VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2019-3846
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
Published 2019-06-03 · Modified
8.8EPSS 0.056
CVE-2021-30599
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Published 2021-08-26 · Modified
8.8EPSS 0.054
CVE-2016-3068
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted git ext:: URL when cloning a subrepository.
Published 2016-04-13 · Modified
8.8EPSS 0.054
CVE-2016-3069
Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a crafted name when converting a Git repository.
Published 2016-04-13 · Modified
8.8EPSS 0.050
CVE-2024-5841
Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-06-11 · Modified
8.8EPSS 0.050
CVE-2020-13584
An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs to visit a malicious web site to trigger this vulnerability.
Published 2020-12-03 · Modified
8.8EPSS 0.049
CVE-2022-29221
PHP Code Injection by malicious block or filename in Smarty
Published 2022-05-24 · Modified
8.8EPSS 0.049
CVE-2016-3630
The binary delta decoder in Mercurial before 3.7.3 allows remote attackers to execute arbitrary code via a (1) clone, (2) push, or (3) pull command, related to (a) a list sizing rounding error and (b) short records.
Published 2016-04-13 · Modified
8.8EPSS 0.049
CVE-2020-24972
The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an arbitrary DLL.
Published 2020-08-29 · Modified
8.8EPSS 0.048
CVE-2016-5157
Heap-based buffer overflow in the opj_dwt_interleave_v function in dwt.c in OpenJPEG, as used in PDFium in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux, allows remote attackers to execute arbitrary code via crafted coordinate values in JPEG 2000 data.
Published 2016-09-11 · Modified
8.8EPSS 0.047
CVE-2021-22879
Nextcloud Desktop Client prior to 3.1.3 is vulnerable to resource injection by way of missing validation of URLs, allowing a malicious server to execute remote commands. User interaction is needed for exploitation.
Published 2021-04-14 · Modified
8.8EPSS 0.047
CVE-2021-29472
Missing argument delimiter can lead to code execution via VCS repository URLs or source download URLs on systems with Mercurial in composer
Published 2021-04-27 · Modified
8.8EPSS 0.046
CVE-2020-35701
An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.
Published 2021-01-11 · Modified
8.8EPSS 0.046
CVE-2018-1000877
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-415: Double Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c, parse_codes(), realloc(rar->lzss.window, new_size) with new_size = 0 that can result in Crash/DoS. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
Published 2018-12-20 · Modified
8.8EPSS 0.046
CVE-2021-39139
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.8EPSS 0.045
CVE-2021-30614
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
Published 2021-09-03 · Modified
8.8EPSS 0.045
CVE-2018-1000878
libarchive version commit 416694915449219d505531b1096384f3237dd6cc onwards (release v3.1.0 onwards) contains a CWE-416: Use After Free vulnerability in RAR decoder - libarchive/archive_read_support_format_rar.c that can result in Crash/DoS - it is unknown if RCE is possible. This attack appear to be exploitable via the victim must open a specially crafted RAR archive.
Published 2018-12-20 · Modified
8.8EPSS 0.044
CVE-2021-32625
Redis vulnerability in STRALGO LCS on 32-bit systems
Published 2021-06-02 · Modified
8.8EPSS 0.043
CVE-2023-5528
Kubernetes - Windows nodes - Insufficient input sanitization in in-tree storage plugin leads to privilege escalation
Published 2023-11-14 · Analyzed
8.8EPSS 0.043
CVE-2011-2692
The png_handle_sCAL function in pngrutil.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 does not properly handle invalid sCAL chunks, which allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted PNG image that triggers the reading of uninitialized memory.
Published 2011-07-17 · Modified
8.8EPSS 0.042
CVE-2022-1227
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
Published 2022-04-29 · Modified
8.8EPSS 0.042
CVE-2021-29477
Vulnerability in the STRALGO LCS command
Published 2021-05-04 · Modified
8.8EPSS 0.042
CVE-2021-30609
Chromium: CVE-2021-30609 Use after free in Sign-In
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30616
Chromium: CVE-2021-30616 Use after free in Media
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30610
Chromium: CVE-2021-30610 Use after free in Extensions API
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30624
Chromium: CVE-2021-30624 Use after free in Autofill
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30613
Chromium: CVE-2021-30613 Use after free in Base internals
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30606
Chromium: CVE-2021-30606 Use after free in Blink
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30620
Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30607
Chromium: CVE-2021-30607 Use after free in Permissions
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30618
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2022-24407
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Published 2022-02-23 · Modified
8.8EPSS 0.041
CVE-2021-33477
rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.
Published 2021-05-20 · Modified
8.8EPSS 0.041
CVE-2021-30622
Chromium: CVE-2021-30622 Use after free in WebApp Installs
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30608
Chromium: CVE-2021-30608 Use after free in Web Share
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2016-1521
The directrun function in directmachine.cpp in Libgraphite in Graphite 2 1.2.4, as used in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.6.1, does not validate a certain skip operation, which allows remote attackers to execute arbitrary code, obtain sensitive information, or cause a denial of service (out-of-bounds read and application crash) via a crafted Graphite smart font.
Published 2016-02-13 · Modified
8.8EPSS 0.041
CVE-2019-9278
In libexif, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege in the media content provider with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112537774
Published 2019-09-27 · Modified
8.8EPSS 0.041
CVE-2021-30623
Chromium: CVE-2021-30623 Use after free in Bookmarks
Published 2021-09-03 · Modified
8.8EPSS 0.040
CVE-2019-13734
Out of bounds write in SQLite in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2019-12-10 · Modified
8.8EPSS 0.039
CVE-2024-0519
Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-01-16 · Analyzed
8.8KEVEPSS 0.038
← Prev18 / 135Next →