VendorsFedora Projectfedora38
Vulnerabilities

Fedora Project Fedora 38

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

640CVEs
CVE-2023-4903
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4360
Inappropriate implementation in Color in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
4.3EPSS 0.007
CVE-2023-4363
Inappropriate implementation in WebShare in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to spoof the contents of a dialog URL via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
4.3EPSS 0.007
CVE-2023-4364
Inappropriate implementation in Permission Prompts in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
4.3EPSS 0.007
CVE-2023-4365
Inappropriate implementation in Fullscreen in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
4.3EPSS 0.007
CVE-2023-48232
Floating point Exception in adjust_plines_for_skipcol() in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2023-48231
Use-After-Free in win_close() in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2023-4906
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2024-2628
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2023-5853
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-11-01 · Modified
4.3EPSS 0.007
CVE-2023-5858
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-11-01 · Modified
4.3EPSS 0.007
CVE-2023-42453
Improper validation of receipts allows forged read receipts in matrix synapse
Published 2023-09-26 · Modified
4.3EPSS 0.007
CVE-2023-2464
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
4.3EPSS 0.006
CVE-2023-4908
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2023-4909
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2023-4904
Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2023-5859
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
Published 2023-11-01 · Modified
4.3EPSS 0.006
CVE-2024-0811
Inappropriate implementation in Extensions API in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (Chromium security severity: Low)
Published 2024-01-23 · Modified
4.3EPSS 0.006
CVE-2023-5542
Moodle: students can view other users in "only see own membership" groups
Published 2023-11-09 · Modified
4.3EPSS 0.004
CVE-2024-0809
Inappropriate implementation in Autofill in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2024-01-23 · Modified
4.3EPSS 0.004
CVE-2024-0805
Inappropriate implementation in Downloads in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
Published 2024-01-23 · Modified
4.3EPSS 0.004
CVE-2022-4917
Incorrect security UI in Notifications in Google Chrome on Android prior to 103.0.5060.53 allowed a remote attacker to obscure the full screen notification via a crafted HTML page. (Chromium security severity: Low)
Published 2023-07-28 · Modified
4.3EPSS 0.003
CVE-2023-45803
Request body not stripped after redirect in urllib3
Published 2023-10-17 · Modified
4.2EPSS 0.005
CVE-2023-50007
FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.
Published 2024-04-19 · Modified
4.0EPSS 0.004
CVE-2023-20867
VMware Tools Authentication Bypass Vulnerability
Published 2023-06-13 · Analyzed
3.9KEVEPSS 0.135
CVE-2023-45143
Undici's cookie header not cleared on cross-origin redirect in fetch
Published 2023-10-12 · Modified
3.9EPSS 0.012
CVE-2023-31124
AutoTools does not set CARES_RANDOM_FILE during cross compilation
Published 2023-05-25 · Modified
3.7EPSS 0.009
CVE-2023-41335
Temporary storage of plaintext passwords during password changes in matrix synapse
Published 2023-09-26 · Modified
3.7EPSS 0.004
CVE-2023-45145
Redis Unix-domain socket may have be exposed with the wrong permissions for a short time window.
Published 2023-10-18 · Modified
3.6EPSS 0.004
CVE-2023-51796
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.
Published 2024-04-19 · Analyzed
3.6EPSS 0.002
CVE-2024-30261
Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrect
Published 2024-04-04 · Modified
3.5EPSS 0.008
CVE-2024-1454
Opensc: memory use after free in authentic driver when updating token info
Published 2024-02-12 · Modified
3.4EPSS 0.004
CVE-2023-25815
Git looks for localized messages in the wrong place
Published 2023-04-25 · Modified
3.3EPSS 0.010
CVE-2023-2602
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
Published 2023-06-06 · Modified
3.3EPSS 0.004
CVE-2023-5551
Moodle: forum summary report shows students from other groups when in separate groups mode
Published 2023-11-09 · Modified
3.3EPSS 0.003
CVE-2023-4016
Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.
Published 2023-08-02 · Modified
3.3EPSS 0.003
CVE-2023-5543
Moodle: duplicating a bigbluebutton activity assigns the same meeting id
Published 2023-11-09 · Modified
3.3EPSS 0.002
CVE-2023-22048
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published 2023-07-18 · Modified
3.1EPSS 0.010
CVE-2023-3674
Keylime: attestation failure when the quote's signature does not validate
Published 2023-07-19 · Modified
2.8EPSS 0.002
CVE-2023-22038
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
Published 2023-07-18 · Modified
2.7EPSS 0.009
← Prev16 / 16