Skip to main content

Vendor archive

fedoraproject CVEs

Beta · best-effort

5,417 CVEs tagged to vendor fedoraproject472 Critical, 2,338 High, 2,343 Medium, 264 Low, 0 Unrated.

CVE-2023-49528

Published Apr 12, 2024

Buffer Overflow vulnerability in FFmpeg version n6.1-3-g466799d4f5, allows a local attacker to execute arbitrary code and cause a denial of service (DoS) via the af_dialoguenhance…

CVSS 8.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3516

Published Apr 10, 2024

Heap buffer overflow in ANGLE in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-3515

Published Apr 10, 2024

Use after free in Dawn in Google Chrome prior to 123.0.6312.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severi…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-3157

Published Apr 10, 2024

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox…

CVSS 9.6 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-2794

Published Apr 10, 2024

A flaw was found in ofono, an Open Source Telephony on Linux. A stack overflow bug is triggered within the decode_deliver() function during the SMS decoding. It is assumed that th…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-3116

Published Apr 4, 2024

pgAdmin <= 8.4 is affected by a Remote Code Execution (RCE) vulnerability through the validate binary path API. This vulnerability allows attackers to execute arbitrary code on t…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2024-30261

Published Apr 4, 2024

Undici is an HTTP/1.1 client, written from scratch for Node.js. An attacker can alter the `integrity` option passed to `fetch()`, allowing `fetch()` to accept requests as valid ev…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-3209

Published Apr 2, 2024

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buff…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 176-200 of 5,417 CVEsPage 8 of 217