VendorsFedora Projectfedora37
Vulnerabilities

Fedora Project Fedora 37

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

698CVEs
CVE-2023-22945
In the GrowthExperiments extension for MediaWiki through 1.39, the growthmanagementorlist API allows blocked users (blocked in ApiManageMentorList) to enroll as mentors or edit any of their mentorship-related properties.
Published 2023-01-11 · Modified
4.3EPSS 0.005
CVE-2022-2619
Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.
Published 2022-08-12 · Modified
4.3EPSS 0.004
CVE-2023-20867
VMware Tools Authentication Bypass Vulnerability
Published 2023-06-13 · Analyzed
3.9KEVEPSS 0.135
CVE-2023-45143
Undici's cookie header not cleared on cross-origin redirect in fetch
Published 2023-10-12 · Modified
3.9EPSS 0.012
CVE-2022-33747
Arm: unbounded memory consumption for 2nd-level page tables Certain actions require e.g. removing pages from a guest's P2M (Physical-to-Machine) mapping. When large pages are in use to map guest pages in the 2nd-stage page tables, such a removal operation may incur a memory allocation (to replace a large mapping with individual smaller ones). These memory allocations are taken from the global memory pool. A malicious guest might be able to cause the global memory pool to be exhausted by manipulating its own P2M mappings.
Published 2022-10-11 · Modified
3.8EPSS 0.003
CVE-2023-31124
AutoTools does not set CARES_RANDOM_FILE during cross compilation
Published 2023-05-25 · Modified
3.7EPSS 0.009
CVE-2023-41335
Temporary storage of plaintext passwords during password changes in matrix synapse
Published 2023-09-26 · Modified
3.7EPSS 0.004
CVE-2023-45145
Redis Unix-domain socket may have be exposed with the wrong permissions for a short time window.
Published 2023-10-18 · Modified
3.6EPSS 0.004
CVE-2023-25815
Git looks for localized messages in the wrong place
Published 2023-04-25 · Modified
3.3EPSS 0.010
CVE-2021-3574
A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.
Published 2022-08-26 · Modified
3.3EPSS 0.005
CVE-2023-39978
ImageMagick before 6.9.12-91 allows attackers to cause a denial of service (memory consumption) in Magick::Draw.
Published 2023-08-08 · Modified
3.3EPSS 0.004
CVE-2023-2602
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
Published 2023-06-06 · Modified
3.3EPSS 0.004
CVE-2022-4123
A flaw was found in Buildah. The local path and the lowest subdirectory may be disclosed due to incorrect absolute path traversal, resulting in an impact to confidentiality.
Published 2022-12-08 · Modified
3.3EPSS 0.002
CVE-2023-1513
A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak.
Published 2023-03-23 · Modified
3.3EPSS 0.002
CVE-2020-14394
An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.
Published 2022-08-17 · Modified
3.2EPSS 0.004
CVE-2023-22048
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are affected are 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N).
Published 2023-07-18 · Modified
3.1EPSS 0.010
CVE-2023-22038
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
Published 2023-07-18 · Modified
2.7EPSS 0.009
CVE-2021-3923
A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel stack information when issuing commands to the /dev/infiniband/rdma_cm device node. While this access is unlikely to leak sensitive user information, it can be further used to defeat existing kernel protection mechanisms.
Published 2023-03-27 · Modified
2.3EPSS 0.002
← Prev18 / 18