VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2023-2609
NULL Pointer Dereference in vim/vim
Published 2023-05-09 · Modified
7.8EPSS 0.005
CVE-2016-3096
The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path directory, or the (3) lxc-attach-script.log or (4) lxc-attach-script.err files in the temporary directory.
Published 2016-06-03 · Modified
7.8EPSS 0.005
CVE-2023-22970
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
Published 2023-05-26 · Modified
7.8EPSS 0.005
CVE-2023-5345
Use-after-free in Linux kernel's fs/smb/client component
Published 2023-10-03 · Analyzed
7.8EPSS 0.005
CVE-2022-38223
There is an out-of-bounds write in checkType located in etc.c in w3m 0.5.3. It can be triggered by sending a crafted HTML file to the w3m binary. It allows an attacker to cause Denial of Service or possibly have unspecified other impact.
Published 2022-08-15 · Modified
7.8EPSS 0.005
CVE-2022-41751
Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.
Published 2022-10-17 · Modified
7.8EPSS 0.005
CVE-2021-3847
An unauthorized access to the execution of the setuid file with capabilities flaw in the Linux kernel OverlayFS subsystem was found in the way user copying a capable file from a nosuid mount into another mount. A local user could use this flaw to escalate their privileges on the system.
Published 2022-04-01 · Modified
7.8EPSS 0.005
CVE-2022-0367
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
Published 2022-08-29 · Modified
7.8EPSS 0.005
CVE-2023-1127
Divide By Zero in vim/vim
Published 2023-03-01 · Modified
7.8EPSS 0.005
CVE-2022-29187
Bypass of safe.directory protections in Git
Published 2022-07-12 · Modified
7.8EPSS 0.004
CVE-2022-30788
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_mft_rec_alloc in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-30786
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_names_full_collate in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-30789
A crafted NTFS image can cause a heap-based buffer overflow in ntfs_check_log_client_array in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2022-4141
Heap-based Buffer Overflow in vim/vim
Published 2022-11-25 · Analyzed
7.8EPSS 0.004
CVE-2023-1393
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
Published 2023-03-30 · Modified
7.8EPSS 0.004
CVE-2021-39254
A crafted NTFS image can cause an integer overflow in memmove, leading to a heap-based buffer overflow in the function ntfs_attr_record_resize, in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2022-26490
st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.
Published 2022-03-06 · Analyzed
7.8EPSS 0.004
CVE-2014-3219
fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.
Published 2018-02-09 · Modified
7.8EPSS 0.004
CVE-2021-32606
In the Linux kernel 5.11 through 5.12.2, isotp_setsockopt in net/can/isotp.c allows privilege escalation to root by leveraging a use-after-free. (This does not affect earlier versions that lack CAN ISOTP SF_BROADCAST support.)
Published 2021-05-11 · Modified
7.8EPSS 0.004
CVE-2013-4251
The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.
Published 2019-11-04 · Modified
7.8EPSS 0.004
CVE-2019-13313
libosinfo 1.5.0 allows local users to discover credentials by listing a process, because credentials are passed to osinfo-install-script via the command line.
Published 2019-07-05 · Modified
7.8EPSS 0.004
CVE-2023-29403
Unsafe behavior in setuid/setgid binaries in runtime
Published 2023-06-08 · Modified
7.8EPSS 0.004
CVE-2023-43787
Libx11: integer overflow in xcreateimage() leading to a heap overflow
Published 2023-10-10 · Modified
7.8EPSS 0.004
CVE-2021-39252
A crafted NTFS image can cause an out-of-bounds read in ntfs_ie_lookup in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2009-3620
The ATI Rage 128 (aka r128) driver in the Linux kernel before 2.6.31-git11 does not properly verify Concurrent Command Engine (CCE) state initialization, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly gain privileges via unspecified ioctl calls.
Published 2009-10-22 · Modified
7.8EPSS 0.004
CVE-2018-16867
A flaw was found in qemu Media Transfer Protocol (MTP) before version 3.1.0. A path traversal in the in usb_mtp_write_data function in hw/usb/dev-mtp.c due to an improper filename sanitization. When the guest device is mounted in read-write mode, this allows to read/write arbitrary files which may lead do DoS scenario OR possibly lead to code execution on the host.
Published 2018-12-12 · Modified
7.8EPSS 0.004
CVE-2022-37047
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_ipv6_next at common/get.c:713. NOTE: this is different from CVE-2022-27940.
Published 2022-08-18 · Modified
7.8EPSS 0.004
CVE-2021-39253
A crafted NTFS image can cause an out-of-bounds read in ntfs_runlists_merge_i in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2022-37048
The component tcprewrite in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in get_l2len_protocol at common/get.c:344. NOTE: this is different from CVE-2022-27941.
Published 2022-08-18 · Modified
7.8EPSS 0.004
CVE-2022-37049
The component tcpprep in Tcpreplay v4.4.1 was discovered to contain a heap-based buffer overflow in parse_mpls at common/get.c:150. NOTE: this is different from CVE-2022-27942.
Published 2022-08-18 · Modified
7.8EPSS 0.004
CVE-2011-2520
fw_dbus.py in system-config-firewall 1.2.29 and earlier uses the pickle Python module unsafely during D-Bus communication between the GUI and the backend, which might allow local users to gain privileges via a crafted serialized object.
Published 2011-07-21 · Modified
7.8EPSS 0.004
CVE-2021-39251
A crafted NTFS image can cause a NULL pointer dereference in ntfs_extent_inode_open in NTFS-3G < 2021.8.22.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2021-33285
In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute is supplied to the function ntfs_get_attribute_value, a heap buffer overflow can occur allowing for memory disclosure or denial of service. The vulnerability is caused by an out-of-bound buffer access which can be triggered by mounting a crafted ntfs partition. The root cause is a missing consistency check after reading an MFT record : the "bytes_in_use" field should be less than the "bytes_allocated" field. When it is not, the parsing of the records proceeds into the wild.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2020-25603
An issue was discovered in Xen through 4.14.x. There are missing memory barriers when accessing/allocating an event channel. Event channels control structures can be accessed lockless as long as the port is considered to be valid. Such a sequence is missing an appropriate memory barrier (e.g., smp_*mb()) to prevent both the compiler and CPU from re-ordering access. A malicious guest may be able to cause a hypervisor crash resulting in a Denial of Service (DoS). Information leak and privilege escalation cannot be excluded. Systems running all versions of Xen are affected. Whether a system is vulnerable will depend on the CPU and compiler used to build Xen. For all systems, the presence and the scope of the vulnerability depend on the precise re-ordering performed by the compiler used to build Xen. We have not been able to survey compilers; consequently we cannot say which compiler(s) might produce vulnerable code (with which code generation options). GCC documentation clearly suggests that re-ordering is possible. Arm systems will also be vulnerable if the CPU is able to re-order memory access. Please consult your CPU vendor. x86 systems are only vulnerable if a compiler performs re-ordering.
Published 2020-09-23 · Modified
7.8EPSS 0.004
CVE-2021-33287
In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.
Published 2021-09-07 · Modified
7.8EPSS 0.004
CVE-2010-4661
udisks before 1.0.3 allows a local user to load arbitrary Linux kernel modules.
Published 2019-11-13 · Modified
7.8EPSS 0.004
CVE-2022-24958
drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.
Published 2022-02-11 · Analyzed
7.8EPSS 0.004
CVE-2022-30784
A crafted NTFS image can cause heap exhaustion in ntfs_get_attribute_value in NTFS-3G through 2021.8.22.
Published 2022-05-26 · Modified
7.8EPSS 0.004
CVE-2021-41864
prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.
Published 2021-10-01 · Analyzed
7.8EPSS 0.004
CVE-2014-7271
Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.
Published 2018-03-08 · Modified
7.8EPSS 0.004
← Prev48 / 135Next →