VendorsFedora Projectfedora38
Vulnerabilities

Fedora Project Fedora 38

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

640CVEs
CVE-2024-27507
libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.
Published 2024-02-27 · Modified
7.5EPSS 0.012
CVE-2023-31137
MaraDNS Integer Underflow Vulnerability in DNS Packet Decompression
Published 2023-05-09 · Modified
7.5EPSS 0.011
CVE-2021-43612
In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
Published 2023-04-15 · Modified
7.5EPSS 0.011
CVE-2023-44271
An issue was discovered in Pillow before 10.0.0. It is a Denial of Service that uncontrollably allocates memory to process a given task, potentially causing a service to crash by having it run out of memory. This occurs for truetype in ImageFont when textlength in an ImageDraw instance operates on a long text argument.
Published 2023-11-03 · Modified
7.5EPSS 0.011
CVE-2023-41909
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
Published 2023-09-05 · Modified
7.5EPSS 0.011
CVE-2023-38552
When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x. Please note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.
Published 2023-10-18 · Modified
7.5EPSS 0.011
CVE-2024-1622
Routinator terminates when RTR connection is reset too quickly after opening
Published 2024-02-26 · Analyzed
7.5EPSS 0.010
CVE-2023-2135
Use after free in DevTools in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who convinced a user to enable specific preconditions to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2023-04-19 · Modified
7.5EPSS 0.010
CVE-2023-39197
Kernel: dccp: conntrack out-of-bounds read in nf_conntrack_dccp_packet()
Published 2024-01-23 · Modified
7.5EPSS 0.010
CVE-2023-29530
Laminas Diactoros vulnerable to HTTP Multiline Header Termination
Published 2023-04-24 · Modified
7.5EPSS 0.010
CVE-2024-3772
Regular expression denial of service in Pydantic < 2.4.0
Published 2024-04-15 · Analyzed
7.5EPSS 0.010
CVE-2024-25978
Msa-24-0001: denial of service risk in file picker unzip functionality
Published 2024-02-19 · Analyzed
7.5EPSS 0.009
CVE-2024-23835
Suricata's pgsql: memory exhaustion use on record parsing
Published 2024-02-26 · Analyzed
7.5EPSS 0.009
CVE-2024-3840
Insufficient policy enforcement in Site Isolation in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-04-17 · Analyzed
7.5EPSS 0.009
CVE-2023-43615
Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.
Published 2023-10-07 · Modified
7.5EPSS 0.008
CVE-2023-34058
VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html  in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Published 2023-10-27 · Modified
7.5EPSS 0.007
CVE-2024-0804
Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published 2024-01-23 · Modified
7.5EPSS 0.005
CVE-2023-39198
Kernel: qxl: race condition leading to use-after-free in qxl_mode_dumb_create()
Published 2023-11-09 · Modified
7.5EPSS 0.004
CVE-2023-0361
A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the attacker would need to send a large amount of specially crafted messages to the vulnerable server. By recovering the secret from the ClientKeyExchange message, the attacker would be able to decrypt the application data exchanged over that connection.
Published 2023-02-15 · Modified
7.4EPSS 0.014
CVE-2023-38709
Apache HTTP Server: HTTP response splitting
Published 2024-04-04 · Modified
7.3EPSS 0.039
CVE-2023-7104
SQLite SQLite3 make alltest sqlite3session.c sessionReadRecord heap-based overflow
Published 2023-12-25 · Modified
7.3EPSS 0.012
CVE-2023-30944
Moodle: minor sql injection risk in external wiki method for listing pages
Published 2023-05-02 · Modified
7.3EPSS 0.011
CVE-2023-1170
Heap-based Buffer Overflow in vim/vim
Published 2023-03-03 · Analyzed
7.3EPSS 0.005
CVE-2023-1175
Incorrect Calculation of Buffer Size in vim/vim
Published 2023-03-04 · Analyzed
7.3EPSS 0.004
CVE-2023-39362
Authenticated command injection in SNMP options of a Device
Published 2023-09-05 · Modified
7.21 PoCEPSS 0.854
CVE-2023-27320
Sudo before 1.9.13p2 has a double free in the per-command chroot feature.
Published 2023-02-28 · Modified
7.2EPSS 0.017
CVE-2023-2454
schema_element defeats protective search_path changes; It was found that certain database calls in PostgreSQL could permit an authed attacker with elevated database-level privileges to execute arbitrary code.
Published 2023-06-09 · Modified
7.2EPSS 0.012
CVE-2022-41804
Unauthorized error injection in Intel(R) SGX or Intel(R) TDX for some Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-08-11 · Modified
7.2EPSS 0.003
CVE-2022-48541
A memory leak in ImageMagick 7.0.10-45 and 6.9.11-22 allows remote attackers to perform a denial of service via the "identify -help" command.
Published 2023-08-22 · Modified
7.1EPSS 0.015
CVE-2023-34241
CUPS vulnerable to use-after-free in cupsdAcceptClient()
Published 2023-06-22 · Modified
7.1EPSS 0.014
CVE-2023-3758
Sssd: race condition during authorization leads to gpo policies functioning inconsistently
Published 2024-04-18 · Modified
7.1EPSS 0.010
CVE-2023-28447
Cross site scripting vulnerability in Javascript escaping in smarty/smarty
Published 2023-03-28 · Modified
7.1EPSS 0.010
CVE-2021-29390
libjpeg-turbo version 2.0.90 has a heap-based buffer over-read (2 bytes) in decompress_smooth_data in jdcoefct.c.
Published 2023-08-22 · Modified
7.1EPSS 0.008
CVE-2023-28686
Dino before 0.2.3, 0.3.x before 0.3.2, and 0.4.x before 0.4.2 allows attackers to modify the personal bookmark store via a crafted message. The attacker can change the display of group chats or force a victim to join a group chat; the victim may then be tricked into disclosing sensitive information.
Published 2023-03-24 · Modified
7.1EPSS 0.007
CVE-2023-2460
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 113.0.5672.63 allowed an attacker who convinced a user to install a malicious extension to bypass file access checks via a crafted HTML page. (Chromium security severity: Medium)
Published 2023-05-02 · Modified
7.1EPSS 0.007
CVE-2023-4156
Heap out of bound read in builtin.c
Published 2023-09-25 · Modified
7.1EPSS 0.004
CVE-2024-27016
netfilter: flowtable: validate pppoe header
Published 2024-05-01 · Modified
7.1EPSS 0.003
CVE-2023-29483
eventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly sending an invalid packet from the expected IP address and source port, aka a "TuDoor" attack. In other words, dnspython does not have the preferred behavior in which the DNS name resolution algorithm would proceed, within the full time window, in order to wait for a valid packet. NOTE: dnspython 2.6.0 is unusable for a different reason that was addressed in 2.6.1.
Published 2024-04-11 · Modified
7.0EPSS 0.019
CVE-2023-4504
OpenPrinting CUPS/libppd Postscript Parsing Heap Overflow
Published 2023-09-21 · Modified
7.0EPSS 0.007
CVE-2023-4001
Grub2: bypass the grub password protection feature
Published 2024-01-15 · Modified
6.8EPSS 0.005
← Prev9 / 16Next →