VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2024-23829
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
Published 2024-01-29 · Modified
6.5EPSS 0.010
CVE-2020-15973
Insufficient policy enforcement in extensions in Google Chrome prior to 86.0.4240.75 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension.
Published 2020-11-03 · Modified
6.5EPSS 0.010
CVE-2020-6538
Inappropriate implementation in WebView in Google Chrome on Android prior to 84.0.4147.105 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2020-09-21 · Modified
6.5EPSS 0.010
CVE-2021-21211
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-04-26 · Modified
6.5EPSS 0.010
CVE-2019-5778
A missing case for handling special schemes in permission request checks in Extensions in Google Chrome prior to 72.0.3626.81 allowed an attacker who convinced a user to install a malicious extension to bypass extension permission checks for privileged pages via a crafted Chrome Extension.
Published 2019-02-19 · Modified
6.5EPSS 0.010
CVE-2021-21209
Inappropriate implementation in storage in Google Chrome prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-04-26 · Modified
6.5EPSS 0.010
CVE-2022-2860
Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.101 allowed a remote attacker to bypass cookie prefix restrictions via a crafted HTML page.
Published 2022-09-26 · Modified
6.5EPSS 0.010
CVE-2024-3044
Graphic on-click binding allows unchecked script execution
Published 2024-05-14 · Analyzed
6.5EPSS 0.010
CVE-2022-24807
net-snmp: A malformed OID in a SET request to SNMP-VIEW-BASED-ACM-MIB::vacmAccessTable can cause an out-of-bounds memory access
Published 2024-04-16 · Analyzed
6.5EPSS 0.010
CVE-2023-1994
GQUIC dissector crash in Wireshark 4.0.0 to 4.0.4 and 3.6.0 to 3.6.12 allows denial of service via packet injection or crafted capture file
Published 2023-04-12 · Modified
6.5EPSS 0.010
CVE-2022-32325
JPEGOPTIM v1.4.7 was discovered to contain a segmentation violation which is caused by a READ memory access at jpegoptim.c.
Published 2022-07-01 · Modified
6.5EPSS 0.010
CVE-2023-1817
Insufficient policy enforcement in Intents in Google Chrome on Android prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-04-04 · Modified
6.5EPSS 0.010
CVE-2023-2459
Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
6.5EPSS 0.010
CVE-2021-34339
Ming 0.4.8 has an out-of-bounds buffer access issue in the function getString() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
Published 2022-03-07 · Modified
6.5EPSS 0.010
CVE-2021-34338
Ming 0.4.8 has an out-of-bounds buffer overwrite issue in the function getName() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
Published 2022-03-07 · Modified
6.5EPSS 0.010
CVE-2021-21163
Insufficient data validation in Reader Mode in Google Chrome on iOS prior to 89.0.4389.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page and a malicious server.
Published 2021-03-09 · Modified
6.5EPSS 0.009
CVE-2023-29408
Excessive resource consumption in golang.org/x/image/tiff
Published 2023-08-02 · Modified
6.5EPSS 0.009
CVE-2023-29659
A Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the heif::Fraction::round() function in box.cc, which causes a denial of service.
Published 2023-05-05 · Modified
6.5EPSS 0.009
CVE-2024-4950
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published 2024-05-15 · Modified
6.5EPSS 0.009
CVE-2023-1822
Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Published 2023-04-04 · Modified
6.5EPSS 0.009
CVE-2019-5814
Insufficient policy enforcement in Blink in Google Chrome prior to 74.0.3729.108 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2019-06-27 · Modified
6.5EPSS 0.009
CVE-2021-38010
Inappropriate implementation in service workers in Google Chrome prior to 96.0.4664.45 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.009
CVE-2024-4059
Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)
Published 2024-05-01 · Modified
6.5EPSS 0.009
CVE-2020-15216
Signature Validation Bypass in goxmldsig
Published 2020-09-29 · Modified
6.5EPSS 0.009
CVE-2023-31147
Insufficient randomness in generation of DNS query IDs in c-ares
Published 2023-05-25 · Modified
6.5EPSS 0.009
CVE-2021-34340
Ming 0.4.8 has an out-of-bounds buffer access issue in the function decompileINCR_DECR() in decompiler.c file that causes a direct segmentation fault and leads to denial of service.
Published 2022-03-07 · Modified
6.5EPSS 0.009
CVE-2021-34341
Ming 0.4.8 has an out-of-bounds read vulnerability in the function decompileIF() in the decompile.c file that causes a direct segmentation fault and leads to denial of service.
Published 2022-03-07 · Modified
6.5EPSS 0.009
CVE-2022-42010
An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures.
Published 2022-10-09 · Modified
6.5EPSS 0.009
CVE-2023-1823
Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2023-04-04 · Modified
6.5EPSS 0.009
CVE-2023-1814
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass download checking via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-04-04 · Modified
6.5EPSS 0.009
CVE-2023-1819
Out of bounds read in Accessibility in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-04-04 · Modified
6.5EPSS 0.009
CVE-2023-29407
Excessive CPU consumption when decoding 0-height images in golang.org/x/image/tiff
Published 2023-08-02 · Modified
6.5EPSS 0.009
CVE-2023-4350
Inappropriate implementation in Fullscreen in Google Chrome on Android prior to 116.0.5845.96 allowed a remote attacker to potentially spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)
Published 2023-08-15 · Modified
6.5EPSS 0.009
CVE-2024-32760
NGINX HTTP/3 QUIC vulnerability
Published 2024-05-29 · Analyzed
6.5EPSS 0.009
CVE-2022-0113
Inappropriate implementation in Blink in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2022-02-11 · Modified
6.5EPSS 0.009
CVE-2021-38022
Inappropriate implementation in WebAuthentication in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
Published 2021-12-23 · Modified
6.5EPSS 0.009
CVE-2020-13231
In Cacti before 1.2.11, auth_profile.php?action=edit allows CSRF for an admin email change.
Published 2020-05-20 · Modified
6.5EPSS 0.009
CVE-2021-21229
Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Published 2021-04-30 · Modified
6.5EPSS 0.009
CVE-2019-13740
Incorrect security UI in sharing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.
Published 2019-12-10 · Modified
6.5EPSS 0.008
CVE-2023-1821
Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Published 2023-04-04 · Modified
6.5EPSS 0.008
← Prev89 / 135Next →