VendorsFedora Projectfedora38
Vulnerabilities

Fedora Project Fedora 38

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

640CVEs
CVE-2023-5187
Use after free in Extensions in Google Chrome prior to 117.0.5938.132 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-28 · Modified
8.8EPSS 0.008
CVE-2024-1938
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-02-29 · Analyzed
8.8EPSS 0.008
CVE-2023-1530
Use after free in PDF in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-03-21 · Modified
8.8EPSS 0.008
CVE-2024-1673
Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via specific UI gestures. (Chromium security severity: Medium)
Published 2024-02-21 · Analyzed
8.8EPSS 0.008
CVE-2024-1674
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-02-21 · Modified
8.8EPSS 0.008
CVE-2023-5686
Heap-based Buffer Overflow in radareorg/radare2
Published 2023-10-20 · Modified
8.8EPSS 0.008
CVE-2023-6186
Link targets allow arbitrary script execution
Published 2023-12-11 · Modified
8.8EPSS 0.008
CVE-2023-1528
Use after free in Passwords in Google Chrome prior to 111.0.5563.110 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-03-21 · Modified
8.8EPSS 0.008
CVE-2023-2461
Use after free in OS Inputs in Google Chrome on ChromeOS prior to 113.0.5672.63 allowed a remote attacker who convinced a user to enage in specific UI interaction to potentially exploit heap corruption via crafted UI interaction. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
8.8EPSS 0.008
CVE-2024-2400
Use after free in Performance Manager in Google Chrome prior to 122.0.6261.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-03-13 · Analyzed
8.8EPSS 0.007
CVE-2023-2726
Inappropriate implementation in WebApp Installs in Google Chrome prior to 113.0.5672.126 allowed an attacker who convinced a user to install a malicious web app to bypass install dialog via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-16 · Modified
8.8EPSS 0.007
CVE-2023-4366
Use after free in Extensions in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-15 · Modified
8.8EPSS 0.007
CVE-2024-25982
Msa-24-0005: csrf risk in language import utility
Published 2024-02-19 · Analyzed
8.8EPSS 0.005
CVE-2024-0812
Inappropriate implementation in Accessibility in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-01-23 · Modified
8.8EPSS 0.005
CVE-2024-0807
Use after free in Web Audio in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-01-23 · Modified
8.8EPSS 0.005
CVE-2024-0806
Use after free in Passwords in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
Published 2024-01-23 · Modified
8.8EPSS 0.004
CVE-2024-0813
Use after free in Reading Mode in Google Chrome prior to 121.0.6167.85 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via specific UI interaction. (Chromium security severity: Medium)
Published 2024-01-23 · Modified
8.8EPSS 0.004
CVE-2024-25111
SQUID-2024:1 Denial of Service in HTTP Chunked Decoding
Published 2024-03-06 · Modified
8.6EPSS 0.653
CVE-2024-25713
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)
Published 2024-02-11 · Modified
8.6EPSS 0.018
CVE-2023-3823
Security issue with external entity loading in XML without enabling it
Published 2023-08-11 · Modified
8.6EPSS 0.016
CVE-2024-34402
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
Published 2024-05-03 · Modified
8.6EPSS 0.012
CVE-2022-42333
x86/HVM pinned cache attributes mis-handling T[his CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To allow cachability control for HVM guests with passed through devices, an interface exists to explicitly override defaults which would otherwise be put in place. While not exposed to the affected guests themselves, the interface specifically exists for domains controlling such guests. This interface may therefore be used by not fully privileged entities, e.g. qemu running deprivileged in Dom0 or qemu running in a so called stub-domain. With this exposure it is an issue that - the number of the such controlled regions was unbounded (CVE-2022-42333), - installation and removal of such regions was not properly serialized (CVE-2022-42334).
Published 2023-03-21 · Modified
8.6EPSS 0.012
CVE-2023-6246
Glibc: heap-based buffer overflow in __vsyslog_internal()
Published 2024-01-31 · Modified
8.4EPSS 0.048
CVE-2023-6779
Glibc: off-by-one heap-based buffer overflow in __vsyslog_internal()
Published 2024-01-31 · Modified
8.2EPSS 0.032
CVE-2023-35934
yt-dlp File Downloader cookie leak
Published 2023-07-06 · Modified
8.2EPSS 0.010
CVE-2024-28960
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
Published 2024-03-29 · Modified
8.2EPSS 0.008
CVE-2024-27018
netfilter: br_netfilter: skip conntrack input hook for promisc packets
Published 2024-05-01 · Modified
8.2EPSS 0.006
CVE-2023-39191
Kernel: ebpf: insufficient stack type checks in dynptr
Published 2023-10-04 · Modified
8.2EPSS 0.005
CVE-2022-46329
Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
8.2EPSS 0.003
CVE-2022-27635
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
8.2EPSS 0.002
CVE-2023-4427
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-08-22 · Modified
8.1EPSS 0.344
CVE-2024-2887
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2024-03-26 · Modified
8.1EPSS 0.179
CVE-2023-4428
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-08-22 · Modified
8.1EPSS 0.113
CVE-2018-1311
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
Published 2019-12-18 · Modified
8.1EPSS 0.095
CVE-2023-41056
Redis vulnerable to integer overflow in certain payloads
Published 2024-01-10 · Modified
8.1EPSS 0.026
CVE-2023-33170
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
Published 2023-07-11 · Modified
8.1EPSS 0.020
CVE-2023-39323
Arbitrary code execution during build via line directives in cmd/go
Published 2023-10-05 · Modified
8.1EPSS 0.018
CVE-2024-23263
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Published 2024-03-08 · Modified
8.1EPSS 0.015
CVE-2023-4761
Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-05 · Modified
8.1EPSS 0.012
CVE-2023-41915
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
Published 2023-09-09 · Modified
8.1EPSS 0.012
← Prev5 / 16Next →