VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2019-15945
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Bitstring in decode_bit_string in libopensc/asn1.c.
Published 2019-09-05 · Modified
6.4EPSS 0.004
CVE-2023-31130
Buffer Underwrite in ares_inet_net_pton()
Published 2023-05-25 · Modified
6.4EPSS 0.004
CVE-2019-15946
OpenSC before 0.20.0-rc1 has an out-of-bounds access of an ASN.1 Octet string in asn1_decode_entry in libopensc/asn1.c.
Published 2019-09-05 · Modified
6.4EPSS 0.004
CVE-2021-22004
An issue was discovered in SaltStack Salt before 3003.3. The salt minion installer will accept and use a minion config file at C:\salt\conf if that file is in place before the installer is run. This allows for a malicious actor to subvert the proper behaviour of the given minion software.
Published 2021-09-08 · Modified
6.4EPSS 0.004
CVE-2021-35937
A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Published 2022-08-25 · Modified
6.4EPSS 0.003
CVE-2021-3700
A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.
Published 2022-02-24 · Modified
6.4EPSS 0.003
CVE-2020-25651
A flaw was found in the SPICE file transfer protocol. File data from the host system can end up in full or in parts in the client connection of an illegitimate local user in the VM system. Active file transfers from other users could also be interrupted, resulting in a denial of service. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.
Published 2020-11-26 · Modified
6.4EPSS 0.003
CVE-2020-13965
An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview.
Published 2020-06-09 · Analyzed
6.3KEVEPSS 0.766
CVE-2023-45866
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
Published 2023-12-08 · Modified
6.3EPSS 0.079
CVE-2022-3140
Macro URL arbitrary script execution
Published 2022-10-11 · Modified
6.3EPSS 0.057
CVE-2019-16782
Possible Information Leak / Session Hijack Vulnerability in Rack
Published 2019-12-18 · Modified
6.3EPSS 0.037
CVE-2020-8555
Kubernetes kube-controller-manager SSRF
Published 2020-06-04 · Modified
6.3EPSS 0.037
CVE-2024-24795
Apache HTTP Server: HTTP Response Splitting in multiple modules
Published 2024-04-04 · Analyzed
6.3EPSS 0.029
CVE-2021-41091
Insufficiently restricted permissions on data directory in Docker Engine
Published 2021-10-04 · Modified
6.3EPSS 0.028
CVE-2024-23672
Apache Tomcat: WebSocket DoS with incomplete closing handshake
Published 2024-03-13 · Modified
6.3EPSS 0.023
CVE-2022-3190
Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file
Published 2022-09-13 · Modified
6.3EPSS 0.023
CVE-2021-21334
environment variable leak
Published 2021-03-10 · Modified
6.3EPSS 0.020
CVE-2021-2022
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Published 2021-01-20 · Modified
6.3EPSS 0.019
CVE-2021-2006
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published 2021-01-20 · Modified
6.3EPSS 0.018
CVE-2020-1945
Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an attacker to inject modified source files into the build process.
Published 2020-05-14 · Modified
6.3EPSS 0.018
CVE-2022-21254
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published 2022-01-19 · Modified
6.3EPSS 0.017
CVE-2021-40403
An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory contents. An attacker can provide a malicious file to trigger this vulnerability.
Published 2022-02-04 · Modified
6.3EPSS 0.011
CVE-2022-36109
Moby vulnerability relating to supplementary group permissions
Published 2022-09-09 · Modified
6.3EPSS 0.010
CVE-2022-23133
Stored XSS in host groups configuration window in Zabbix Frontend
Published 2022-01-13 · Modified
6.3EPSS 0.010
CVE-2021-21392
Open redirect via transitional IPv6 addresses on dual-stack networks
Published 2021-04-12 · Modified
6.3EPSS 0.009
CVE-2022-2980
NULL Pointer Dereference in vim/vim
Published 2022-08-25 · Modified
6.3EPSS 0.009
CVE-2023-39365
Unchecked regular expressions can lead to SQL Injection and data leakage in Cacti
Published 2023-09-05 · Modified
6.3EPSS 0.009
CVE-2021-3802
A vulnerability found in udisks2. This flaw allows an attacker to input a specially crafted image file/USB leading to kernel panic. The highest threat from this vulnerability is to system availability.
Published 2021-11-29 · Modified
6.3EPSS 0.008
CVE-2022-2164
Inappropriate implementation in Extensions API in Google Chrome prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted HTML page.
Published 2022-07-28 · Modified
6.3EPSS 0.006
CVE-2020-28049
An issue was discovered in SDDM before 0.19.0. It incorrectly starts the X server in a way that - for a short time period - allows local unprivileged users to create a connection to the X server without providing proper authentication. A local attacker can thus access X server display contents and, for example, intercept keystrokes or access the clipboard. This is caused by a race condition during Xauthority file creation.
Published 2020-11-04 · Modified
6.3EPSS 0.004
CVE-2021-39219
Wrong type for `Linker`-define functions when used across two `Engine`s
Published 2021-09-17 · Modified
6.3EPSS 0.004
CVE-2020-25653
A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from the host. The highest threat from this vulnerability is to data confidentiality as well as system availability. This flaw affects spice-vdagent versions 0.20 and prior.
Published 2020-11-26 · Modified
6.3EPSS 0.003
CVE-2023-1544
Qemu: pvrdma: out-of-bounds read in pvrdma_ring_next_elem_read()
Published 2023-03-23 · Modified
6.3EPSS 0.003
CVE-2021-39216
Use after free passing `externref`s to Wasm in Wasmtime
Published 2021-09-17 · Modified
6.3EPSS 0.003
CVE-2021-39218
Out-of-bounds read/write and invalid free with `externref`s and GC safepoints in Wasmtime
Published 2021-09-17 · Modified
6.3EPSS 0.003
CVE-2021-41089
`docker cp` allows unexpected chmod of host files
Published 2021-10-04 · Modified
6.3EPSS 0.003
CVE-2012-5630
libuser 0.56 and 0.57 has a TOCTOU (time-of-check time-of-use) race condition when copying and removing directory trees.
Published 2019-11-25 · Modified
6.3EPSS 0.003
CVE-2020-3350
Cisco AMP for Endpoints and ClamAV Privilege Escalation Vulnerability
Published 2020-06-18 · Modified
6.3EPSS 0.003
CVE-2023-1611
A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea
Published 2023-04-03 · Modified
6.3EPSS 0.002
CVE-2010-4258
The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.
Published 2010-12-30 · Modified
6.21 PoCEPSS 0.027
← Prev92 / 135Next →