VendorsFedora Projectfedora35
Vulnerabilities

Fedora Project Fedora 35

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1095CVEs
CVE-2021-30599
Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Published 2021-08-26 · Modified
8.8EPSS 0.054
CVE-2021-39139
XStream is vulnerable to an Arbitrary Code Execution attack
Published 2021-08-23 · Analyzed
8.8EPSS 0.045
CVE-2021-30614
Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip
Published 2021-09-03 · Modified
8.8EPSS 0.045
CVE-2022-1227
A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the attacker access to the host filesystem, leading to information disclosure or denial of service.
Published 2022-04-29 · Modified
8.8EPSS 0.042
CVE-2021-30616
Chromium: CVE-2021-30616 Use after free in Media
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30609
Chromium: CVE-2021-30609 Use after free in Sign-In
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30610
Chromium: CVE-2021-30610 Use after free in Extensions API
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30606
Chromium: CVE-2021-30606 Use after free in Blink
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30607
Chromium: CVE-2021-30607 Use after free in Permissions
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30613
Chromium: CVE-2021-30613 Use after free in Base internals
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30618
Chromium: CVE-2021-30618 Inappropriate implementation in DevTools
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30624
Chromium: CVE-2021-30624 Use after free in Autofill
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30620
Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2022-24407
In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.
Published 2022-02-23 · Modified
8.8EPSS 0.041
CVE-2021-30608
Chromium: CVE-2021-30608 Use after free in Web Share
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30622
Chromium: CVE-2021-30622 Use after free in WebApp Installs
Published 2021-09-03 · Modified
8.8EPSS 0.041
CVE-2021-30623
Chromium: CVE-2021-30623 Use after free in Bookmarks
Published 2021-09-03 · Modified
8.8EPSS 0.040
CVE-2022-21664
SQL injection in WordPress
Published 2022-01-06 · Modified
8.8EPSS 0.038
CVE-2022-39260
Git vulnerable to Remote Code Execution via Heap overflow in `git shell`
Published 2022-10-19 · Modified
8.8EPSS 0.033
CVE-2021-21897
A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-09-08 · Modified
8.8EPSS 0.029
CVE-2021-30590
Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-08-26 · Modified
8.8EPSS 0.028
CVE-2021-30611
Chromium: CVE-2021-30611 Use after free in WebRTC
Published 2021-09-03 · Modified
8.8EPSS 0.028
CVE-2021-21899
A code execution vulnerability exists in the dwgCompressor::copyCompBytes21 functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-11-19 · Modified
8.8EPSS 0.028
CVE-2021-30612
Chromium: CVE-2021-30612 Use after free in WebRTC
Published 2021-09-03 · Modified
8.8EPSS 0.028
CVE-2021-21898
A code execution vulnerability exists in the dwgCompressor::decompress18() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dwg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-11-19 · Modified
8.8EPSS 0.026
CVE-2021-21900
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.
Published 2021-11-19 · Modified
8.8EPSS 0.025
CVE-2021-30600
Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Published 2021-08-26 · Modified
8.8EPSS 0.025
CVE-2021-30591
Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-08-26 · Modified
8.8EPSS 0.025
CVE-2021-30604
Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-08-26 · Modified
8.8EPSS 0.025
CVE-2021-33621
The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that use untrusted user input either to generate an HTTP response or to create a CGI::Cookie object.
Published 2022-11-18 · Modified
8.8EPSS 0.024
CVE-2018-20545
There is an illegal WRITE memory access at common-image.c (function load_image) in libcaca 0.99.beta19 for 4bpp data.
Published 2018-12-28 · Modified
8.8EPSS 0.024
CVE-2022-21703
Cross Site Request Forgery in Grafana
Published 2022-02-08 · Modified
8.8EPSS 0.023
CVE-2021-30602
Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.
Published 2021-08-26 · Modified
8.8EPSS 0.021
CVE-2021-30951
A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
8.8EPSS 0.020
CVE-2021-30592
Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
Published 2021-08-26 · Modified
8.8EPSS 0.020
CVE-2021-30588
Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Published 2021-08-03 · Modified
8.8EPSS 0.020
CVE-2021-30601
Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Published 2021-08-26 · Modified
8.8EPSS 0.019
CVE-2021-30953
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.
Published 2021-08-24 · Modified
8.8EPSS 0.019
CVE-2021-44648
GNOME gdk-pixbuf 2.42.6 is vulnerable to a heap-buffer overflow vulnerability when decoding the lzw compressed stream of image data in GIF files with lzw minimum code size equals to 12.
Published 2022-01-12 · Modified
8.8EPSS 0.019
CVE-2021-30565
Out of bounds write in Tab Groups in Google Chrome on Linux and ChromeOS prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.
Published 2021-08-03 · Modified
8.8EPSS 0.019
← Prev4 / 28Next →