Fedora / Fedora
56 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-19816 | PackageKit: dnf5 backend ignores SIMULATE on RepoRemove | HIGH | 7.1 | Sep 14, 2026 |
| CVE-2026-19624 | NetworkManager-l2tp: local privilege escalation via ipsec.conf injection | HIGH | 7.8 | Sep 14, 2026 |
| CVE-2023-4235 | Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_deliver_report() function | HIGH | 8.1 | Apr 17, 2024 |
| CVE-2023-4234 | Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_submit_report() function | HIGH | 8.1 | Apr 17, 2024 |
| CVE-2023-4233 | Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the sms_decode_address_field() function | HIGH | 8.1 | Apr 17, 2024 |
| CVE-2023-4232 | Ofono: sms decoder stack-based buffer overflow remote code execution vulnerability within the decode_status_report() function | HIGH | 8.1 | Apr 17, 2024 |
| CVE-2023-3966 | Openvswsitch: ovs-vswitch fails to recover after malformed geneve metadata packet | HIGH | 7.5 | Feb 22, 2024 |
| CVE-2024-1312 | Kernel: race condition leads to use after free during vma lock in lock_vma_under_rcu | MEDIUM | 5.1 | Feb 8, 2024 |
| CVE-2023-6780 | Glibc: integer overflow in __vsyslog_internal() | MEDIUM | 5.3 | Jan 31, 2024 |
| CVE-2023-6779 | Glibc: off-by-one heap-based buffer overflow in __vsyslog_internal() | HIGH | 8.2 | Jan 31, 2024 |
| CVE-2023-6246 | Glibc: heap-based buffer overflow in __vsyslog_internal() | HIGH | 8.4 | Jan 31, 2024 |
| CVE-2023-6258 | Pkcs11-provider: side-channel proofing pkcs#1 1.5 paths | HIGH | 8.1 | Jan 30, 2024 |
| CVE-2023-6200 | Kernel: icmpv6 router advertisement packets, aka linux tcp/ip remote code execution vulnerability | HIGH | 7.5 | Jan 28, 2024 |
| CVE-2023-6395 | Mock: privilege escalation for users that can access mock configuration | CRITICAL | 9.8 | Jan 16, 2024 |
| CVE-2023-4255 | W3m: out-of-bounds write in function checktype() in etc.c (incomplete fix for cve-2022-38223) | MEDIUM | 5.5 | Dec 21, 2023 |
| CVE-2023-4256 | Tcpreplay: tcprewrite: double free in tcpedit_dlt_cleanup() in plugins/dlt_plugins.c | MEDIUM | 5.5 | Dec 21, 2023 |
| CVE-2023-3430 | Openimageio: heap-buffer-overflow in file src/gif.imageio/gifinput.cpp | HIGH | 7.5 | Dec 18, 2023 |
| CVE-2023-6560 | Kernel: io_uring out of boundary memory access in __io_uaddr_map() | MEDIUM | 5.5 | Dec 8, 2023 |
| CVE-2023-5972 | Kernel: the nfta_inner_num and nfta_expr_name netlink attributes accessed without checking its presence in nft_inner.c | HIGH | 7.8 | Nov 23, 2023 |
| CVE-2023-6238 | Kernel: nvme: memory corruption via unprivileged user passthrough | MEDIUM | 6.7 | Nov 21, 2023 |
| CVE-2023-4154 | Samba: ad dc password exposure to privileged users and rodcs | HIGH | 7.5 | Nov 7, 2023 |
| CVE-2023-1194 | Use-after-free in parse_lease_state() | HIGH | 8.1 | Nov 3, 2023 |
| CVE-2022-4900 | Potential buffer overflow in php_cli_server_startup_workers | MEDIUM | 6.2 | Nov 2, 2023 |
| CVE-2023-38473 | Reachable assertion in avahi_alternative_host_name | MEDIUM | 6.2 | Nov 2, 2023 |
| CVE-2023-38472 | Reachable assertion in avahi_rdata_parse | MEDIUM | 6.2 | Nov 2, 2023 |
Showing 1 to 25 of 56 CVEs