VendorsFedora Projectfedora38
Vulnerabilities

Fedora Project Fedora 38

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

640CVEs
CVE-2024-1931
Denial of service when trimming EDE text on positive replies
Published 2024-03-07 · Analyzed
7.5EPSS 0.025
CVE-2023-2911
Exceeding the recursive-clients quota may cause named to terminate unexpectedly when stale-answer-client-timeout is set to 0
Published 2023-06-21 · Modified
7.5EPSS 0.025
CVE-2023-4236
named may terminate unexpectedly under high DNS-over-TLS query load
Published 2023-09-20 · Modified
7.5EPSS 0.022
CVE-2023-31490
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.
Published 2023-05-09 · Modified
7.5EPSS 0.022
CVE-2023-43669
The Tungstenite crate before 0.20.1 for Rust allows remote attackers to cause a denial of service (minutes of CPU consumption) via an excessive length of an HTTP header in a client handshake. The length affects both how many times a parse is attempted (e.g., thousands of times) and the average amount of data for each parse attempt (e.g., millions of bytes).
Published 2023-09-21 · Modified
7.5EPSS 0.021
CVE-2023-5157
Mariadb: node crashes with transport endpoint is not connected mysqld got signal 6
Published 2023-09-26 · Modified
7.5EPSS 0.020
CVE-2024-28757
libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).
Published 2024-03-10 · Modified
7.5EPSS 0.020
CVE-2023-30631
Apache Traffic Server: Configuration option to block the PUSH method in ATS didn't work
Published 2023-06-14 · Modified
7.5EPSS 0.020
CVE-2023-38403
iperf3 before 3.14 allows peers to cause an integer overflow and heap corruption via a crafted length field.
Published 2023-07-17 · Modified
7.5EPSS 0.020
CVE-2023-38802
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
Published 2023-08-29 · Modified
7.5EPSS 0.018
CVE-2024-2886
Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Published 2024-03-26 · Modified
7.5EPSS 0.018
CVE-2023-39350
Incorrect offset calculation leading to denial of service in FreeRDP
Published 2023-08-31 · Modified
7.5EPSS 0.016
CVE-2022-36440
A reachable assertion was found in Frrouting frr-bgpd 8.3.0 in the peek_for_as4_capability function. Attackers can maliciously construct BGP open packets and send them to BGP peers running frr-bgpd, resulting in DoS.
Published 2023-04-03 · Modified
7.5EPSS 0.016
CVE-2023-3354
Improper i/o watch removal in tls handshake can lead to remote unauthenticated denial of service
Published 2023-07-11 · Modified
7.5EPSS 0.016
CVE-2023-39354
FreeRDP Out-Of-Bounds Read in nsc_rle_decompress_data
Published 2023-08-31 · Modified
7.5EPSS 0.016
CVE-2023-32067
0-byte UDP payload DoS in c-ares
Published 2023-05-25 · Modified
7.5EPSS 0.016
CVE-2023-39351
FreeRDP Null Pointer Dereference leading denial of service
Published 2023-08-31 · Modified
7.5EPSS 0.016
CVE-2024-22871
An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.
Published 2024-02-29 · Modified
7.5EPSS 0.015
CVE-2023-38200
Keylime: registrar is subject to a dos against ssl connections
Published 2023-07-24 · Modified
7.5EPSS 0.014
CVE-2024-0567
Gnutls: rejects certificate chain with distributed trust
Published 2024-01-16 · Modified
7.5EPSS 0.014
CVE-2023-50967
latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.
Published 2024-03-20 · Modified
7.5EPSS 0.014
CVE-2023-4408
Parsing large DNS messages may cause excessive CPU load
Published 2024-02-13 · Modified
7.5EPSS 0.013
CVE-2023-40589
FreeRDP Global-Buffer-Overflow in ncrush_decompress
Published 2023-08-31 · Modified
7.5EPSS 0.013
CVE-2024-23280
An injection issue was addressed with improved validation. This issue is fixed in Safari 17.4, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, watchOS 10.4. A maliciously crafted webpage may be able to fingerprint the user.
Published 2024-03-08 · Modified
7.5EPSS 0.013
CVE-2023-20900
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Published 2023-08-31 · Modified
7.5EPSS 0.013
CVE-2023-41358
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
Published 2023-08-29 · Modified
7.5EPSS 0.013
CVE-2023-5517
Querying RFC 1918 reverse zones may cause an assertion failure when "nxdomain-redirect" is enabled
Published 2024-02-13 · Modified
7.5EPSS 0.012
CVE-2023-5679
Enabling both DNS64 and serve-stale may cause an assertion failure during recursive resolution
Published 2024-02-13 · Modified
7.5EPSS 0.012
CVE-2023-41752
Apache Traffic Server: s3_auth plugin problem with hash calculation
Published 2023-10-17 · Modified
7.5EPSS 0.012
CVE-2023-29197
Improper header name validation in guzzlehttp/psr7
Published 2023-04-17 · Modified
7.5EPSS 0.012
CVE-2024-32661
FreeRDP rdp_write_logon_info_v1 NULL access
Published 2024-04-23 · Modified
7.5EPSS 0.012
CVE-2024-23837
LibHTP unbounded folded header handling leads to denial service
Published 2024-02-26 · Modified
7.5EPSS 0.012
CVE-2023-5344
Heap-based Buffer Overflow in vim/vim
Published 2023-10-02 · Modified
7.5EPSS 0.012
CVE-2024-4559
Heap buffer overflow in WebAudio in Google Chrome prior to 124.0.6367.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-07 · Analyzed
7.5EPSS 0.012
CVE-2024-31578
FFmpeg version n6.1.1 was discovered to contain a heap use-after-free via the av_hwframe_ctx_init function.
Published 2024-04-17 · Modified
7.5EPSS 0.012
CVE-2024-26134
CBOR2 decoder has potential buffer overflow
Published 2024-02-19 · Analyzed
7.5EPSS 0.012
CVE-2023-46838
Linux: netback processing of zero-length transmit fragment
Published 2024-01-29 · Modified
7.5EPSS 0.012
CVE-2023-20197
A vulnerability in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an incorrect check for completion when a file is decompressed, which may result in a loop condition that could cause the affected software to stop responding. An attacker could exploit this vulnerability by submitting a crafted HFS+ filesystem image to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to cause the ClamAV scanning process to stop responding, resulting in a DoS condition on the affected software and consuming available system resources. For a description of this vulnerability, see the ClamAV blog .
Published 2023-08-16 · Modified
7.5EPSS 0.012
CVE-2024-32660
FreeRDP zgfx_decompress out of memory vulnerability
Published 2024-04-23 · Modified
7.5EPSS 0.012
CVE-2024-23836
crafted traffic can cause denial of service
Published 2024-02-26 · Analyzed
7.5EPSS 0.012
← Prev8 / 16Next →