VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2021-21289
Command Injection Vulnerability in Mechanize
Published 2021-02-02 · Modified
8.3EPSS 0.035
CVE-2010-3705
The sctp_auth_asoc_get_hmac function in net/sctp/auth.c in the Linux kernel before 2.6.36 does not properly validate the hmac_ids array of an SCTP peer, which allows remote attackers to cause a denial of service (memory corruption and panic) via a crafted value in the last element of this array.
Published 2010-11-26 · Modified
8.3EPSS 0.020
CVE-2020-6575
Race in Mojo in Google Chrome prior to 85.0.4183.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2020-09-21 · Modified
8.3EPSS 0.014
CVE-2020-13379
The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information about the network that Grafana is running on. Furthermore, passing invalid URL objects could be used for DOS'ing Grafana via SegFault.
Published 2020-06-03 · Modified
8.21 PoCEPSS 0.999
CVE-2021-44224
Possible NULL dereference or SSRF in forward proxy configurations in Apache HTTP Server 2.4.51 and earlier
Published 2021-12-20 · Modified
8.2EPSS 0.823
CVE-2020-11987
Apache Batik 1.13 is vulnerable to server-side request forgery, caused by improper input validation by the NodePickerPanel. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests.
Published 2021-02-24 · Modified
8.2EPSS 0.133
CVE-2020-10543
Perl before 5.30.3 on 32-bit platforms allows a heap-based buffer overflow because nested regular expression quantifiers have an integer overflow.
Published 2020-06-05 · Modified
8.2EPSS 0.113
CVE-2020-11988
Apache XmlGraphics Commons 2.4 and earlier is vulnerable to server-side request forgery, caused by improper input validation by the XMPParser. By using a specially-crafted argument, an attacker could exploit this vulnerability to cause the underlying server to make arbitrary GET requests. Users should upgrade to 2.6 or later.
Published 2021-02-24 · Modified
8.2EPSS 0.067
CVE-2023-6779
Glibc: off-by-one heap-based buffer overflow in __vsyslog_internal()
Published 2024-01-31 · Modified
8.2EPSS 0.032
CVE-2019-16789
HTTP Request Smuggling in Waitress: Invalid whitespace characters in headers
Published 2019-12-26 · Modified
8.2EPSS 0.026
CVE-2021-43818
HTML Cleaner allows crafted and SVG embedded scripts to pass through
Published 2021-12-13 · Modified
8.2EPSS 0.025
CVE-2012-1168
Moodle before 2.2.2 has a password and web services issue where when the user profile is updated the user password is reset if not specified.
Published 2019-11-14 · Modified
8.2EPSS 0.023
CVE-2020-36323
In the standard library in Rust before 1.52.0, there is an optimization for joining strings that can cause uninitialized bytes to be exposed (or the program to crash) if the borrowed string changes after its length is checked.
Published 2021-04-14 · Modified
8.2EPSS 0.020
CVE-2021-3796
Use After Free in vim/vim
Published 2021-09-15 · Modified
8.2EPSS 0.017
CVE-2021-21381
Sandbox escape via special tokens in .desktop file
Published 2021-03-11 · Modified
8.2EPSS 0.015
CVE-2021-41164
Advanced Content Filter (ACF) vulnerability allowing to execute JavaScript code using malformed HTML
Published 2021-11-17 · Modified
8.2EPSS 0.013
CVE-2021-21332
Cross-site scripting (XSS) vulnerability in the password reset endpoint
Published 2021-03-26 · Modified
8.2EPSS 0.012
CVE-2020-25632
A flaw was found in grub2 in versions prior to 2.06. The rmmod implementation allows the unloading of a module used as a dependency without checking if any other dependent module is still loaded leading to a use-after-free scenario. This could allow arbitrary code to be executed or a bypass of Secure Boot protections. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-03-03 · Modified
8.2EPSS 0.012
CVE-2023-35934
yt-dlp File Downloader cookie leak
Published 2023-07-06 · Modified
8.2EPSS 0.010
CVE-2024-28960
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
Published 2024-03-29 · Modified
8.2EPSS 0.008
CVE-2021-32677
Cross-Site Request Forgery (CSRF) in FastAPI
Published 2021-06-09 · Modified
8.2EPSS 0.007
CVE-2021-3929
A DMA reentrancy issue was found in the NVM Express Controller (NVME) emulation in QEMU. This CVE is similar to CVE-2021-3750 and, just like it, when the reentrancy write triggers the reset function nvme_ctrl_reset(), data structs will be freed leading to a use-after-free issue. A malicious guest could use this flaw to crash the QEMU process on the host, resulting in a denial of service condition or, potentially, executing arbitrary code within the context of the QEMU process on the host.
Published 2022-08-25 · Modified
8.2EPSS 0.007
CVE-2024-27018
netfilter: br_netfilter: skip conntrack input hook for promisc packets
Published 2024-05-01 · Modified
8.2EPSS 0.006
CVE-2021-20233
A flaw was found in grub2 in versions prior to 2.06. Setparam_prefix() in the menu rendering code performs a length calculation on the assumption that expressing a quoted single quote will require 3 characters, while it actually requires 4 characters which allows an attacker to corrupt memory by one byte for each quote in the input. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-03-03 · Modified
8.2EPSS 0.006
CVE-2023-39191
Kernel: ebpf: insufficient stack type checks in dynptr
Published 2023-10-04 · Modified
8.2EPSS 0.005
CVE-2021-4120
snapd could be made to bypass intended access restrictions through snap content interfaces and layout paths
Published 2022-02-17 · Modified
8.2EPSS 0.004
CVE-2022-46329
Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
8.2EPSS 0.003
CVE-2022-27635
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
8.2EPSS 0.002
CVE-2020-8625
A vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
Published 2021-02-17 · Modified
8.1EPSS 0.642
CVE-2016-5387
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, aka an "httpoxy" issue. NOTE: the vendor states "This mitigation has been assigned the identifier CVE-2016-5387"; in other words, this is not a CVE ID for a vulnerability.
Published 2016-07-19 · Modified
8.1EPSS 0.557
CVE-2016-5385
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy server via a crafted Proxy header in an HTTP request, as demonstrated by (1) an application that makes a getenv('HTTP_PROXY') call or (2) a CGI configuration of PHP, aka an "httpoxy" issue.
Published 2016-07-19 · Modified
8.1EPSS 0.504
CVE-2023-4427
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-08-22 · Modified
8.1EPSS 0.344
CVE-2024-2887
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2024-03-26 · Modified
8.1EPSS 0.179
CVE-2019-13115
In libssh2 before 1.9.0, kex_method_diffie_hellman_group_exchange_sha256_key_exchange in kex.c has an integer overflow that could lead to an out-of-bounds read in the way packets are read from the server. A remote attacker who compromises a SSH server may be able to disclose sensitive information or cause a denial of service condition on the client system when a user connects to the server. This is related to an _libssh2_check_length mistake, and is different from the various issues fixed in 1.8.1, such as CVE-2019-3855.
Published 2019-07-16 · Modified
8.1EPSS 0.117
CVE-2023-4428
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-08-22 · Modified
8.1EPSS 0.113
CVE-2018-1311
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
Published 2019-12-18 · Modified
8.1EPSS 0.095
CVE-2020-8265
Node.js versions before 10.23.1, 12.20.1, 14.15.4, 15.5.1 are vulnerable to a use-after-free bug in its TLS implementation. When writing to a TLS enabled socket, node::StreamBase::Write calls node::TLSWrap::DoWrite with a freshly allocated WriteWrap object as first argument. If the DoWrite method does not return an error, this object is passed back to the caller as part of a StreamWriteResult structure. This may be exploited to corrupt memory leading to a Denial of Service or potentially other exploits.
Published 2021-01-06 · Modified
8.1EPSS 0.090
CVE-2016-5421
Use-after-free vulnerability in libcurl before 7.50.1 allows attackers to control which connection is used or possibly have unspecified other impact via unknown vectors.
Published 2016-08-10 · Modified
8.1EPSS 0.080
CVE-2020-28374
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
Published 2021-01-13 · Modified
8.1EPSS 0.063
CVE-2022-32212
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
Published 2022-07-14 · Modified
8.1EPSS 0.061
← Prev36 / 135Next →