fedoraproject
74 known vulnerabilities affecting fedoraproject products.
Products
Vulnerabilities by priority
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2021-40438 | Act now | 100.0% | 9.0 | ● | A crafted request uri-path can cause mod_proxy to forward the request to an orig… |
| CVE-2020-1938 | Act now | 99.3% | 9.8 | ● | When using the Apache JServ Protocol (AJP), care must be taken when trusting inc… |
| CVE-2022-2294 | Act now | 70.5% | 8.8 | ● | Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed … |
| CVE-2024-1086 | Act now | 28.1% | 7.8 | ● | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables compon… |
| CVE-2023-38180 | Act now | 14.0% | 7.5 | ● | .NET and Visual Studio Denial of Service Vulnerability |
| CVE-2022-0995 | Act now | 9.5% | 7.8 | ● | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_q… |
| CVE-2020-9484 | High | 56.6% | 7.0 | When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.… | |
| CVE-2021-41184 | Medium | 40.8% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2021-41182 | Medium | 39.4% | 6.5 | jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0… | |
| CVE-2019-10086 | Medium | 29.2% | 7.3 | In Apache Commons Beanutils 1.9.2, a special BeanIntrospector class was added wh… | |
| CVE-2024-21626 | Medium | 18.1% | 8.6 | runc is a CLI tool for spawning and running containers on Linux according to the… | |
| CVE-2020-25649 | Medium | 17.8% | 7.5 | A flaw was found in FasterXML Jackson Databind, where it did not have entity exp… | |
| CVE-2021-20322 | Medium | 6.8% | 7.4 | A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP … | |
| CVE-2022-27666 | Medium | 5.5% | 7.8 | A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ip… | |
| CVE-2023-36664 | Medium | 4.3% | 7.8 | Artifex Ghostscript before 10.01.2 mishandles permission validation for pipe dev… | |
| CVE-2022-37967 | Medium | 4.1% | 7.2 | Windows Kerberos Elevation of Privilege Vulnerability | |
| CVE-2022-38177 | Medium | 3.2% | 7.5 | By spoofing the target resolver with responses that have a malformed ECDSA signa… | |
| CVE-2022-38178 | Medium | 3.0% | 7.5 | By spoofing the target resolver with responses that have a malformed EdDSA signa… | |
| CVE-2022-37966 | Medium | 2.5% | 8.1 | Windows Kerberos RC4-HMAC Elevation of Privilege Vulnerability | |
| CVE-2022-38023 | Medium | 2.4% | 8.1 | Netlogon RPC Elevation of Privilege Vulnerability | |
| CVE-2011-4088 | Medium | 1.6% | 7.5 | ABRT might allow attackers to obtain sensitive information from crash reports. | |
| CVE-2024-22373 | Medium | 1.6% | 8.1 | An out-of-bounds write vulnerability exists in the JPEG2000Codec::DecodeByStream… | |
| CVE-2021-41164 | Medium | 1.3% | 8.2 | CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerab… | |
| CVE-2022-1011 | Medium | 1.2% | 7.8 | A use-after-free flaw was found in the Linux kernel’s FUSE filesystem in the way… | |
| CVE-2024-27398 | Medium | 0.8% | 8.0 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: … | |
| CVE-2021-33034 | Medium | 0.8% | 7.8 | In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-fre… | |
| CVE-2023-6546 | Medium | 0.7% | 7.0 | A race condition was found in the GSM 0710 tty multiplexor in the Linux kernel. … | |
| CVE-2021-44733 | Medium | 0.7% | 7.0 | A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Lin… | |
| CVE-2024-27018 | Medium | 0.6% | 8.2 | In the Linux kernel, the following vulnerability has been resolved: netfilter: … | |
| CVE-2021-3739 | Medium | 0.6% | 7.1 | A NULL pointer dereference flaw was found in the btrfs_rm_device function in fs/… | |
| CVE-2023-4752 | Medium | 0.6% | 7.8 | Use After Free in GitHub repository vim/vim prior to 9.0.1858. | |
| CVE-2023-4733 | Medium | 0.5% | 7.8 | Use After Free in GitHub repository vim/vim prior to 9.0.1840. | |
| CVE-2023-5535 | Medium | 0.5% | 7.8 | Use After Free in GitHub repository vim/vim prior to v9.0.2010. | |
| CVE-2023-4750 | Medium | 0.5% | 7.8 | Use After Free in GitHub repository vim/vim prior to 9.0.1857. | |
| CVE-2022-1055 | Medium | 0.5% | 7.8 | A use-after-free exists in the Linux Kernel in tc_new_tfilter that could allow a… | |
| CVE-2022-26490 | Medium | 0.4% | 7.8 | st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux k… | |
| CVE-2022-24958 | Medium | 0.4% | 7.8 | drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles … | |
| CVE-2021-41864 | Medium | 0.4% | 7.8 | prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before … | |
| CVE-2022-0330 | Medium | 0.4% | 7.8 | A random memory access flaw was found in the Linux kernel's GPU i915 kernel driv… | |
| CVE-2021-3501 | Medium | 0.4% | 7.1 | A flaw was found in the Linux kernel in versions before 5.12. The value of inter… | |
| CVE-2021-23134 | Medium | 0.4% | 7.8 | Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 al… | |
| CVE-2024-27016 | Medium | 0.3% | 7.1 | In the Linux kernel, the following vulnerability has been resolved: netfilter: … | |
| CVE-2024-1488 | Medium | 0.3% | 8.0 | A vulnerability was found in Unbound due to incorrect default permissions, allow… | |
| CVE-2021-38166 | Medium | 0.3% | 7.8 | In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer … | |
| CVE-2024-26922 | Medium | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu:… | |
| CVE-2021-40490 | Medium | 0.3% | 7.0 | A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.… | |
| CVE-2024-27401 | Medium | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: firewire: n… | |
| CVE-2024-26994 | Medium | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: speakup: Av… | |
| CVE-2024-27017 | Medium | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: … | |
| CVE-2024-27012 | Medium | 0.3% | 7.8 | In the Linux kernel, the following vulnerability has been resolved: netfilter: … |
Page 1 of 2
Next →