VendorsFedora Projectfedora39
Vulnerabilities

Fedora Project Fedora 39

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

493CVEs
CVE-2023-3966
Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet
Published 2024-02-22 · Analyzed
7.5EPSS 0.010
CVE-2024-1622
Routinator terminates when RTR connection is reset too quickly after opening
Published 2024-02-26 · Analyzed
7.5EPSS 0.010
CVE-2024-25711
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.
Published 2024-02-11 · Modified
7.5EPSS 0.010
CVE-2024-28084
p2putil.c in iNet wireless daemon (IWD) through 2.15 allows attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact because of initialization issues in situations where parsing of advertised service information fails.
Published 2024-03-03 · Modified
7.5EPSS 0.009
CVE-2024-23835
Suricata's pgsql: memory exhaustion use on record parsing
Published 2024-02-26 · Analyzed
7.5EPSS 0.009
CVE-2024-31031
An issue in `coap_pdu.c` in libcoap 4.3.4 allows attackers to cause undefined behavior via a sequence of messages leading to unsigned integer overflow.
Published 2024-04-17 · Modified
7.5EPSS 0.009
CVE-2024-3840
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-04-17 · Analyzed
7.5EPSS 0.009
CVE-2024-4854
Loop with Unreachable Exit Condition ('Infinite Loop') in Wireshark
Published 2024-05-14 · Modified
7.5EPSS 0.008
CVE-2023-43615
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
Published 2023-10-07 · Modified
7.5EPSS 0.008
CVE-2023-34058
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Published 2023-10-27 · Modified
7.5EPSS 0.007
CVE-2024-0804
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-01-23 · Modified
7.5EPSS 0.005
CVE-2023-40548
Shim: interger overflow leads to heap buffer overflow in verify_sbat_section on 32-bits systems
Published 2024-01-29 · Modified
7.4EPSS 0.004
CVE-2023-38709
Apache HTTP Server: HTTP response splitting
Published 2024-04-04 · Modified
7.3EPSS 0.039
CVE-2024-29131
Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
Published 2024-03-21 · Analyzed
7.3EPSS 0.021
CVE-2023-7104
SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow
Published 2023-12-25 · Modified
7.3EPSS 0.012
CVE-2022-48541
A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.
Published 2023-08-22 · Modified
7.1EPSS 0.015
CVE-2023-3758
Sssd: race condition during authorization leads to gpo policies functioning inconsistently
Published 2024-04-18 · Modified
7.1EPSS 0.010
CVE-2021-29390
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
Published 2023-08-22 · Modified
7.1EPSS 0.008
CVE-2024-27016
netfilter: flowtable: validate pppoe header
Published 2024-05-01 · Modified
7.1EPSS 0.003
CVE-2023-29483
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
Published 2024-04-11 · Modified
7.0EPSS 0.019
CVE-2023-6546
Kernel: gsm multiplexing race condition leads to privilege escalation
Published 2023-12-21 · Modified
7.0EPSS 0.007
CVE-2023-4504
OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow
Published 2023-09-21 · Modified
7.0EPSS 0.007
CVE-2023-51767
OpenSSH through 10.0, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. NOTE: this is disputed by the Supplier, who states "we do not consider it to be the application's responsibility to defend against platform architectural weaknesses."
Published 2023-12-24 · Modified
7.0EPSS 0.007
CVE-2023-6270
Kernel: aoe: improper reference count leads to use-after-free vulnerability
Published 2024-01-04 · Modified
7.0EPSS 0.004
CVE-2023-41914
SchedMD Slurm 23.02.x before 23.02.6 and 22.05.x before 22.05.10 allows filesystem race conditions for gaining ownership of a file, overwriting a file, or deleting files.
Published 2023-11-03 · Modified
7.0EPSS 0.002
CVE-2023-4001
Grub2: bypass the grub password protection feature
Published 2024-01-15 · Modified
6.8EPSS 0.005
CVE-2023-51797
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame
Published 2024-04-19 · Analyzed
6.7EPSS 0.004
CVE-2024-0607
Kernel: nf_tables: pointer math issue in nft_byteorder_eval()
Published 2024-01-18 · Modified
6.6EPSS 0.002
CVE-2023-42916
An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information. Apple is aware of a report that this issue may have been exploited against versions of iOS before iOS 16.7.1.
Published 2023-11-30 · Analyzed
6.5KEVEPSS 0.178
CVE-2022-24599
In autofile Audio File Library 0.3.6, there exists one memory leak vulnerability in printfileinfo, in printinfo.c, which allows an attacker to leak sensitive information via a crafted file. The printfileinfo function calls the copyrightstring function to get data, however, it dosn't use zero bytes to truncate the data.
Published 2022-02-22 · Modified
6.5EPSS 0.017
CVE-2023-46218
This flaw allows a malicious HTTP server to set "super cookies" in curl that are then passed back to more origins than what is otherwise allowed or possible. This allows a site to set cookies that then would get sent to different and unrelated sites and domains. It could do this by exploiting a mixed case flaw in curl's function that verifies a given cookie domain against the Public Suffix List (PSL). For example a cookie could be set with `domain=co.UK` when the URL used a lower case hostname `curl.co.uk`, even though `co.uk` is listed as a PSL domain.
Published 2023-12-07 · Modified
6.5EPSS 0.017
CVE-2023-4527
Glibc: stack read overflow in getaddrinfo in no-aaaa mode
Published 2023-09-18 · Modified
6.5EPSS 0.017
CVE-2023-21946
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published 2023-04-18 · Modified
6.5EPSS 0.015
CVE-2024-23284
A logic issue was addressed with improved state management. This issue is fixed in Safari 17.4, iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, tvOS 17.4, visionOS 1.1, watchOS 10.4. Processing maliciously crafted web content may prevent Content Security Policy from being enforced.
Published 2024-03-08 · Modified
6.5EPSS 0.015
CVE-2024-31208
Synapse's V2 state resolution weakness allows DoS from remote room members
Published 2024-04-23 · Analyzed
6.5EPSS 0.015
CVE-2023-0003
Cortex XSOAR: Local File Disclosure Vulnerability in the Cortex XSOAR Server
Published 2023-02-08 · Modified
6.5EPSS 0.013
CVE-2023-41983
The issue was addressed with improved memory handling. This issue is fixed in macOS Sonoma 14.1, Safari 17.1, iOS 16.7.2 and iPadOS 16.7.2, iOS 17.1 and iPadOS 17.1. Processing web content may lead to a denial-of-service.
Published 2023-10-25 · Modified
6.5EPSS 0.013
CVE-2023-6512
Inappropriate implementation in Web Browser UI in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to potentially spoof the contents of an iframe dialog context menu via a crafted HTML page. (Chromium security severity: Low)
Published 2023-12-06 · Modified
6.5EPSS 0.013
CVE-2023-4091
Samba: smb clients can truncate files with read-only permissions
Published 2023-11-03 · Modified
6.5EPSS 0.012
CVE-2023-52160
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during Phase 1 authentication, and an eap_peap_decrypt vulnerability can then be abused to skip Phase 2 authentication. The attack vector is sending an EAP-TLV Success packet instead of starting Phase 2. This allows an adversary to impersonate Enterprise Wi-Fi networks.
Published 2024-02-22 · Modified
6.5EPSS 0.012
← Prev8 / 13Next →