged read receipts in matrix synapse
Published 2023-09-26 · Modified
4.3EPSS 0.008
CVE-2019-5838
Insufficient policy enforcement in extensions API in Google Chrome prior to 75.0.3770.80 allowed an attacker who convinced a user to install a malicious extension to bypass restrictions on file URIs via a crafted Chrome Extension.
Published 2019-06-27 · Modified
4.3EPSS 0.008
CVE-2019-10740
In Roundcube Webmail before 1.3.10, an attacker in possession of S/MIME or PGP encrypted emails can wrap them as sub-parts within a crafted multipart email. The encrypted part(s) can further be hidden using HTML/CSS or ASCII newline characters. This modified multipart email can be re-sent by the attacker to the intended receiver. If the receiver replies to this (benign looking) email, they unknowingly leak the plaintext of the encrypted message part(s) back to the attacker.
Published 2019-04-07 · Modified
4.3EPSS 0.008
CVE-2023-48233
overflow with count for :s command in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-48234
overflow in nv_z_get_count in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-48235
overflow in ex address parsing in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-48237
overflow in shift_line in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-4901
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-28336
Moodle: teacher can access names of users they do not have permission to access
Published 2023-03-23 · Modified
4.3EPSS 0.007
CVE-2024-30260
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Published 2024-04-04 · Modified
4.3EPSS 0.007
CVE-2021-30630
Inappropriate implementation in Blink in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
Published 2021-10-08 · Modified
4.3EPSS 0.007
CVE-2024-2629
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2024-2631
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2024-3844
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Published 2024-04-17 · Analyzed
4.3EPSS 0.007
CVE-2021-37966
Inappropriate implementation in Compositing in Google Chrome on Android prior to 94.0.4606.54 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Published 2021-10-08 · Modified
4.3EPSS 0.007
CVE-2023-4905
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-48236
overflow in get_number in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2023-4907
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4900
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4902
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4903
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4360
Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
4.3EPSS 0.007
CVE-2023-4363
Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
4.3EPSS 0.007
CVE-2023-4364
Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
4.3EPSS 0.007
CVE-2023-4365
Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
4.3EPSS 0.007
CVE-2023-48232
Floating point Exception in adjust_plines_for_skipcol() in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2021-38020
Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Published 2021-12-23 · Modified
4.3EPSS 0.007
CVE-2023-48231
Use-After-Free in win_close() in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2022-3053
Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.
Published 2022-09-26 · Modified
4.3EPSS 0.007
CVE-2022-40316
The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.
Published 2022-09-30 · Modified
4.3EPSS 0.007
CVE-2023-4906
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2024-2628
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2023-5853
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-11-01 · Modified
4.3EPSS 0.007
CVE-2023-5858
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-11-01 · Modified
4.3EPSS 0.007
CVE-2023-2464
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
4.3EPSS 0.006
CVE-2023-4908
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2023-4909
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.006
← Prev130 / 135Next →