VendorsFedora Projectfedora40
Vulnerabilities

Fedora Project Fedora 40

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

244CVEs
CVE-2024-4060
Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-01 · Modified
7.5EPSS 0.010
CVE-2024-1622
Routinator terminates when RTR connection is reset too quickly after opening
Published 2024-02-26 · Analyzed
7.5EPSS 0.010
CVE-2024-28084
p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.
Published 2024-03-03 · Modified
7.5EPSS 0.009
CVE-2024-34506
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service.
Published 2024-05-05 · Modified
7.5EPSS 0.009
CVE-2024-31031
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
Published 2024-04-17 · Modified
7.5EPSS 0.009
CVE-2024-3840
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-04-17 · Analyzed
7.5EPSS 0.009
CVE-2023-42843
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
Published 2024-02-21 · Analyzed
7.5EPSS 0.009
CVE-2024-4854
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Published 2024-05-14 · Modified
7.5EPSS 0.008
CVE-2024-34507
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.
Published 2024-05-05 · Modified
7.4EPSS 0.007
CVE-2024-28184
WeasyPrint allows the attachment of arbitrary files and URLs to a PDF
Published 2024-03-09 · Analyzed
7.4EPSS 0.006
CVE-2024-4216
XSS vulnerability in /settings/store API response json payload in pgAdmin 4
Published 2024-05-02 · Analyzed
7.4EPSS 0.005
CVE-2023-38709
Apache HTTP Server: HTTP response splitting
Published 2024-04-04 · Modified
7.3EPSS 0.039
CVE-2024-29131
Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Published 2024-03-21 · Analyzed
7.3EPSS 0.021
CVE-2023-3758
Sssd: race condition during authorization leads to gpo policies functioning inconsistently
Published 2024-04-18 · Modified
7.1EPSS 0.010
CVE-2024-32021
Local Git clone may hardlink arbitrary user-readable files into the new repository's "objects/" directory
Published 2024-05-14 · Analyzed
7.1EPSS 0.010
CVE-2024-27016
netfilter: flowtable: validate pppoe header
Published 2024-05-01 · Modified
7.1EPSS 0.003
CVE-2023-29483
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
Published 2024-04-11 · Modified
7.0EPSS 0.019
CVE-2023-51797
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame
Published 2024-04-19 · Analyzed
6.7EPSS 0.004
CVE-2023-46842
x86 HVM hypercalls may trigger Xen bug check
Published 2024-05-16 · Analyzed
6.5EPSS 0.085
CVE-2024-25082
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.
Published 2024-02-26 · Modified
6.5EPSS 0.019
CVE-2024-23284
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Published 2024-03-08 · Modified
6.5EPSS 0.015
CVE-2024-31208
Synapse's V2 state resolution weakness allows DoS from remote room members
Published 2024-04-23 · Analyzed
6.5EPSS 0.015
CVE-2024-23254
The issue was addressed with improved UI handling. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. A malicious website may exfiltrate audio data cross-origin.
Published 2024-03-08 · Modified
6.5EPSS 0.013
CVE-2024-25569
An out-of-bounds read vulnerability exists in the RAWCodec::DecodeBytes functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to an out-of-bounds read. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-04-25 · Modified
6.5EPSS 0.011
CVE-2024-4950
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published 2024-05-15 · Modified
6.5EPSS 0.009
CVE-2024-4059
Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-01 · Modified
6.5EPSS 0.009
CVE-2024-32760
NGINX HTTP/3 QUIC vulnerability
Published 2024-05-29 · Analyzed
6.5EPSS 0.009
CVE-2024-2630
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
6.5EPSS 0.008
CVE-2024-2626
Out of bounds read in Swiftshader in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
6.5EPSS 0.008
CVE-2024-3515
Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-04-10 · Analyzed
6.5EPSS 0.008
CVE-2023-43279
Null Pointer Dereference in mask_cidr6 component at cidr.c in Tcpreplay 4.4.4 allows attackers to crash the application via crafted tcprewrite command.
Published 2024-03-12 · Modified
6.5EPSS 0.007
CVE-2023-5455
Ipa: invalid csrf protection
Published 2024-01-10 · Modified
6.5EPSS 0.006
CVE-2024-5840
Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-06-11 · Modified
6.5EPSS 0.004
CVE-2023-46841
x86: shadow stack vs exceptions from emulation stubs
Published 2024-03-20 · Modified
6.5EPSS 0.003
CVE-2024-24795
Apache HTTP Server: HTTP Response Splitting in multiple modules
Published 2024-04-04 · Analyzed
6.3EPSS 0.029
CVE-2024-23672
Apache Tomcat: WebSocket DoS with incomplete closing handshake
Published 2024-03-13 · Modified
6.3EPSS 0.023
CVE-2024-27306
aiohttp vulnerable to XSS on index pages for static file handling
Published 2024-04-18 · Modified
6.1EPSS 0.007
CVE-2024-34500
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class.
Published 2024-05-05 · Modified
6.1EPSS 0.005
CVE-2024-38274
moodle: stored XSS via calendar's event title when deleting the event
Published 2024-06-18 · Analyzed
6.1EPSS 0.004
CVE-2024-31497
In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of signed messages may be publicly readable because they are stored in a public Git service that supports use of SSH for commit signing, and the signatures were made by Pageant through an agent-forwarding mechanism. In other words, an adversary may already have enough signature information to compromise a victim's private key, even if there is no further use of vulnerable PuTTY versions. After a key compromise, an adversary may be able to conduct supply-chain attacks on software maintained in Git. A second, independent scenario is that the adversary is an operator of an SSH server to which the victim authenticates (for remote login or file copy), even though this server is not fully trusted by the victim, and the victim uses the same private key for SSH connections to other services operated by other entities. Here, the rogue server operator (who would otherwise have no way to determine the victim's private key) can derive the victim's private key, and then use it for unauthorized access to those other services. If the other services include Git services, then again it may be possible to conduct supply-chain attacks on software maintained in Git. This also affects, for example, FileZilla before 3.67.0, WinSCP before 6.3.3, TortoiseGit before 2.15.0.1, and TortoiseSVN through 1.14.6.
Published 2024-04-15 · Modified
5.9EPSS 0.058
← Prev5 / 7Next →