VendorsFedora Projectfedoraall versions
Vulnerabilities

Fedora Project Fedora

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5368CVEs
CVE-2021-45472
In MediaWiki through 1.37, XSS can occur in Wikibase because an external identifier property can have a URL format that includes a $1 formatter substitution marker, and the javascript: URL scheme (among others) can be used.
Published 2021-12-24 · Modified
6.1EPSS 0.010
CVE-2021-45474
In MediaWiki through 1.37, the Special:ImportFile URI (aka FileImporter) allows XSS, as demonstrated by the clientUrl parameter.
Published 2021-12-24 · Modified
6.1EPSS 0.010
CVE-2021-37999
Insufficient data validation in New Tab Page in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to inject arbitrary scripts or HTML in a new browser tab via a crafted HTML page.
Published 2021-11-23 · Modified
6.1EPSS 0.010
CVE-2023-22298
Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.
Published 2023-01-17 · Modified
6.1EPSS 0.009
CVE-2023-39513
Stored Cross-site Scripting on host.php verbose data-query debug view in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.009
CVE-2023-39360
Reflected Cross-site Scripting in graphs_new.php in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.009
CVE-2022-27920
libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.
Published 2022-03-25 · Modified
6.1EPSS 0.009
CVE-2023-39366
Stored Cross-site Scripting in data_sources.php through Device-Name in 'select' input in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.009
CVE-2023-39514
Stored Cross-site Scripting on graphs.php data template formated name view in Cacti
Published 2023-09-05 · Analyzed
6.1EPSS 0.009
CVE-2021-43558
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
Published 2021-11-22 · Modified
6.1EPSS 0.009
CVE-2023-39516
Stored Cross-Site-Scripting on data_sources.php debug html-block in Cacti
Published 2023-09-05 · Analyzed
6.1EPSS 0.008
CVE-2023-39515
Stored Cross-site Scripting on data_debug.php datasource path view in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.008
CVE-2023-39510
Stored Cross-site Scripting in reports_admin.php through Device-Name in 'select' input in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.008
CVE-2023-39512
Stored Cross-site Scripting on data_sources.php device name view in Cacti
Published 2023-09-05 · Modified
6.1EPSS 0.008
CVE-2022-40626
Reflected XSS in the backurl parameter of Zabbix Frontend
Published 2022-09-14 · Modified
6.1EPSS 0.008
CVE-2023-39511
Stored Cross-Site-Scripting on reports_admin.php device name in Cacti
Published 2023-09-06 · Analyzed
6.1EPSS 0.008
CVE-2014-7154
Race condition in HVMOP_track_dirty_vram in Xen 4.0.0 through 4.4.x does not ensure possession of the guarding lock for dirty video RAM tracking, which allows certain local guest domains to cause a denial of service via unspecified vectors.
Published 2014-10-02 · Modified
6.1EPSS 0.007
CVE-2023-28439
ckeditor4 plugins vulnerable to cross-site scripting caused by the editor instance destroying process
Published 2023-03-22 · Modified
6.1EPSS 0.007
CVE-2020-25664
In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of-bounds write later when PopShortPixel() from MagickCore/quantum-private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.
Published 2020-12-08 · Modified
6.1EPSS 0.007
CVE-2022-45150
A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in user's browser in context of vulnerable website. This vulnerability may allow an attacker to perform cross-site scripting (XSS) attacks to gain access potentially sensitive information and modification of web pages.
Published 2022-11-23 · Modified
6.1EPSS 0.007
CVE-2022-46391
AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.
Published 2022-12-04 · Modified
6.1EPSS 0.007
CVE-2024-27306
aiohttp vulnerable to XSS on index pages for static file handling
Published 2024-04-18 · Modified
6.1EPSS 0.007
CVE-2021-20208
A flaw was found in cifs-utils in versions before 6.13. A user when mounting a krb5 CIFS file system from within a container can use Kerberos credentials of the host. The highest threat from this vulnerability is to data confidentiality and integrity.
Published 2021-04-19 · Modified
6.1EPSS 0.007
CVE-2023-47272
Roundcube 1.5.x before 1.5.6 and 1.6.x before 1.6.5 allows XSS via a Content-Type or Content-Disposition header (used for attachment preview or download).
Published 2023-11-05 · Modified
6.1EPSS 0.006
CVE-2023-22911
An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML attribute context.
Published 2023-01-10 · Modified
6.1EPSS 0.006
CVE-2022-1355
A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of service.
Published 2022-08-31 · Modified
6.1EPSS 0.006
CVE-2019-3870
A vulnerability was found in Samba from version (including) 4.9 to versions before 4.9.6 and 4.10.2. During the creation of a new Samba AD DC, files are created in a private subdirectory of the install location. This directory is typically mode 0700, that is owner (root) only access. However in some upgraded installations it will have other permissions, such as 0755, because this was the default before Samba 4.8. Within this directory, files are created with mode 0666, which is world-writable, including a sample krb5.conf, and the list of DNS names and servicePrincipalName values to update.
Published 2019-04-09 · Modified
6.1EPSS 0.006
CVE-2023-5547
Moodle: xss risk when previewing data in course upload tool
Published 2023-11-09 · Modified
6.1EPSS 0.005
CVE-2024-34500
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in the Hooks class.
Published 2024-05-05 · Modified
6.1EPSS 0.005
CVE-2023-39193
Kernel: netfilter: xtables sctp out-of-bounds read in match_flags()
Published 2023-10-09 · Modified
6.1EPSS 0.004
CVE-2024-38274
moodle: stored XSS via calendar's event title when deleting the event
Published 2024-06-18 · Analyzed
6.1EPSS 0.004
CVE-2021-3623
A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this vulnerability is to system availability.
Published 2022-03-02 · Modified
6.1EPSS 0.003
CVE-2011-0495
Stack-based buffer overflow in the ast_uri_encode function in main/utils.c in Asterisk Open Source before 1.4.38.1, 1.4.39.1, 1.6.1.21, 1.6.2.15.1, 1.6.2.16.1, 1.8.1.2, 1.8.2.; and Business Edition before C.3.6.2; when running in pedantic mode allows remote authenticated users to execute arbitrary code via crafted caller ID data in vectors involving the (1) SIP channel driver, (2) URIENCODE dialplan function, or (3) AGI dialplan function.
Published 2011-01-20 · Modified
6.0EPSS 0.042
CVE-2020-13401
An issue was discovered in Docker Engine before 19.03.11. An attacker in a container, with the CAP_NET_RAW capability, can craft IPv6 router advertisements, and consequently spoof external IPv6 hosts, obtain sensitive information, or cause a denial of service.
Published 2020-06-02 · Modified
6.0EPSS 0.028
CVE-2009-2813
Samba 3.4 before 3.4.2, 3.3 before 3.3.8, 3.2 before 3.2.15, and 3.0.12 through 3.0.36, as used in the SMB subsystem in Apple Mac OS X 10.5.8 when Windows File Sharing is enabled, Fedora 11, and other operating systems, does not properly handle errors in resolving pathnames, which allows remote authenticated users to bypass intended sharing restrictions, and read, create, or modify files, in certain circumstances involving user accounts that lack home directories.
Published 2009-09-14 · Modified
6.0EPSS 0.027
CVE-2012-1988
Puppet 2.6.x before 2.6.15 and 2.7.x before 2.7.13, and Puppet Enterprise (PE) Users 1.0, 1.1, 1.2.x, 2.0.x, and 2.5.x before 2.5.1 allows remote authenticated users with agent SSL keys and file-creation permissions on the puppet master to execute arbitrary commands by creating a file whose full pathname contains shell metacharacters, then performing a filebucket request.
Published 2012-05-29 · Modified
6.0EPSS 0.026
CVE-2020-10749
A vulnerability was found in all versions of containernetworking/plugins before version 0.8.6, that allows malicious containers in Kubernetes clusters to perform man-in-the-middle (MitM) attacks. A malicious container can exploit this flaw by sending rogue IPv6 router advertisements to the host or other containers, to redirect traffic to the malicious container.
Published 2020-06-03 · Modified
6.0EPSS 0.024
CVE-2020-4050
set-screen-option filter misuse by plugins leading to privilege escalation in WordPress
Published 2020-06-12 · Modified
6.0EPSS 0.014
CVE-2019-14891
A flaw was found in cri-o, as a result of all pod-related processes being placed in the same memory cgroup. This can result in container management (conmon) processes being killed if a workload process triggers an out-of-memory (OOM) condition for the cgroup. An attacker could abuse this flaw to get host network access on an cri-o host.
Published 2019-11-25 · Modified
6.0EPSS 0.008
CVE-2020-27171
An issue was discovered in the Linux kernel before 5.11.8. kernel/bpf/verifier.c has an off-by-one error (with a resultant integer underflow) affecting out-of-bounds speculation on pointer arithmetic, leading to side-channel attacks that defeat Spectre mitigations and obtain sensitive information from kernel memory, aka CID-10d2bb2e6b1d.
Published 2021-03-20 · Modified
6.0EPSS 0.006
← Prev96 / 135Next →