VendorsFedora Projectfedora39
Vulnerabilities

Fedora Project Fedora 39

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

493CVEs
CVE-2024-25111
SQUID-2024:1 Denial of Service in HTTP Chunked Decoding
Published 2024-03-06 · Modified
8.6EPSS 0.653
CVE-2024-2398
HTTP/2 push headers memory-leak
Published 2024-03-27 · Analyzed
8.6EPSS 0.361
CVE-2024-21626
runc container breakout through process.cwd trickery and leaked fds
Published 2024-01-31 · Modified
8.6EPSS 0.181
CVE-2024-25713
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)
Published 2024-02-11 · Modified
8.6EPSS 0.018
CVE-2024-34402
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
Published 2024-05-03 · Modified
8.6EPSS 0.012
CVE-2023-6246
Glibc: heap-based buffer overflow in __vsyslog_internal()
Published 2024-01-31 · Modified
8.4EPSS 0.048
CVE-2024-32462
Flatpak vulnerable to a sandbox escape via RequestBackground portal due to bad argument parsing
Published 2024-04-18 · Analyzed
8.4EPSS 0.005
CVE-2023-6779
Glibc: off-by-one heap-based buffer overflow in __vsyslog_internal()
Published 2024-01-31 · Modified
8.2EPSS 0.032
CVE-2024-28960
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
Published 2024-03-29 · Modified
8.2EPSS 0.008
CVE-2024-27018
netfilter: br_netfilter: skip conntrack input hook for promisc packets
Published 2024-05-01 · Modified
8.2EPSS 0.006
CVE-2022-46329
Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
8.2EPSS 0.003
CVE-2022-27635
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
8.2EPSS 0.002
CVE-2023-4427
Out of bounds memory access in V8 in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-08-22 · Modified
8.1EPSS 0.344
CVE-2024-2887
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2024-03-26 · Modified
8.1EPSS 0.179
CVE-2023-4428
Out of bounds memory access in CSS in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-08-22 · Modified
8.1EPSS 0.113
CVE-2018-1311
The Apache Xerces-C 3.0.0 to 3.2.3 XML parser contains a use-after-free error triggered during the scanning of external DTDs. This flaw has not been addressed in the maintained version of the library and has no current mitigation other than to disable DTD processing. This can be accomplished via the DOM using a standard parser feature, or via SAX using the XERCES_DISABLE_DTD environment variable.
Published 2019-12-18 · Modified
8.1EPSS 0.095
CVE-2023-41056
Redis vulnerable to integer overflow in certain payloads
Published 2024-01-10 · Modified
8.1EPSS 0.026
CVE-2023-39323
Arbitrary code execution during build via line directives in cmd/go
Published 2023-10-05 · Modified
8.1EPSS 0.018
CVE-2024-23263
A logic issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Published 2024-03-08 · Modified
8.1EPSS 0.015
CVE-2023-2794
Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_deliver() function
Published 2024-04-10 · Modified
8.1EPSS 0.013
CVE-2023-4761
Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-05 · Modified
8.1EPSS 0.012
CVE-2023-41915
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
Published 2023-09-09 · Modified
8.1EPSS 0.012
CVE-2023-43804
`Cookie` HTTP header isn't stripped on cross-origin redirects
Published 2023-10-04 · Modified
8.1EPSS 0.012
CVE-2023-4234
Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_submit_report() function
Published 2024-04-17 · Modified
8.1EPSS 0.011
CVE-2023-4233
Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the sms_decode_address_field() function
Published 2024-04-17 · Modified
8.1EPSS 0.010
CVE-2023-4232
Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_status_report() function
Published 2024-04-17 · Modified
8.1EPSS 0.010
CVE-2023-4431
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-22 · Modified
8.1EPSS 0.009
CVE-2024-23839
Suricata http: heap use after free with http.request_header and http.response_header keywords
Published 2024-02-26 · Analyzed
8.1EPSS 0.008
CVE-2024-27834
The issue was addressed with improved checks. This issue is fixed in Safari 17.5, iOS 16.7.8 and iPadOS 16.7.8, iOS 17.5 and iPadOS 17.5, macOS Sonoma 14.5, tvOS 17.5, watchOS 10.5. An attacker with arbitrary read and write capability may be able to bypass Pointer Authentication.
Published 2024-05-13 · Modified
8.1EPSS 0.006
CVE-2024-31458
Cacti SQL Injection vulnerability in lib/html_form_templates.php by reading dirty data stored in database
Published 2024-05-13 · Modified
8.0EPSS 0.126
CVE-2024-31459
Cacti RCE vulnerability by file include in lib/plugin.php
Published 2024-05-13 · Modified
8.0EPSS 0.027
CVE-2024-27398
Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout
Published 2024-05-13 · Modified
8.0EPSS 0.008
CVE-2023-50009
FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.
Published 2024-04-19 · Modified
8.0EPSS 0.004
CVE-2023-49528
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.
Published 2024-04-12 · Modified
8.0EPSS 0.004
CVE-2023-49501
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.
Published 2024-04-19 · Modified
8.0EPSS 0.004
CVE-2023-51795
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame
Published 2024-04-19 · Analyzed
8.0EPSS 0.003
CVE-2022-40964
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
7.9EPSS 0.002
CVE-2024-26256
Libarchive Remote Code Execution Vulnerability
Published 2024-04-09 · Analyzed
7.8EPSS 0.848
CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
Published 2023-10-03 · Analyzed
7.8KEV1 PoCEPSS 0.814
CVE-2024-1086
Use-after-free in Linux kernel's netfilter: nf_tables component
Published 2024-01-31 · Analyzed
7.8KEVEPSS 0.281
← Prev5 / 13Next →