VendorsFedora Projectfedora38
Vulnerabilities

Fedora Project Fedora 38

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

639CVEs
CVE-2024-24576
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
Published 2024-04-09 · Analyzed
10.0EPSS 0.203
CVE-2022-22995
Western Digital My Cloud OS 5 and My Cloud Home Unauthenticated Arbitrary File Write Vulnerability in Netatalk
Published 2022-03-25 · Modified
10.0EPSS 0.028
CVE-2023-39361
Unauthenticated SQL Injection in graph_view.php in Cacti
Published 2023-09-05 · Modified
9.8EPSS 0.888
CVE-2023-38408
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an agent is forwarded to an attacker-controlled system. (Code in /usr/lib is not necessarily safe for loading into ssh-agent.) NOTE: this issue exists because of an incomplete fix for CVE-2016-10009.
Published 2023-07-20 · Modified
9.8EPSS 0.797
CVE-2023-3824
Buffer overflow and overread in phar_dir_read()
Published 2023-08-11 · Modified
9.8EPSS 0.218
CVE-2024-1676
Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)
Published 2024-02-21 · Analyzed
9.8EPSS 0.188
CVE-2024-1283
Heap buffer overflow in Skia in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-02-06 · Modified
9.8EPSS 0.187
CVE-2023-34152
A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.
Published 2023-05-30 · Modified
9.8EPSS 0.080
CVE-2022-24439
Remote Code Execution (RCE)
Published 2022-12-12 · Modified
9.8EPSS 0.057
CVE-2024-32459
FreeRDP Out-Of-Bounds Read in ncrush_decompress
Published 2024-04-22 · Modified
9.8EPSS 0.037
CVE-2024-32039
FreeRDP Integer overflow & OutOfBound Write in clear_decompress_residual_data
Published 2024-04-22 · Modified
9.8EPSS 0.023
CVE-2024-32458
FreeRDP Out-Of-Bounds Read in planar_skip_plane_rle
Published 2024-04-22 · Modified
9.8EPSS 0.019
CVE-2024-32041
FreeRDP OutOfBound Read in zgfx_decompress_segment
Published 2024-04-22 · Analyzed
9.8EPSS 0.019
CVE-2024-32460
FreeRDP Out-Of-Bounds Read in interleaved_decompress
Published 2024-04-22 · Modified
9.8EPSS 0.019
CVE-2024-32040
FreeRDP vulnerable to integer underflow in nsc_rle_decode
Published 2024-04-22 · Modified
9.8EPSS 0.019
CVE-2023-29404
Improper handling of non-optional LDFLAGS in go command with cgo in cmd/go
Published 2023-06-08 · Modified
9.8EPSS 0.018
CVE-2023-29405
Improper sanitization of LDFLAGS with embedded spaces in go command with cgo in cmd/go
Published 2023-06-08 · Modified
9.8EPSS 0.017
CVE-2023-29402
Code injection via go command with cgo in cmd/go
Published 2023-06-08 · Modified
9.8EPSS 0.017
CVE-2024-22373
An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStreamsCommon functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted DICOM file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-04-25 · Modified
9.8EPSS 0.016
CVE-2023-6395
Mock: privilege escalation for users that can access mock configuration
Published 2024-01-16 · Modified
9.8EPSS 0.016
CVE-2023-39352
Invalid offset validation leading to Out Of Bound Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.015
CVE-2023-40567
Out-Of-Bounds Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.015
CVE-2023-47212
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-05-01 · Modified
9.8EPSS 0.014
CVE-2024-22391
A heap-based buffer overflow vulnerability exists in the LookupTable::SetLUT functionality of Mathieu Malaterre Grassroot DICOM 3.0.23. A specially crafted malformed file can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
Published 2024-04-25 · Analyzed
9.8EPSS 0.014
CVE-2023-31047
In Django 3.2 before 3.2.19, 4.x before 4.1.9, and 4.2 before 4.2.1, it was possible to bypass validation when using one form field to upload multiple files. This multiple upload has never been supported by forms.FileField or forms.ImageField (only the last uploaded file was validated). However, Django's "Uploading multiple files" documentation suggested otherwise.
Published 2023-05-07 · Modified
9.8EPSS 0.014
CVE-2023-5550
Moodle: rce due to lfi risk in some misconfigured shared hosting environments
Published 2023-11-09 · Modified
9.8EPSS 0.014
CVE-2024-32658
FreeRDP ExtractRunLengthRegular* out of bound read
Published 2024-04-23 · Modified
9.8EPSS 0.014
CVE-2023-40186
IntegerOverflow leading to Out-Of-Bound Write Vulnerability in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.014
CVE-2023-40569
Out-Of-Bounds Write in FreeRDP
Published 2023-08-31 · Modified
9.8EPSS 0.013
CVE-2023-36328
Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).
Published 2023-09-01 · Modified
9.8EPSS 0.013
CVE-2024-3209
UPX bele.h get_ne64 heap-based overflow
Published 2024-04-02 · Analyzed
9.8EPSS 0.012
CVE-2024-32659
freerdp_image_copy out of bound read
Published 2024-04-23 · Modified
9.8EPSS 0.012
CVE-2023-6879
heap buffer overflow in libaom
Published 2023-12-27 · Modified
9.8EPSS 0.012
CVE-2024-1284
Use after free in Mojo in Google Chrome prior to 121.0.6167.160 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2024-02-06 · Modified
9.8EPSS 0.011
CVE-2024-31581
FFmpeg version n6.1 was discovered to contain an improper validation of array index vulnerability in libavcodec/cbs_h266_syntax_template.c. This vulnerability allows attackers to cause undefined behavior within the application.
Published 2024-04-17 · Modified
9.8EPSS 0.011
CVE-2023-1529
Out of bounds memory access in WebHID in Google Chrome prior to 111.0.5563.110 allowed a remote attacker to potentially exploit heap corruption via a malicious HID device. (Chromium security severity: High)
Published 2023-03-21 · Modified
9.8EPSS 0.011
CVE-2023-4322
Heap-based Buffer Overflow in radareorg/radare2
Published 2023-08-14 · Modified
9.8EPSS 0.009
CVE-2024-3847
Insufficient policy enforcement in WebUI in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
Published 2024-04-17 · Analyzed
9.8EPSS 0.009
CVE-2024-3845
Inappropriate implementation in Networks in Google Chrome prior to 124.0.6367.60 allowed a remote attacker to bypass mixed content policy via a crafted HTML page. (Chromium security severity: Low)
Published 2024-04-17 · Analyzed
9.8EPSS 0.009
CVE-2024-32662
FreeRDP rdp_redirection_read_base64_wchar out of bound read
Published 2024-04-23 · Analyzed
9.8EPSS 0.008
1 / 16Next →