VendorsFedora Projectfedora38
Vulnerabilities

Fedora Project Fedora 38

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

640CVEs
CVE-2023-33204
sysstat through 12.7.2 allows a multiplication integer overflow in check_overflow in common.c. NOTE: this issue exists because of an incomplete fix for CVE-2022-39377.
Published 2023-05-18 · Modified
7.8EPSS 0.003
CVE-2023-51798
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via a floating point exception (FPE) error at libavfilter/vf_minterpolate.c:1078:60 in interpolate.
Published 2024-04-19 · Analyzed
7.8EPSS 0.003
CVE-2024-26922
drm/amdgpu: validate the parameters of bo mapping operations more clearly
Published 2024-04-23 · Modified
7.8EPSS 0.003
CVE-2024-27008
drm: nv04: Fix out of bounds access
Published 2024-05-01 · Analyzed
7.8EPSS 0.003
CVE-2024-26994
speakup: Avoid crash on very long word
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2024-27017
netfilter: nft_set_pipapo: walk over current view on netlink dump
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2023-3106
Kernel: netlink socket crash (null pointer deref) in netlink_dump function
Published 2023-07-12 · Modified
7.8EPSS 0.003
CVE-2024-26988
init/main.c: Fix potential static_command_line memory overflow
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2023-34318
Heap-buffer-overflow in src/hcom.c
Published 2023-07-10 · Modified
7.8EPSS 0.003
CVE-2023-51791
Buffer Overflow vulenrability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavcodec/jpegxl_parser.c in gen_alias_map.
Published 2024-04-19 · Analyzed
7.8EPSS 0.003
CVE-2024-27012
netfilter: nf_tables: restore set elements when delete set fails
Published 2024-05-01 · Modified
7.8EPSS 0.003
CVE-2022-42332
x86 shadow plus log-dirty mode use-after-free In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Shadow mode maintains a pool of memory used for both shadow page tables as well as auxiliary data structures. To migrate or snapshot guests, Xen additionally runs them in so called log-dirty mode. The data structures needed by the log-dirty tracking are part of aformentioned auxiliary data. In order to keep error handling efforts within reasonable bounds, for operations which may require memory allocations shadow mode logic ensures up front that enough memory is available for the worst case requirements. Unfortunately, while page table memory is properly accounted for on the code path requiring the potential establishing of new shadows, demands by the log-dirty infrastructure were not taken into consideration. As a result, just established shadow page tables could be freed again immediately, while other code is still accessing them on the assumption that they would remain allocated.
Published 2023-03-21 · Modified
7.8EPSS 0.003
CVE-2022-42335
x86 shadow paging arbitrary pointer dereference In environments where host assisted address translation is necessary but Hardware Assisted Paging (HAP) is unavailable, Xen will run guests in so called shadow mode. Due to too lax a check in one of the hypervisor routines used for shadow page handling it is possible for a guest with a PCI device passed through to cause the hypervisor to access an arbitrary pointer partially under guest control.
Published 2023-04-25 · Modified
7.8EPSS 0.003
CVE-2022-38076
Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
7.8EPSS 0.003
CVE-2023-3899
Subscription-manager: inadequate authorization of com.redhat.rhsm1 d-bus interface allows local users to modify configuration
Published 2023-08-23 · Modified
7.8EPSS 0.002
CVE-2023-1386
Qemu: 9pfs: suid/sgid bits not dropped on file write
Published 2023-07-24 · Modified
7.8EPSS 0.002
CVE-2024-27019
netfilter: nf_tables: Fix potential data-race in __nft_obj_type_get()
Published 2024-05-01 · Modified
7.8EPSS 0.002
CVE-2024-27021
r8169: fix LED-related deadlock on module removal
Published 2024-05-01 · Modified
7.8EPSS 0.002
CVE-2024-3841
Insufficient data validation in Browser Switcher in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to inject scripts or HTML into a privileged page via a malicious file. (Chromium security severity: Medium)
Published 2024-04-17 · Analyzed
7.6EPSS 0.007
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2024-31309
Apache Traffic Server: HTTP/2 CONTINUATION frames can be utilized for DoS attack
Published 2024-04-10 · Modified
7.5EPSS 0.946
CVE-2024-27316
Apache HTTP Server: HTTP/2 DoS by memory exhaustion on endless continuation frames
Published 2024-04-04 · Modified
7.5EPSS 0.913
CVE-2023-50868
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Published 2024-02-14 · Analyzed
7.5EPSS 0.817
CVE-2023-34966
Samba: infinite loop in mdssvc rpc service for spotlight
Published 2023-07-20 · Modified
7.5EPSS 0.624
CVE-2023-38039
When curl retrieves an HTTP response, it stores the incoming headers so that they can be accessed later via the libcurl headers API. However, curl did not have a limit in how many or how large headers it would accept in a response, allowing a malicious server to stream an endless series of headers and eventually cause curl to run out of heap memory.
Published 2023-09-15 · Modified
7.5EPSS 0.581
CVE-2023-39456
Apache Traffic Server: Malformed http/2 frames can cause an abort
Published 2023-10-17 · Modified
7.5EPSS 0.538
CVE-2023-25652
"git apply --reject" partially-controlled arbitrary file write
Published 2023-04-25 · Modified
7.5EPSS 0.519
CVE-2024-20290
A vulnerability in the OLE2 file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for end-of-string values during scanning, which may result in a heap buffer over-read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to terminate, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .
Published 2024-02-07 · Modified
7.5EPSS 0.336
CVE-2023-24329
An issue in the urllib.parse component of Python before 3.11.4 allows attackers to bypass blocklisting methods by supplying a URL that starts with blank characters.
Published 2023-02-17 · Modified
7.5EPSS 0.205
CVE-2024-31142
x86: Incorrect logic for BTC/SRSO mitigations
Published 2024-05-16 · Analyzed
7.5EPSS 0.174
CVE-2023-38180
.NET and Visual Studio Denial of Service Vulnerability
Published 2023-08-08 · Analyzed
7.5KEVEPSS 0.140
CVE-2023-2156
A flaw was found in the networking subsystem of the Linux kernel within the handling of the RPL protocol. This issue results from the lack of proper handling of user-supplied data, which can lead to an assertion failure. This may allow an unauthenticated remote attacker to create a denial of service condition on the system.
Published 2023-05-09 · Modified
7.5EPSS 0.061
CVE-2023-1992
RPCoRDMA dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Published 2023-04-12 · Modified
7.5EPSS 0.046
CVE-2023-30589
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20
Published 2023-06-30 · Modified
7.5EPSS 0.039
CVE-2023-39325
HTTP/2 rapid reset can cause excessive work in net/http
Published 2023-10-11 · Modified
7.5EPSS 0.038
CVE-2023-2828
named's configured cache size limit can be significantly exceeded
Published 2023-06-21 · Modified
7.5EPSS 0.038
CVE-2024-34069
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
Published 2024-05-06 · Analyzed
7.5EPSS 0.034
CVE-2023-31122
Apache HTTP Server: mod_macro buffer over-read
Published 2023-10-23 · Analyzed
7.5EPSS 0.030
CVE-2023-36053
In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
Published 2023-07-03 · Modified
7.5EPSS 0.030
CVE-2023-3341
A stack exhaustion flaw in control channel code may cause named to terminate unexpectedly
Published 2023-09-20 · Modified
7.5EPSS 0.029
← Prev7 / 16Next →