VendorsFedora Projectfedora38
Vulnerabilities

Fedora Project Fedora 38

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

640CVEs
CVE-2023-43804
`Cookie` HTTP header isn't stripped on cross-origin redirects
Published 2023-10-04 · Modified
8.1EPSS 0.012
CVE-2023-4234
Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_submit_report() function
Published 2024-04-17 · Modified
8.1EPSS 0.011
CVE-2023-4233
Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the sms_decode_address_field() function
Published 2024-04-17 · Modified
8.1EPSS 0.010
CVE-2023-4431
Out of bounds memory access in Fonts in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-08-22 · Modified
8.1EPSS 0.009
CVE-2024-23839
Suricata http: heap use after free with http.request_header and http.response_header keywords
Published 2024-02-26 · Analyzed
8.1EPSS 0.008
CVE-2023-50009
FFmpeg v.n6.1-3-g466799d4f5 allows a heap-based buffer overflow via the ff_gaussian_blur_8 function in libavfilter/edge_template.c:116:5 component.
Published 2024-04-19 · Modified
8.0EPSS 0.004
CVE-2023-49528
Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance.c:261:5 in the de_stereo component.
Published 2024-04-12 · Modified
8.0EPSS 0.004
CVE-2023-49501
Buffer Overflow vulnerability in Ffmpeg v.n6.1-3-g466799d4f5 allows a local attacker to execute arbitrary code via the config_eq_output function in the libavfilter/asrc_afirsrc.c:495:30 component.
Published 2024-04-19 · Modified
8.0EPSS 0.004
CVE-2023-51795
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showspectrum.c:1789:52 component in showspectrumpic_request_frame
Published 2024-04-19 · Analyzed
8.0EPSS 0.003
CVE-2023-38497
Cargo not respecting umask when extracting crate archives
Published 2023-08-04 · Modified
7.9EPSS 0.007
CVE-2022-40964
Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
7.9EPSS 0.002
CVE-2023-4911
Glibc: buffer overflow in ld.so leading to privilege escalation
Published 2023-10-03 · Analyzed
7.8KEV1 PoCEPSS 0.814
CVE-2023-7101
Arbitrary Code Execution (ACE) Vulnerability
Published 2023-12-24 · Analyzed
7.8KEVEPSS 0.191
CVE-2023-29007
Arbitrary configuration injection via `git submodule deinit`
Published 2023-04-25 · Modified
7.8EPSS 0.061
CVE-2023-36664
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).
Published 2023-06-25 · Modified
7.8EPSS 0.040
CVE-2023-34153
A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.
Published 2023-05-30 · Analyzed
7.8EPSS 0.031
CVE-2023-31248
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability
Published 2023-07-05 · Modified
7.8EPSS 0.021
CVE-2023-35001
Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability
Published 2023-07-05 · Modified
7.8EPSS 0.015
CVE-2023-3269
Distros-[dirtyvma] privilege escalation via non-rcu-protected vma traversal
Published 2023-07-11 · Modified
7.8EPSS 0.013
CVE-2023-4004
Kernel: netfilter: use-after-free due to improper element removal in nft_pipapo_remove()
Published 2023-07-31 · Modified
7.8EPSS 0.009
CVE-2023-5367
Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty
Published 2023-10-25 · Modified
7.8EPSS 0.006
CVE-2022-45188
Netatalk through 3.1.13 has an afp_getappl heap-based buffer overflow resulting in code execution via a crafted .appl file. This provides remote root access on some platforms such as FreeBSD (used for TrueNAS).
Published 2022-11-12 · Modified
7.8EPSS 0.006
CVE-2023-2603
A vulnerability was found in libcap. This issue occurs in the _libcap_strdup() function and can lead to an integer overflow if the input string is close to 4GiB.
Published 2023-06-06 · Modified
7.8EPSS 0.006
CVE-2023-4752
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.006
CVE-2023-4147
Kernel: netfilter: nf_tables_newrule when adding a rule with nfta_rule_chain_id leads to use-after-free
Published 2023-08-07 · Modified
7.8EPSS 0.006
CVE-2024-22667
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
Published 2024-02-05 · Modified
7.8EPSS 0.006
CVE-2023-5764
Ansible: template injection
Published 2023-12-12 · Modified
7.8EPSS 0.005
CVE-2023-4733
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.005
CVE-2023-4750
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.005
CVE-2023-5535
Use After Free in vim/vim
Published 2023-10-11 · Analyzed
7.8EPSS 0.005
CVE-2023-50010
FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component.
Published 2024-04-19 · Modified
7.8EPSS 0.005
CVE-2023-22970
Bottles before 51.0 mishandles YAML load, which allows remote code execution via a crafted file.
Published 2023-05-26 · Modified
7.8EPSS 0.005
CVE-2023-5345
Use-after-free in Linux kernel's fs/smb/client component
Published 2023-10-03 · Analyzed
7.8EPSS 0.005
CVE-2023-1393
A flaw was found in X.Org Server Overlay Window. A Use-After-Free may lead to local privilege escalation. If a client explicitly destroys the compositor overlay window (aka COW), the Xserver would leave a dangling pointer to that window in the CompScreen structure, which will trigger a use-after-free later.
Published 2023-03-30 · Modified
7.8EPSS 0.004
CVE-2023-29403
Unsafe behavior in setuid/setgid binaries in runtime
Published 2023-06-08 · Modified
7.8EPSS 0.004
CVE-2023-43787
Libx11: integer overflow in xcreateimage() leading to a heap overflow
Published 2023-10-10 · Modified
7.8EPSS 0.004
CVE-2023-34432
Heap-buffer-overflow in src/formats_i.c
Published 2023-07-10 · Modified
7.8EPSS 0.004
CVE-2023-50008
FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.
Published 2024-04-19 · Modified
7.8EPSS 0.004
CVE-2024-31582
FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input.
Published 2024-04-17 · Modified
7.8EPSS 0.003
CVE-2023-33204
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
Published 2023-05-18 · Modified
7.8EPSS 0.003
← Prev6 / 16Next →