VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2022-32511
jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.
Published 2022-06-06 · Modified
9.8EPSS 0.024
CVE-2021-28879
In the standard library in Rust before 1.52.0, the Zip implementation can report an incorrect size due to an integer overflow. This bug can lead to a buffer overflow when a consumed Zip iterator is used again.
Published 2021-04-11 · Modified
9.8EPSS 0.024
CVE-2023-3961
Samba: smbd allows client access to unix domain sockets on the file system as root
Published 2023-11-03 · Modified
9.8EPSS 0.024
CVE-2019-18928
Cyrus IMAP 2.5.x before 2.5.14 and 3.x before 3.0.12 allows privilege escalation because an HTTP request may be interpreted in the authentication context of an unrelated previous request that arrived over the same connection.
Published 2019-11-15 · Modified
9.8EPSS 0.024
CVE-2020-17353
scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.
Published 2020-08-05 · Modified
9.8EPSS 0.024
CVE-2017-9104
An issue was discovered in adns before 1.5.2. It hangs, eating CPU, if a compression pointer loop is encountered.
Published 2020-06-18 · Modified
9.8EPSS 0.024
CVE-2022-24883
FreeRDP Server authentication might allow invalid credentials to pass
Published 2022-04-26 · Modified
9.8EPSS 0.024
CVE-2019-19010
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
Published 2019-11-16 · Modified
9.8EPSS 0.023
CVE-2010-4197
Use-after-free vulnerability in WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving text editing.
Published 2010-11-05 · Modified
9.8EPSS 0.023
CVE-2018-17825
An issue was discovered in AdPlug 2.3.1. There are several double-free vulnerabilities in the CEmuopl class in emuopl.cpp because of a destructor's two OPLDestroy calls, each of which frees TL_TABLE, SIN_TABLE, AMS_TABLE, and VIB_TABLE.
Published 2018-10-01 · Modified
9.8EPSS 0.023
CVE-2024-32039
FreeRDP Integer overflow & OutOfBound Write in clear_decompress_residual_data
Published 2024-04-22 · Modified
9.8EPSS 0.023
CVE-2017-18922
It was discovered that websockets.c in LibVNCServer prior to 0.9.12 did not properly decode certain WebSocket frames. A malicious attacker could exploit this by sending specially crafted WebSocket frames to a server, causing a heap-based buffer overflow.
Published 2020-06-30 · Modified
9.8EPSS 0.023
CVE-2010-4204
WebKit, as used in Google Chrome before 7.0.517.44, webkitgtk before 1.2.6, and other products, accesses a frame object after this object has been destroyed, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Published 2010-11-05 · Modified
9.8EPSS 0.023
CVE-2018-18408
A use-after-free was discovered in the tcpbridge binary of Tcpreplay 4.3.0 beta1. The issue gets triggered in the function post_args() at tcpbridge.c, causing a denial of service or possibly unspecified other impact.
Published 2018-10-17 · Modified
9.8EPSS 0.023
CVE-2019-18622
An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
Published 2019-11-22 · Modified
9.8EPSS 0.022
CVE-2021-3325
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because a new access-control feature was introduced without considering that some exiting installations became unsafe, upon an update to 3.13.0, unless the new feature was immediately configured.
Published 2021-01-27 · Modified
9.8EPSS 0.022
CVE-2021-30475
aom_dsp/noise_model.c in libaom in AOMedia before 2021-03-24 has a buffer overflow.
Published 2021-06-04 · Modified
9.8EPSS 0.022
CVE-2019-9687
PoDoFo 0.9.6 has a heap-based buffer overflow in PdfString::ConvertUTF16toUTF8 in base/PdfString.cpp.
Published 2019-03-11 · Modified
9.8EPSS 0.022
CVE-2022-3275
Puppetlabs-apt Command Injection
Published 2022-10-07 · Modified
9.8EPSS 0.022
CVE-2021-20204
A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This vulnerability may lead to arbitrary code execution or privilege escalation depending on input/skills of attacker.
Published 2021-05-06 · Modified
9.8EPSS 0.022
CVE-2013-2166
python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass
Published 2019-12-10 · Modified
9.8EPSS 0.021
CVE-2022-4170
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
Published 2022-12-09 · Modified
9.8EPSS 0.021
CVE-2023-6816
Xorg-x11-server: heap buffer overflow in devicefocusevent and procxiquerypointer
Published 2024-01-18 · Modified
9.8EPSS 0.021
CVE-2021-3420
A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buffer and then to a heap-based buffer overflow.
Published 2021-03-05 · Modified
9.8EPSS 0.021
CVE-2019-14532
An issue was discovered in The Sleuth Kit (TSK) 4.6.6. There is an off-by-one overwrite due to an underflow on tools/hashtools/hfind.cpp while using a bogus hash table.
Published 2019-08-02 · Modified
9.8EPSS 0.021
CVE-2019-15151
AdPlug 2.3.1 has a double free in the Cu6mPlayer class in u6m.h.
Published 2019-08-18 · Modified
9.8EPSS 0.021
CVE-2020-26892
The JWT library in NATS nats-server before 2.1.9 has Incorrect Access Control because of how expired credentials are handled.
Published 2020-11-06 · Modified
9.8EPSS 0.021
CVE-2022-31799
Bottle before 0.12.20 mishandles errors during early request binding.
Published 2022-05-29 · Modified
9.8EPSS 0.021
CVE-2017-9109
An issue was discovered in adns before 1.5.2. It fails to ignore apparent answers before the first RR that was found the first time. when this is fixed, the second answer scan finds the same RRs at the first. Otherwise, adns can be confused by interleaving answers for the CNAME target, with the CNAME itself. In that case the answer data structure (on the heap) can be overrun. With this fixed, it prefers to look only at the answer RRs which come after the CNAME, which is at least arguably correct.
Published 2020-06-18 · Modified
9.8EPSS 0.021
CVE-2017-9103
An issue was discovered in adns before 1.5.2. pap_mailbox822 does not properly check st from adns__findlabel_next. Without this, an uninitialised stack value can be used as the first label length. Depending on the circumstances, an attacker might be able to trick adns into crashing the calling program, leaking aspects of the contents of some of its memory, causing it to allocate lots of memory, or perhaps overrunning a buffer. This is only possible with applications which make non-raw queries for SOA or RP records.
Published 2020-06-18 · Modified
9.8EPSS 0.021
CVE-2021-30473
aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.
Published 2021-05-06 · Modified
9.8EPSS 0.021
CVE-2016-6233
The (1) order and (2) group methods in Zend_Db_Select in the Zend Framework before 1.12.19 might allow remote attackers to conduct SQL injection attacks via vectors related to use of the character pattern [\w]* in a regular expression.
Published 2017-02-16 · Modified
9.8EPSS 0.020
CVE-2020-7677
Arbitrary Code Execution
Published 2022-07-25 · Modified
9.8EPSS 0.020
CVE-2023-46850
Use after free in OpenVPN version 2.6.0 to 2.6.6 may lead to undefined behavoir, leaking memory buffers or remote execution when sending network buffers to a remote peer.
Published 2023-11-11 · Modified
9.8EPSS 0.020
CVE-2023-27533
A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input, thereby enabling attackers to execute arbitrary code on the system.
Published 2023-03-30 · Modified
9.8EPSS 0.020
CVE-2022-0582
Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
Published 2022-02-14 · Modified
9.8EPSS 0.020
CVE-2021-20307
Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.
Published 2021-04-05 · Modified
9.8EPSS 0.019
CVE-2024-32458
FreeRDP Out-Of-Bounds Read in planar_skip_plane_rle
Published 2024-04-22 · Modified
9.8EPSS 0.019
CVE-2024-32041
FreeRDP OutOfBound Read in zgfx_decompress_segment
Published 2024-04-22 · Analyzed
9.8EPSS 0.019
CVE-2021-32810
Data race in crossbeam-deque
Published 2021-08-02 · Modified
9.8EPSS 0.019
← Prev9 / 135Next →