VendorsFedora Projectfedora34
Vulnerabilities

Fedora Project Fedora 34

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1181CVEs
CVE-2021-21393
Denial of service (via resource exhaustion) due to improper input validation on groups/communities endpoints
Published 2021-04-12 · Modified
6.5EPSS 0.016
CVE-2021-29470
Out-of-bounds read in Exiv2::Jp2Image::encodeJp2Header
Published 2021-04-23 · Modified
6.5EPSS 0.016
CVE-2021-21221
Insufficient validation of untrusted input in Mojo in Google Chrome prior to 90.0.4430.72 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.
Published 2021-04-26 · Modified
6.5EPSS 0.016
CVE-2021-21394
Denial of service (via resource exhaustion) due to improper input validation on third-party identifier endpoints
Published 2021-04-12 · Modified
6.5EPSS 0.015
CVE-2022-0996
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
Published 2022-03-23 · Modified
6.5EPSS 0.015
CVE-2020-28463
Server-side Request Forgery (SSRF)
Published 2021-02-18 · Modified
6.5EPSS 0.015
CVE-2022-0117
Policy bypass in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2022-02-11 · Modified
6.5EPSS 0.015
CVE-2021-3677
A flaw was found in postgresql. A purpose-crafted query can read arbitrary bytes of server memory. In the default configuration, any authenticated database user can complete this attack at will. The attack does not require the ability to create objects. If server settings include max_worker_processes=0, the known versions of this attack are infeasible. However, undiscovered variants of the attack may be independent of that setting.
Published 2022-03-02 · Modified
6.5EPSS 0.014
CVE-2021-30540
Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Published 2021-06-07 · Modified
6.5EPSS 0.014
CVE-2021-41270
CSV Injection in Symfony
Published 2021-11-24 · Modified
6.5EPSS 0.014
CVE-2021-21208
Insufficient data validation in QR scanner in Google Chrome on iOS prior to 90.0.4430.72 allowed an attacker displaying a QR code to perform domain spoofing via a crafted QR code.
Published 2021-04-26 · Modified
6.5EPSS 0.014
CVE-2021-30580
Insufficient policy enforcement in Android intents in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious application to obtain potentially sensitive information via a crafted HTML page.
Published 2021-08-03 · Modified
6.5EPSS 0.013
CVE-2022-0109
Inappropriate implementation in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.
Published 2022-02-11 · Modified
6.5EPSS 0.013
CVE-2022-1706
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible workaround is to not put secrets in the Ignition config.
Published 2022-05-17 · Modified
6.5EPSS 0.013
CVE-2021-4068
Insufficient data validation in new tab page in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.013
CVE-2021-4059
Insufficient data validation in loader in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.013
CVE-2021-43337
SchedMD Slurm 21.08.* before 21.08.4 has Incorrect Access Control. On sites using the new AccountingStoreFlags=job_script and/or job_env options, the access control rules in SlurmDBD may permit users to request job scripts and environment files to which they should not have access.
Published 2021-11-17 · Modified
6.5EPSS 0.012
CVE-2021-30534
Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Published 2021-06-07 · Modified
6.5EPSS 0.012
CVE-2021-20205
Libjpeg-turbo versions 2.0.91 and 2.0.90 is vulnerable to a denial of service vulnerability caused by a divide by zero when processing a crafted GIF image.
Published 2021-03-10 · Modified
6.5EPSS 0.012
CVE-2021-4054
Incorrect security UI in autofill in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.012
CVE-2021-21175
Inappropriate implementation in Site isolation in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-03-09 · Modified
6.5EPSS 0.012
CVE-2021-27836
An issue was discoverered in in function xls_getWorkSheet in xls.c in libxls 1.6.2, allows attackers to cause a denial of service, via a crafted XLS file.
Published 2021-11-03 · Modified
6.5EPSS 0.012
CVE-2022-0108
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2022-02-11 · Modified
6.5EPSS 0.011
CVE-2020-35884
An issue was discovered in the tiny_http crate through 2020-06-16 for Rust. HTTP Request smuggling can occur via a malformed Transfer-Encoding header.
Published 2020-12-31 · Modified
6.5EPSS 0.011
CVE-2021-4024
A flaw was found in podman. The `podman machine` function (used to create and manage Podman virtual machine containing a Podman process) spawns a `gvproxy` process on the host system. The `gvproxy` API is accessible on port 7777 on all IP addresses on the host. If that port is open on the host's firewall, an attacker can potentially use the `gvproxy` API to forward ports on the host to ports in the VM, making private services on the VM accessible to the network. This issue could be also used to interrupt the host's services by forwarding all ports to the VM.
Published 2021-12-23 · Modified
6.5EPSS 0.011
CVE-2021-21211
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-04-26 · Modified
6.5EPSS 0.010
CVE-2021-21209
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-04-26 · Modified
6.5EPSS 0.010
CVE-2021-21163
Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server.
Published 2021-03-09 · Modified
6.5EPSS 0.009
CVE-2021-38010
Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.009
CVE-2022-0113
Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2022-02-11 · Modified
6.5EPSS 0.009
CVE-2021-38022
Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.009
CVE-2021-21229
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Published 2021-04-30 · Modified
6.5EPSS 0.009
CVE-2021-38009
Inappropriate implementation in cache in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.008
CVE-2021-38019
Insufficient policy enforcement in CORS in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.008
CVE-2021-21164
Insufficient data validation in Chrome on iOS in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-03-09 · Modified
6.5EPSS 0.008
CVE-2022-0111
Inappropriate implementation in Navigation in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to incorrectly set origin via a crafted HTML page.
Published 2022-02-11 · Modified
6.5EPSS 0.008
CVE-2021-3658
bluetoothd from bluez incorrectly saves adapters' Discoverable status when a device is powered down, and restores it when powered up. If a device is powered down while discoverable, it will be discoverable when powered on again. This could lead to inadvertent exposure of the bluetooth stack to physically nearby attackers.
Published 2022-03-02 · Modified
6.5EPSS 0.008
CVE-2021-38021
Inappropriate implementation in referrer in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.008
CVE-2021-38018
Inappropriate implementation in navigation in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.008
CVE-2022-0120
Inappropriate implementation in Passwords in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially leak cross-origin data via a malicious website.
Published 2022-02-11 · Modified
6.5EPSS 0.008
← Prev21 / 30Next →