VendorsFedora Projectfedora37
Vulnerabilities

Fedora Project Fedora 37

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

696CVEs
CVE-2022-22995
Western Digital My Cloud OS 5 and My Cloud Home Unauthenticated Arbitrary File Write Vulnerability in Netatalk
Published 2022-03-25 · Modified
10.0EPSS 0.028
CVE-2023-39361
Unauthenticated SQL Injection in graph_view.php in Cacti
Published 2023-09-05 · Modified
9.8EPSS 0.888
CVE-2023-38408
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
Published 2023-07-20 · Modified
9.8EPSS 0.797
CVE-2023-38545
This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.
Published 2023-10-18 · Modified
9.8EPSS 0.785
CVE-2022-39379
Fluentd vulnerable to remote code execution due to insecure deserialization (in non-default configuration)
Published 2022-11-02 · Modified
9.8EPSS 0.450
CVE-2022-25765
Command Injection
Published 2022-09-09 · Modified
9.8EPSS 0.430
CVE-2022-37434
zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field. NOTE: only applications that call inflateGetHeader are affected. Some common applications bundle the affected zlib source code but may be unable to call inflateGetHeader (e.g., see the nodejs/node reference).
Published 2022-08-05 · Modified
9.8EPSS 0.179
CVE-2023-34152
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
Published 2023-05-30 · Modified
9.8EPSS 0.080
CVE-2022-24439
Remote Code Execution (RCE)
Published 2022-12-12 · Modified
9.8EPSS 0.057
CVE-2022-45063
xterm before 375 allows code execution via font ops, e.g., because an OSC 50 response may have Ctrl-g and therefore lead to command execution within the vi line-editing mode of Zsh. NOTE: font ops are not allowed in the xterm default configurations of some Linux distributions.
Published 2022-11-10 · Modified
9.8EPSS 0.054
CVE-2022-35951
Redis subject to Integer Overflow leading to Remote Code Execution via Heap Overflow
Published 2022-09-23 · Modified
9.8EPSS 0.039
CVE-2022-42920
Apache Commons BCEL prior to 6.6.0 allows producing arbitrary bytecode via out-of-bounds writing
Published 2022-11-07 · Modified
9.8EPSS 0.030
CVE-2021-35368
OWASP ModSecurity Core Rule Set 3.1.x before 3.1.2, 3.2.x before 3.2.1, and 3.3.x before 3.3.2 is affected by a Request Body Bypass via a trailing pathname.
Published 2021-11-05 · Modified
9.8EPSS 0.027
CVE-2022-21797
Arbitrary Code Execution
Published 2022-09-26 · Modified
9.8EPSS 0.026
CVE-2022-36227
In libarchive before 3.6.2, the software does not check for an error after calling calloc function that can return with a NULL pointer if the function fails, which leads to a resultant NULL pointer dereference. NOTE: the discoverer cites this CWE-476 remark but third parties dispute the code-execution impact: "In rare circumstances, when NULL is equivalent to the 0x0 memory address and privileged code can access it, then writing or reading memory is possible, which may lead to code execution."
Published 2022-11-22 · Modified
9.8EPSS 0.024
CVE-2022-3275
Puppetlabs-apt Command Injection
Published 2022-10-07 · Modified
9.8EPSS 0.022
CVE-2022-4170
The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.
Published 2022-12-09 · Modified
9.8EPSS 0.021
CVE-2020-7677
Arbitrary Code Execution
Published 2022-07-25 · Modified
9.8EPSS 0.020
CVE-2023-39352
Invalid offset validation leading to Out Of Bound Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.015
CVE-2023-40567
Out-Of-Bounds Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.015
CVE-2022-45062
In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.
Published 2022-11-09 · Modified
9.8EPSS 0.015
CVE-2022-39955
Partial rule set bypass in OWASP ModSecurity Core Rule Set by submitting a specially crafted HTTP Content-Type header
Published 2022-09-20 · Modified
9.8EPSS 0.014
CVE-2023-40186
IntegerOverflow leading to Out-Of-Bound Write Vulnerability in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.014
CVE-2023-40569
Out-Of-Bounds Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.013
CVE-2023-36328
Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).
Published 2023-09-01 · Modified
9.8EPSS 0.013
CVE-2022-39956
Partial rule set bypass in OWASP ModSecurity Core Rule Set for HTTP multipart requests using character encoding in the Content-Type or Content-Transfer-Encoding header
Published 2022-09-20 · Modified
9.8EPSS 0.012
CVE-2023-29141
An issue was discovered in MediaWiki before 1.35.10, 1.36.x through 1.38.x before 1.38.6, and 1.39.x before 1.39.3. An auto-block can occur for an untrusted X-Forwarded-For header.
Published 2023-03-31 · Modified
9.8EPSS 0.012
CVE-2022-46393
An issue was discovered in Mbed TLS before 2.28.2 and 3.x before 3.3.0. There is a potential heap-based buffer overflow and heap-based buffer over-read in DTLS if MBEDTLS_SSL_DTLS_CONNECTION_ID is enabled and MBEDTLS_SSL_CID_IN_LEN_MAX > 2 * MBEDTLS_SSL_CID_OUT_LEN_MAX.
Published 2022-12-15 · Modified
9.8EPSS 0.012
CVE-2023-1529
Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)
Published 2023-03-21 · Modified
9.8EPSS 0.011
CVE-2023-4322
Heap-based Buffer Overflow in radareorg/radare2
Published 2023-08-14 · Modified
9.8EPSS 0.009
CVE-2022-3620
Exim DMARC dmarc.c dmarc_dns_lookup use after free
Published 2022-10-20 · Analyzed
9.8EPSS 0.008
CVE-2021-33640
After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).
Published 2022-12-19 · Modified
9.8EPSS 0.007
CVE-2023-6345
Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Published 2023-11-29 · Analyzed
9.6KEVEPSS 0.165
CVE-2022-3075
Insufficient data validation in Mojo in Google Chrome prior to 105.0.5195.102 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2022-09-26 · Analyzed
9.6KEVEPSS 0.058
CVE-2023-2136
Integer overflow in Skia in Google Chrome prior to 112.0.5615.137 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2023-04-19 · Analyzed
9.6KEVEPSS 0.057
CVE-2021-38714
In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.
Published 2021-08-24 · Modified
9.3EPSS 0.028
CVE-2022-2010
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2022-07-28 · Modified
9.3EPSS 0.012
CVE-2021-46848
GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.
Published 2022-10-24 · Modified
9.1EPSS 0.022
CVE-2022-24790
HTTP Request Smuggling in puma
Published 2022-03-30 · Modified
9.1EPSS 0.022
CVE-2023-39356
Missing offset validation leading to Out-of-Bounds Read in FreeRDP
Published 2023-08-31 · Modified
9.1EPSS 0.018
1 / 18Next →