VendorsFedora Projectfedora37
Vulnerabilities

Fedora Project Fedora 37

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

698CVEs
CVE-2023-22005
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published 2023-07-18 · Modified
4.4EPSS 0.013
CVE-2023-22033
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published 2023-07-18 · Modified
4.4EPSS 0.012
CVE-2022-0216
A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest to crash the QEMU process on the host, resulting in a denial of service.
Published 2022-08-26 · Modified
4.4EPSS 0.004
CVE-2023-2269
A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.
Published 2023-04-25 · Modified
4.4EPSS 0.002
CVE-2022-3435
Linux Kernel IPv4 fib_semantics.c fib_nh_match out-of-bounds
Published 2022-10-08 · Modified
4.3EPSS 0.041
CVE-2023-30534
Insecure Deserialization in Cacti
Published 2023-09-05 · Analyzed
4.3EPSS 0.029
CVE-2018-14628
An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.
Published 2023-01-17 · Analyzed
4.3EPSS 0.012
CVE-2023-39999
WordPress < 6.3.2 is vulnerable to Broken Access Control
Published 2023-10-13 · Modified
4.3EPSS 0.010
CVE-2023-2465
Inappropriate implementation in CORS in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
4.3EPSS 0.010
CVE-2023-5850
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)
Published 2023-11-01 · Modified
4.3EPSS 0.009
CVE-2023-5851
Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-11-01 · Modified
4.3EPSS 0.009
CVE-2023-2463
Inappropriate implementation in Full Screen Mode in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
4.3EPSS 0.009
CVE-2023-2467
Inappropriate implementation in Prompts in Google Chrome on Android prior to 113.0.5672.63 allowed a remote attacker to bypass permissions restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2023-05-02 · Modified
4.3EPSS 0.008
CVE-2023-2462
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to obfuscate main origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
4.3EPSS 0.008
CVE-2023-2466
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to spoof the contents of the security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-05-02 · Modified
4.3EPSS 0.008
CVE-2023-2468
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed a remote attacker who had compromised the renderer process to obfuscate the security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-05-02 · Modified
4.3EPSS 0.008
CVE-2023-48233
overflow with count for :s command in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-48234
overflow in nv_z_get_count in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-48235
overflow in ex address parsing in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-48237
overflow in shift_line in vim
Published 2023-11-16 · Modified
4.3EPSS 0.008
CVE-2023-4901
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4905
Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-48236
overflow in get_number in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2023-4907
Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4900
Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4902
Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-4903
Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-48232
Floating point Exception in adjust_plines_for_skipcol() in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2023-48231
Use-After-Free in win_close() in vim
Published 2023-11-16 · Modified
4.3EPSS 0.007
CVE-2022-3053
Inappropriate implementation in Pointer Lock in Google Chrome on Mac prior to 105.0.5195.52 allowed a remote attacker to restrict user navigation via a crafted HTML page.
Published 2022-09-26 · Modified
4.3EPSS 0.007
CVE-2023-4906
Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.007
CVE-2023-5858
Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-11-01 · Modified
4.3EPSS 0.007
CVE-2023-5853
Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-11-01 · Modified
4.3EPSS 0.007
CVE-2023-42453
Improper validation of receipts allows forged read receipts in matrix synapse
Published 2023-09-26 · Modified
4.3EPSS 0.007
CVE-2023-2464
Inappropriate implementation in PictureInPicture in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to perform an origin spoof in the security UI via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
4.3EPSS 0.006
CVE-2023-4908
Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2023-4909
Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2023-4904
Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)
Published 2023-09-12 · Modified
4.3EPSS 0.006
CVE-2022-2611
Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Published 2022-08-12 · Modified
4.3EPSS 0.006
CVE-2023-5859
Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)
Published 2023-11-01 · Modified
4.3EPSS 0.006
← Prev17 / 18Next →