VendorsFedora Projectfedora37
Vulnerabilities

Fedora Project Fedora 37

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

698CVEs
CVE-2023-4761
Out of bounds memory access in FedCM in Google Chrome prior to 116.0.5845.179 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2023-09-05 · Modified
8.1EPSS 0.012
CVE-2023-41915
OpenPMIx PMIx before 4.2.6 and 5.0.x before 5.0.1 allows attackers to obtain ownership of arbitrary files via a race condition during execution of library code with UID 0.
Published 2023-09-09 · Modified
8.1EPSS 0.012
CVE-2023-43804
`Cookie` HTTP header isn't stripped on cross-origin redirects
Published 2023-10-04 · Modified
8.1EPSS 0.012
CVE-2023-1194
Use-after-free in parse_lease_state()
Published 2023-11-03 · Analyzed
8.1EPSS 0.011
CVE-2023-4431
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-22 · Modified
8.1EPSS 0.009
CVE-2015-20107
In Python (aka CPython) up to 3.10.8, the mailcap module does not add escape characters into commands discovered in the system mailcap file. This may allow attackers to inject shell commands into applications that call mailcap.findmatch with untrusted input (if they lack validation of user-provided filenames or arguments). The fix is also back-ported to 3.7, 3.8, 3.9
Published 2022-04-13 · Modified
8.0EPSS 0.071
CVE-2022-23634
Information Exposure when using Puma with Rails
Published 2022-02-11 · Modified
8.0EPSS 0.021
CVE-2022-39369
Service Hostname Discovery Exploitation in phpCAS
Published 2022-11-01 · Modified
8.0EPSS 0.012
CVE-2022-40964
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
7.9EPSS 0.002
CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
Published 2023-10-03 · Analyzed
7.8KEV1 PoCEPSS 0.814
CVE-2023-22809
In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value.
Published 2023-01-18 · Modified
7.81 PoCEPSS 0.554
CVE-2023-29007
Arbitrary configuration injection via `git submodule deinit`
Published 2023-04-25 · Modified
7.8EPSS 0.061
CVE-2023-36664
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
Published 2023-06-25 · Modified
7.8EPSS 0.040
CVE-2021-43138
In Async before 2.6.4 and 3.x before 3.2.2, a malicious user can obtain privileges via the mapValues() method, aka lib/internal/iterator.js createObjectIterator prototype pollution.
Published 2022-04-06 · Modified
7.8EPSS 0.033
CVE-2023-34153
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
Published 2023-05-30 · Analyzed
7.8EPSS 0.031
CVE-2023-31248
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability
Published 2023-07-05 · Modified
7.8EPSS 0.021
CVE-2023-0179
A buffer overflow vulnerability was found in the Netfilter subsystem in the Linux Kernel. This issue could allow the leakage of both stack and heap addresses, and potentially allow Local Privilege Escalation to the root user via arbitrary code execution.
Published 2023-03-27 · Modified
7.8EPSS 0.019
CVE-2023-35001
Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability
Published 2023-07-05 · Modified
7.8EPSS 0.015
CVE-2023-3269
Distros-[dirtyvma] privilege escalation via non-rcu-protected vma traversal
Published 2023-07-11 · Modified
7.8EPSS 0.013
CVE-2022-39377
sysstat Incorrect Buffer Size calculation on 32-bit systems results in RCE via buffer overflow
Published 2022-11-08 · Modified
7.8EPSS 0.012
CVE-2022-41032
NuGet Client Elevation of Privilege Vulnerability
Published 2022-10-11 · Modified
7.8EPSS 0.011
CVE-2022-27942
tcpprep in Tcpreplay 4.4.1 has a heap-based buffer over-read in parse_mpls in common/get.c.
Published 2022-03-26 · Modified
7.8EPSS 0.011
CVE-2022-27940
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_ipv6_next in common/get.c.
Published 2022-03-26 · Modified
7.8EPSS 0.011
CVE-2022-27941
tcprewrite in Tcpreplay 4.4.1 has a heap-based buffer over-read in get_l2len_protocol in common/get.c.
Published 2022-03-26 · Modified
7.8EPSS 0.011
CVE-2022-24765
Uncontrolled search for the Git directory in Git for Windows
Published 2022-04-12 · Modified
7.8EPSS 0.010
CVE-2022-4283
A vulnerability was found in X.Org. This security flaw occurs because the XkbCopyNames function left a dangling pointer to freed memory, resulting in out-of-bounds memory access on subsequent XkbGetKbdByName requests.. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
Published 2022-12-14 · Modified
7.8EPSS 0.010
CVE-2022-2982
Use After Free in vim/vim
Published 2022-08-25 · Modified
7.8EPSS 0.010
CVE-2022-2862
Use After Free in vim/vim
Published 2022-08-17 · Modified
7.8EPSS 0.009
CVE-2023-0494
A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where the X server runs privileged and remote code execution for ssh X forwarding sessions.
Published 2023-03-27 · Modified
7.8EPSS 0.009
CVE-2022-42720
Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
Published 2022-10-13 · Modified
7.8EPSS 0.009
CVE-2022-41741
NGINX ngx_http_mp4_module vulnerability CVE-2022-41741
Published 2022-10-19 · Modified
7.8EPSS 0.008
CVE-2022-45934
An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.
Published 2022-11-27 · Modified
7.8EPSS 0.008
CVE-2022-42919
Python 3.9.x before 3.9.16 and 3.10.x before 3.10.9 on Linux allows local privilege escalation in a non-default configuration. The Python multiprocessing library, when used with the forkserver start method on Linux, allows pickles to be deserialized from any user in the same machine local network namespace, which in many system configurations means any user on the same machine. Pickles can execute arbitrary code. Thus, this allows for local user privilege escalation to the user that any forkserver process is running as. Setting multiprocessing.util.abstract_sockets_supported to False is a workaround. The forkserver start method for multiprocessing is not the default start method. This issue is Linux specific because only Linux supports abstract namespace sockets. CPython before 3.9 does not make use of Linux abstract namespace sockets by default. Support for users manually specifying an abstract namespace socket was added as a bugfix in 3.7.8 and 3.8.3, but users would need to make specific uncommon API calls in order to do that in CPython before 3.9.
Published 2022-11-06 · Modified
7.8EPSS 0.007
CVE-2022-45939
GNU Emacs through 28.2 allows attackers to execute commands via shell metacharacters in the name of a source-code file, because lib-src/etags.c uses the system C library function in its implementation of the ctags program. For example, a victim may use the "ctags *" command (suggested in the ctags documentation) in a situation where the current working directory has contents that depend on untrusted input.
Published 2022-11-28 · Modified
7.8EPSS 0.007
CVE-2022-38784
Poppler prior to and including 22.08.0 contains an integer overflow in the JBIG2 decoder (JBIG2Stream::readTextRegionSeg() in JBIGStream.cc). Processing a specially crafted PDF file or JBIG2 image could lead to a crash or the execution of arbitrary code. This is similar to the vulnerability described by CVE-2022-38171 in Xpdf.
Published 2022-08-30 · Modified
7.8EPSS 0.006
CVE-2023-5367
Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty
Published 2023-10-25 · Modified
7.8EPSS 0.006
CVE-2022-45188
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
Published 2022-11-12 · Modified
7.8EPSS 0.006
CVE-2023-2603
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
Published 2023-06-06 · Modified
7.8EPSS 0.006
CVE-2023-0049
Out-of-bounds Read in vim/vim
Published 2023-01-04 · Analyzed
7.8EPSS 0.006
CVE-2023-4752
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.006
← Prev6 / 18Next →