VendorsFedora Projectfedora39
Vulnerabilities

Fedora Project Fedora 39

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

493CVEs
CVE-2023-7101
Arbitrary Code Execution (ACE) Vulnerability
Published 2023-12-24 · Analyzed
7.8KEVEPSS 0.191
CVE-2024-2955
Mismatched Memory Management Routines in Wireshark
Published 2024-03-26 · Modified
7.8EPSS 0.014
CVE-2024-0229
Xorg-x11-server: reattaching to different master device may lead to out-of-bounds memory access
Published 2024-02-09 · Modified
7.8EPSS 0.012
CVE-2023-47038
Perl: write past buffer end via illegal user-defined unicode property
Published 2023-12-18 · Modified
7.8EPSS 0.008
CVE-2023-5367
Xorg-x11-server: out-of-bounds write in xichangedeviceproperty/rrchangeoutputproperty
Published 2023-10-25 · Modified
7.8EPSS 0.006
CVE-2023-4752
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.006
CVE-2024-22667
Vim before 9.0.2142 has a stack-based buffer overflow because did_set_langmap in map.c calls sprintf to write to the error buffer that is passed down to the option callback functions.
Published 2024-02-05 · Modified
7.8EPSS 0.006
CVE-2023-5764
Ansible: template injection
Published 2023-12-12 · Modified
7.8EPSS 0.005
CVE-2023-4733
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.005
CVE-2023-4750
Use After Free in vim/vim
Published 2023-09-04 · Analyzed
7.8EPSS 0.005
CVE-2023-5535
Use After Free in vim/vim
Published 2023-10-11 · Analyzed
7.8EPSS 0.005
CVE-2023-50010
FFmpeg v.n6.1-3-g466799d4f5 allows a buffer over-read at ff_gradfun_blur_line_movdqa_sse2, as demonstrated by a call to the set_encoder_id function in /fftools/ffmpeg_enc.c component.
Published 2024-04-19 · Modified
7.8EPSS 0.005
CVE-2023-5345
Use-after-free in Linux kernel's fs/smb/client component
Published 2023-10-03 · Analyzed
7.8EPSS 0.005
CVE-2023-50008
FFmpeg v.n6.1-3-g466799d4f5 allows memory consumption when using the colorcorrect filter, in the av_malloc function in libavutil/mem.c:105:9 component.
Published 2024-04-19 · Modified
7.8EPSS 0.004
CVE-2024-0409
Xorg-x11-server: selinux context corruption
Published 2024-01-18 · Modified
7.8EPSS 0.004
CVE-2024-31582
FFmpeg version n6.1 was discovered to contain a heap buffer overflow vulnerability in the draw_block_rectangle function of libavfilter/vf_codecview.c. This vulnerability allows attackers to cause undefined behavior or a Denial of Service (DoS) via crafted input.
Published 2024-04-17 · Modified
7.8EPSS 0.003
CVE-2024-27000
serial: mxs-auart: add spinlock around changing cts state
Published 2024-05-01 · Analyzed
7.8EPSS 0.003
CVE-2023-51798
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.
Published 2024-04-19 · Analyzed
7.8EPSS 0.003
CVE-2024-26922
drm/amdgpu: validate the parameters of bo mapping operations more clearly
Published 2024-04-23 · Modified
7.8EPSS 0.003
CVE-2024-27401
firewire: nosy: ensure user_length is taken into account when fetching packet contents
Published 2024-05-13 · Modified
7.8EPSS 0.003
CVE-2024-27008
drm: nv04: Fix out of bounds access
Published 2024-05-01 · Analyzed
7.8EPSS 0.003
CVE-2024-26994
speakup: Avoid crash on very long word
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2024-27017
netfilter: nft_set_pipapo: walk over current view on netlink dump
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2024-26988
init/main.c: Fix potential static_command_line memory overflow
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2023-5972
Kernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.c
Published 2023-11-23 · Modified
7.8EPSS 0.003
CVE-2023-51791
Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.
Published 2024-04-19 · Analyzed
7.8EPSS 0.003
CVE-2024-27012
netfilter: nf_tables: restore set elements when delete set fails
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2022-38076
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
7.8EPSS 0.003
CVE-2024-27400
drm/amdgpu: once more fix the call oder in amdgpu_ttm_move() v2
Published 2024-05-13 · Modified
7.8EPSS 0.002
CVE-2024-27019
netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get()
Published 2024-05-01 · Modified
7.8EPSS 0.002
CVE-2024-27021
r8169: fix LED-related deadlock on module removal
Published 2024-05-01 · Modified
7.8EPSS 0.002
CVE-2024-3841
Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)
Published 2024-04-17 · Analyzed
7.6EPSS 0.007
CVE-2024-22421
Potential authentication and CSRF tokens leak in JupyterLab
Published 2024-01-19 · Modified
7.6EPSS 0.007
CVE-2023-50387
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.
Published 2024-02-14 · Modified
7.5EPSS 1.000
CVE-2024-31309
Apache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack
Published 2024-04-10 · Modified
7.5EPSS 0.946
CVE-2024-27316
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
Published 2024-04-04 · Modified
7.5EPSS 0.913
CVE-2023-50868
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Published 2024-02-14 · Analyzed
7.5EPSS 0.817
CVE-2024-23334
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
Published 2024-01-29 · Modified
7.51 PoCEPSS 0.769
CVE-2023-38039
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.
Published 2023-09-15 · Modified
7.5EPSS 0.581
CVE-2024-20290
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .
Published 2024-02-07 · Modified
7.5EPSS 0.336
← Prev6 / 13Next →