VulnSea

fedora vulnerabilities

CVEs whose affected-version data names the fedora package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

97 CVEsRSS

CVE-2021-20322High· 7.4
4y ago

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports

A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effect…

▾ Twilightnetapp · active_iq_unified_managerEPSS 6.9%via NVD
CVE-2022-24958High· 7.8
4y ago

drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

▾ Twilightlinux · linux_kernelEPSS 0.41%via NVD
CVE-2022-23304Critical· 9.8
4y ago

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns

The implementations of EAP-pwd in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side-channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9495.

▾ Midnightw1.fi · hostapdEPSS 1.9%via NVD
CVE-2022-23303Critical· 9.8PoC
4y ago

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns

The implementations of SAE in hostapd before 2.10 and wpa_supplicant before 2.10 are vulnerable to side channel attacks as a result of cache access patterns. NOTE: this issue exists because of an incomplete fix for CVE-2019-9494.

▾ Abyssalw1.fi · hostapdEPSS 3.1%via NVD
CVE-2021-44733High· 7.0PoC
4y ago

A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11

A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11. This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object.

▾ Midnightlinux · linux_kernelEPSS 0.70%via NVD
CVE-2021-41164High· 8.2
4y ago

CKEditor4 is an open source WYSIWYG HTML editor

CKEditor4 is an open source WYSIWYG HTML editor. In affected versions a vulnerability has been discovered in the Advanced Content Filter (ACF) module and may affect all plugins used by CKEditor 4. The vulnerability allowed to inject malf…

▾ Twilightckeditor · ckeditorEPSS 1.3%via NVD
CVE-2021-41184Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `of` option of the `.position()` util from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0.…

▾ Twilightjqueryui · jquery_uiEPSS 41%via NVD
CVE-2021-41183Medium· 6.5
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI …

▾ Sunlitjqueryui · jquery_uiEPSS 8.5%via NVD
CVE-2021-41182Medium· 6.5PoC
4y ago

jQuery-UI is the official jQuery user interface library

jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of the `altField` option of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.…

▾ Twilightjqueryui · jquery_uiEPSS 39%via NVD
CVE-2021-41864High· 7.8
4y ago

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

prealloc_elems_and_freelist in kernel/bpf/stackmap.c in the Linux kernel before 5.14.12 allows unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write.

▾ Twilightnetapp · cloud_backupEPSS 0.41%via NVD
CVE-2021-41617High· 7.0PoC
4y ago

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected

sshd in OpenSSH 6.2 through 8.x before 8.8, when certain non-default configurations are used, allows privilege escalation because supplemental groups are not initialized as expected. Helper programs for AuthorizedKeysCommand and Authoriz…

▾ Midnightopenbsd · opensshEPSS 2.5%via NVD
CVE-2021-40438Critical· 9.0CISA KEVPoC
5y ago

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

▾ Hadalredhat · jboss_core_servicesEPSS 100%via NVD
CVE-2021-35267High· 7.8
5y ago

NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.

NTFS-3G versions < 2021.8.22, a stack buffer overflow can occur when correcting differences in the MFT and MFTMirror allowing for code execution or escalation of privileges when setuid-root.

▾ Twilighttuxera · ntfs-3gEPSS 0.49%via NVD
CVE-2021-35266High· 7.8
5y ago

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode pathname is supplied in an NTFS image a heap buffer overflow can occur resulting in memory disclosure, denial of service and even code execution.

▾ Twilighttuxera · ntfs-3gEPSS 0.49%via NVD
CVE-2021-33287High· 7.8
5y ago

In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.

In NTFS-3G versions < 2021.8.22, when specially crafted NTFS attributes are read in the function ntfs_attr_pread_i, a heap buffer overflow can occur and allow for writing to arbitrary memory or denial of service of the application.

▾ Twilighttuxera · ntfs-3gEPSS 0.41%via NVD
CVE-2021-35269High· 7.8
5y ago

NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.

NTFS-3G versions < 2021.8.22, when a specially crafted NTFS attribute from the MFT is setup in the function ntfs_attr_setup_flag, a heap buffer overflow can occur allowing for code execution and escalation of privileges.

▾ Twilighttuxera · ntfs-3gEPSS 0.48%via NVD
CVE-2021-35268High· 7.8
5y ago

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.

In NTFS-3G versions < 2021.8.22, when a specially crafted NTFS inode is loaded in the function ntfs_inode_real_open, a heap buffer overflow can occur allowing for code execution and escalation of privileges.

▾ Twilighttuxera · ntfs-3gEPSS 0.47%via NVD
CVE-2021-33289High· 7.8
5y ago

In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.

In NTFS-3G versions < 2021.8.22, when a specially crafted MFT section is supplied in an NTFS image a heap buffer overflow can occur and allow for code execution.

▾ Twilighttuxera · ntfs-3gEPSS 0.49%via NVD
CVE-2021-40490High· 7.0
5y ago

A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.

A race condition was discovered in ext4_write_inline_data_end in fs/ext4/inline.c in the ext4 subsystem in the Linux kernel through 5.13.13.

▾ Twilightnetapp · solidfire_baseboard_management_controllerEPSS 0.30%via NVD
CVE-2021-38166High· 7.8
5y ago

In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket

In kernel/bpf/hashtab.c in the Linux kernel through 5.13.8, there is an integer overflow and out-of-bounds write when many elements are placed in a single bucket. NOTE: exploitation might be impractical without the CAP_SYS_ADMIN capability.

▾ Twilightlinux · linux_kernelEPSS 0.32%via NVD
CVE-2021-33034High· 7.8PoC
5y ago

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409

In the Linux kernel before 5.12.4, net/bluetooth/hci_event.c has a use-after-free when destroying an hci_chan, aka CID-5c4c8c954409. This leads to writing an arbitrary value.

▾ Midnightlinux · linux_kernelEPSS 0.82%via NVD
CVE-2021-23134High· 7.8
5y ago

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges

Use After Free vulnerability in nfc sockets in the Linux Kernel before 5.12.4 allows local attackers to elevate their privileges. In typical configurations, the issue can only be triggered by a privileged local user with the CAP_NET_RAW …

▾ Twilightnetapp · cloud_backupEPSS 0.38%via NVD
CVE-2021-3501High· 7.1
5y ago

A flaw was found in the Linux kernel in versions before 5.12

A flaw was found in the Linux kernel in versions before 5.12. The value of internal.ndata, in the KVM API, is mapped to an array index, which can be updated by a user process at anytime which could lead to an out-of-bounds write. The hig…

▾ Twilightredhat · virtualizationEPSS 0.37%via NVD
CVE-2021-23133Medium· 6.7
5y ago

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process

A race condition in Linux kernel SCTP sockets (net/sctp/socket.c) before 5.12-rc8 can lead to kernel privilege escalation from the context of a network service or an unprivileged process. If sctp_destroy_sock is called without sock_net(s…

▾ Sunlitnetapp · cloud_backupEPSS 0.47%via NVD
CVE-2020-25649High· 7.5
5y ago

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly

A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.

▾ Twilightfasterxml · jackson-databindEPSS 18%via NVD
CVE-2020-8619Medium· 4.9
6y ago

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at le…

In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -> 9.14.12, BIND 9.16.0 -> 9.16.3, BIND Supported Preview Edition 9.11.14-S1 -> 9.11.19-S1: Unless a nameserver is providing authoritative service for one or more zones and at le…

▾ Sunlitisc · bindEPSS 2.1%via NVD
CVE-2020-9484High· 7.0PoC
6y ago

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…

When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use…

▾ Midnightapache · tomcatEPSS 57%via NVD
CVE-2020-9281Medium· 6.1
6y ago

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

A cross-site scripting (XSS) vulnerability in the HTML Data Processor for CKEditor 4.0 before 4.14 allows remote attackers to inject arbitrary web script through a crafted "protected" comment (with the cke_protected syntax).

▾ Sunlitckeditor · ckeditorEPSS 4.3%via NVD
CVE-2020-1938Critical· 9.8CISA KEVPoC
6y ago

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat

When using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections ar…

▾ Hadalapache · geodeEPSS 99%via NVD
CVE-2011-4088High· 7.5
6y ago

ABRT might allow attackers to obtain sensitive information from crash reports.

ABRT might allow attackers to obtain sensitive information from crash reports.

▾ Twilightredhat · automatic_bug_reporting_toolEPSS 1.6%via NVD
fedora vulnerabilities (CVEs) — page 3 · VulnSea