VendorsFedora Projectfedora40
Vulnerabilities

Fedora Project Fedora 40

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

244CVEs
CVE-2024-34403
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
Published 2024-05-03 · Modified
5.9EPSS 0.013
CVE-2024-2408
PHP is vulnerable to the Marvin Attack
Published 2024-06-09 · Modified
5.9EPSS 0.012
CVE-2024-24246
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
Published 2024-02-29 · Modified
5.5EPSS 0.004
CVE-2024-4853
Mismatched Memory Management Routines in editcap
Published 2024-05-14 · Modified
5.5EPSS 0.004
CVE-2024-4855
Use After Free in editcap
Published 2024-05-14 · Analyzed
5.5EPSS 0.004
CVE-2024-25629
c-ares out of bounds read in ares__read_line()
Published 2024-02-23 · Analyzed
5.5EPSS 0.004
CVE-2024-1062
389-ds-base: a heap overflow leading to denail-of-servce while writing a value larger than 256 chars (in log_entry_attr)
Published 2024-02-12 · Modified
5.5EPSS 0.003
CVE-2024-27399
Bluetooth: l2cap: fix null-ptr-deref in l2cap_chan_timeout
Published 2024-05-13 · Analyzed
5.5EPSS 0.003
CVE-2024-27001
comedi: vmk80xx: fix incomplete endpoint checking
Published 2024-05-01 · Analyzed
5.5EPSS 0.003
CVE-2024-27013
tun: limit printing rate when illegal packet received by tun dev
Published 2024-05-01 · Modified
5.5EPSS 0.003
CVE-2024-35947
dyndbg: fix old BUG_ON in >control parser
Published 2024-05-19 · Analyzed
5.5EPSS 0.003
CVE-2024-26986
drm/amdkfd: Fix memory leak in create_process failure
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-27015
netfilter: flowtable: incorrect pppoe tuple
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-27004
clk: Get runtime PM before walking tree during disable_unused
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-27014
net/mlx5e: Prevent deadlock while disabling aRFS
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-26987
mm/memory-failure: fix deadlock when hugetlb_optimize_vmemmap is enabled
Published 2024-05-01 · Modified
5.5EPSS 0.002
CVE-2024-29133
Apache Commons Configuration: StackOverflowError calling ListDelimiterHandler.flatten(Object, int) with a cyclical object tree
Published 2024-03-21 · Analyzed
5.4EPSS 0.017
CVE-2024-34064
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
Published 2024-05-06 · Modified
5.4EPSS 0.010
CVE-2024-3846
Inappropriate implementation in Prompts in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published 2024-04-17 · Analyzed
5.4EPSS 0.009
CVE-2024-38273
moodle: BigBlueButton web service leaks meeting joining information to users who should not have access
Published 2024-06-18 · Analyzed
5.4EPSS 0.004
CVE-2024-38277
moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys
Published 2024-06-18 · Analyzed
5.4EPSS 0.002
CVE-2024-28182
Reading unbounded number of HTTP/2 CONTINUATION frames to cause excessive CPU usage
Published 2024-04-04 · Modified
5.3EPSS 0.850
CVE-2024-5458
Filter bypass in filter_var (FILTER_VALIDATE_URL)
Published 2024-06-09 · Modified
5.3EPSS 0.121
CVE-2024-21501
Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.
Published 2024-02-24 · Analyzed
5.3EPSS 0.010
CVE-2024-35200
NGINX HTTP/3 QUIC vulnerability
Published 2024-05-29 · Analyzed
5.3EPSS 0.009
CVE-2024-34161
NGINX HTTP/3 QUIC vulnerability
Published 2024-05-29 · Analyzed
5.3EPSS 0.009
CVE-2024-31585
FFmpeg version n5.1 to n6.1 was discovered to contain an Off-by-one Error vulnerability in libavfilter/avf_showspectrum.c. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
Published 2024-04-17 · Modified
5.3EPSS 0.003
CVE-2024-34397
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
Published 2024-05-07 · Modified
5.2EPSS 0.008
CVE-2024-21096
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L).
Published 2024-04-16 · Analyzed
4.9EPSS 0.004
CVE-2024-31079
NGINX HTTP/3 QUIC vulnerability
Published 2024-05-29 · Analyzed
4.8EPSS 0.009
CVE-2024-3843
Insufficient data validation in Downloads in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-04-17 · Analyzed
4.6EPSS 0.006
CVE-2024-30260
Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipeline
Published 2024-04-04 · Modified
4.3EPSS 0.007
CVE-2024-2629
Incorrect security UI in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2024-2631
Inappropriate implementation in iOS in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2024-3844
Inappropriate implementation in Extensions in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Published 2024-04-17 · Analyzed
4.3EPSS 0.007
CVE-2024-2628
Inappropriate implementation in Downloads in Google Chrome prior to 123.0.6312.58 allowed a remote attacker to perform UI spoofing via a crafted URL. (Chromium security severity: Medium)
Published 2024-03-20 · Modified
4.3EPSS 0.007
CVE-2024-25081
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
Published 2024-02-26 · Modified
4.2EPSS 0.011
CVE-2023-50007
FFmpeg v.n6.1-3-g466799d4f5 allows an attacker to trigger use of a parameter of negative size in the av_samples_set_silence function in thelibavutil/samplefmt.c:260:9 component.
Published 2024-04-19 · Modified
4.0EPSS 0.004
CVE-2024-32020
Cloning local Git repository by untrusted user allows the untrusted user to modify objects in the cloned repository at will
Published 2024-05-14 · Analyzed
3.9EPSS 0.005
CVE-2023-51796
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/f_reverse.c:269:26 in areverse_request_frame.
Published 2024-04-19 · Analyzed
3.6EPSS 0.002
← Prev6 / 7Next →