VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2019-19270
An issue was discovered in tls_verify_crl in ProFTPD through 1.3.6b. Failure to check for the appropriate field of a CRL entry (checking twice for subject, rather than once for subject and once for issuer) prevents some valid CRLs from being taken into account, and can allow clients whose certificates have been revoked to proceed with a connection to the server.
Published 2019-11-26 · Modified
7.5EPSS 0.010
CVE-2024-4060
Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-01 · Modified
7.5EPSS 0.010
CVE-2024-1622
Routinator terminates when RTR connection is reset too quickly after opening
Published 2024-02-26 · Analyzed
7.5EPSS 0.010
CVE-2023-2135
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-04-19 · Modified
7.5EPSS 0.010
CVE-2022-39957
Response body bypass in OWASP ModSecurity Core Rule Set via a specialy crafted charset in the HTTP Accept header
Published 2022-09-20 · Modified
7.5EPSS 0.010
CVE-2024-25711
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
Published 2024-02-11 · Modified
7.5EPSS 0.010
CVE-2023-39197
Kernel: dccp: conntrack out-of-bounds read in nf_conntrack_dccp_packet()
Published 2024-01-23 · Modified
7.5EPSS 0.010
CVE-2021-29510
Use of "infinity" as an input to datetime and date fields causes infinite loop in pydantic
Published 2021-05-13 · Modified
7.5EPSS 0.010
CVE-2023-29530
Laminas Diactoros vulnerable to HTTP Multiline Header Termination
Published 2023-04-24 · Modified
7.5EPSS 0.010
CVE-2024-3772
Regular expression denial of service in Pydantic < 2.4.0
Published 2024-04-15 · Analyzed
7.5EPSS 0.010
CVE-2021-25636
Incorrect trust validation of signature with ambiguous KeyInfo children
Published 2022-02-22 · Modified
7.5EPSS 0.010
CVE-2016-10937
IMAPFilter through 2.6.12 does not validate the hostname in an SSL certificate.
Published 2019-09-08 · Modified
7.5EPSS 0.009
CVE-2024-25978
Msa-24-0001: denial of service risk in file picker unzip functionality
Published 2024-02-19 · Analyzed
7.5EPSS 0.009
CVE-2024-28084
p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.
Published 2024-03-03 · Modified
7.5EPSS 0.009
CVE-2024-23835
Suricata's pgsql: memory exhaustion use on record parsing
Published 2024-02-26 · Analyzed
7.5EPSS 0.009
CVE-2021-45451
In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.
Published 2021-12-21 · Modified
7.5EPSS 0.009
CVE-2012-1170
Moodle before 2.2.2 has an external enrolment plugin context check issue where capability checks are not thorough
Published 2019-11-14 · Modified
7.5EPSS 0.009
CVE-2022-39282
RDP client: Read of uninitialized memory with parallel port redirection
Published 2022-10-12 · Modified
7.5EPSS 0.009
CVE-2024-34506
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximum request time, leading to a denial of service.
Published 2024-05-05 · Modified
7.5EPSS 0.009
CVE-2024-31031
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
Published 2024-04-17 · Modified
7.5EPSS 0.009
CVE-2022-3725
Crash in the OPUS protocol dissector in Wireshark 3.6.0 to 3.6.8 allows denial of service via packet injection or crafted capture file
Published 2022-10-27 · Modified
7.5EPSS 0.009
CVE-2023-42843
An inconsistent user interface issue was addressed with improved state management. This issue is fixed in iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1, Safari 17.1, macOS Sonoma 14.1. Visiting a malicious website may lead to address bar spoofing.
Published 2024-02-21 · Analyzed
7.5EPSS 0.009
CVE-2024-3840
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-04-17 · Analyzed
7.5EPSS 0.009
CVE-2024-4854
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Published 2024-05-14 · Modified
7.5EPSS 0.008
CVE-2022-23132
Incorrect permissions of [/var/run/zabbix] forces dac_override
Published 2022-01-13 · Modified
7.5EPSS 0.008
CVE-2023-43615
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
Published 2023-10-07 · Modified
7.5EPSS 0.008
CVE-2023-34058
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Published 2023-10-27 · Modified
7.5EPSS 0.007
CVE-2021-34825
Quassel through 0.13.1, when --require-ssl is enabled, launches without SSL or TLS support if a usable X.509 certificate is not found on the local system.
Published 2021-06-17 · Modified
7.5EPSS 0.006
CVE-2021-36377
Fossil before 2.14.2 and 2.15.x before 2.15.2 often skips the hostname check during TLS certificate validation.
Published 2021-07-12 · Modified
7.5EPSS 0.006
CVE-2021-3748
A use-after-free vulnerability was found in the virtio-net device of QEMU. It could occur when the descriptor's address belongs to the non direct access region, due to num_buffers being set after the virtqueue elem has been unmapped. A malicious guest could use this flaw to crash QEMU, resulting in a denial of service condition, or potentially execute code on the host with the privileges of the QEMU process.
Published 2022-03-23 · Modified
7.5EPSS 0.005
CVE-2024-0804
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-01-23 · Modified
7.5EPSS 0.005
CVE-2021-29157
Dovecot before 2.3.15 allows ../ Path Traversal. An attacker with access to the local filesystem can trick OAuth2 authentication into using an HS256 validation key from an attacker-controlled location. This occurs during use of local JWT validation with the posix fs driver.
Published 2021-06-28 · Modified
7.5EPSS 0.005
CVE-2023-39198
Kernel: qxl: race condition leading to use-after-free in qxl_mode_dumb_create()
Published 2023-11-09 · Modified
7.5EPSS 0.004
CVE-2020-27779
A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory layout. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2021-03-03 · Modified
7.5EPSS 0.004
CVE-2014-0224
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive information, via a crafted TLS handshake, aka the "CCS Injection" vulnerability.
Published 2014-06-05 · Modified
7.4EPSS 0.953
CVE-2020-13777
GnuTLS 3.6.x before 3.6.14 uses incorrect cryptography for encrypting a session ticket (a loss of confidentiality in TLS 1.2, and an authentication bypass in TLS 1.3). The earliest affected version is 3.6.4 (2018-09-24) because of an error in a 2018-09-18 commit. Until the first key rotation, the TLS server always uses wrong data in place of an encryption key derived from an application.
Published 2020-06-04 · Modified
7.4EPSS 0.223
CVE-2021-3450
CA certificate check bypass with X509_V_FLAG_X509_STRICT
Published 2021-03-25 · Modified
7.4EPSS 0.183
CVE-2021-20322
A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.
Published 2022-02-18 · Analyzed
7.4EPSS 0.069
CVE-2021-25217
A buffer overrun in lease file parsing code can be used to exploit a common vulnerability shared by dhcpd and dhclient
Published 2021-05-26 · Modified
7.4EPSS 0.061
CVE-2020-8201
Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can be crafted by an attacker to hijack user sessions, poison cookies, perform clickjacking, and a multitude of other attacks depending on the architecture of the underlying system. The attack was possible due to a bug in processing of carrier-return symbols in the HTTP header names.
Published 2020-09-18 · Modified
7.4EPSS 0.053
← Prev70 / 135Next →