Fedoraproject
Fedoraproject Fedora: vulnerabilidades y CVE
Fedoraproject Fedora tiene 5359 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 493 son críticas y 86 figuran en el catálogo de explotación activa de CISA.
CVE5359
Últimos 12 meses4
Críticas493
Explotadas activamente86
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-0995 | Alta (7.8) | 8.8% | ⚠ Explotación activa | 25 mar 2022 | An out-of-bounds (OOB) memory write flaw was found in the Linux kernel’s watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged… |
| CVE-2022-0492 | Alta (7.8) | 5.5% | ⚠ Explotación activa | 3 mar 2022 | A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to… |
| CVE-2021-30952 | Alta (7.8) | 7.0% | ⚠ Explotación activa | 24 ago 2021 | An integer overflow was addressed with improved input validation. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may… |
| CVE-2019-5418 | Alta (7.5) | 99% | ⚠ Explotación activa | 27 mar 2019 | There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where specially crafted accept headers can cause contents of arbitrary files on the target system's… |
| CVE-2020-11023 | Media (6.1) | 85% | ⚠ Explotación activa | 29 abr 2020 | In jQuery versions greater than or equal to 1.0.3 and before 3.5.0, passing HTML containing <option> elements from untrusted sources - even after sanitizing it - to one of jQuery's DOM manipulation methods (i.e.… |
| CVE-2020-13965 | Media (6.1) | 77% | ⚠ Explotación activa | 9 jun 2020 | An issue was discovered in Roundcube Webmail before 1.3.12 and 1.4.x before 1.4.5. There is XSS via a malicious XML attachment because text/xml is among the allowed types for a preview. |
| CVE-2024-4577 | Crítica (9.8) | 100% | ⚠ Explotación activa | 9 jun 2024 | In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace… |
| CVE-2024-1086 | Alta (7.8) | 28% | ⚠ Explotación activa | 31 ene 2024 | A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. The nft_verdict_init() function allows positive values as drop error within the… |
| CVE-2024-5274 | Crítica (9.6) | 7.5% | ⚠ Explotación activa | 28 may 2024 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.112 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-4947 | Crítica (9.6) | 15% | ⚠ Explotación activa | 15 may 2024 | Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-4761 | Alta (8.8) | 11% | ⚠ Explotación activa | 14 may 2024 | Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-4671 | Crítica (9.6) | 8.3% | ⚠ Explotación activa | 14 may 2024 | Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security… |
| CVE-2023-4762 | Alta (8.8) | 41% | ⚠ Explotación activa | 5 sept 2023 | Type Confusion in V8 in Google Chrome prior to 116.0.5845.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-0519 | Alta (8.8) | 3.8% | ⚠ Explotación activa | 16 ene 2024 | Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2023-7101 | Alta (7.8) | 19% | ⚠ Explotación activa | 24 dic 2023 | Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file… |
| CVE-2023-7024 | Alta (8.8) | 6.7% | ⚠ Explotación activa | 21 dic 2023 | Heap buffer overflow in WebRTC in Google Chrome prior to 120.0.6099.129 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2023-42917 | Alta (8.8) | 9.3% | ⚠ Explotación activa | 30 nov 2023 | A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may lead to arbitrary code… |
| CVE-2023-42916 | Media (6.5) | 18% | ⚠ Explotación activa | 30 nov 2023 | An out-of-bounds read was addressed with improved input validation. This issue is fixed in iOS 17.1.2 and iPadOS 17.1.2, macOS Sonoma 14.1.2, Safari 17.1.2. Processing web content may disclose sensitive information.… |
| CVE-2023-6345 | Crítica (9.6) | 16% | ⚠ Explotación activa | 29 nov 2023 | Integer overflow in Skia in Google Chrome prior to 119.0.6045.199 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security… |
| CVE-2023-4911 | Alta (7.8) | 81% | ⚠ Explotación activa | 3 oct 2023 | A buffer overflow was discovered in the GNU C Library's dynamic loader ld.so while processing the GLIBC_TUNABLES environment variable. This issue could allow a local attacker to use maliciously crafted GLIBC_TUNABLES… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-54231 | Media (5.5) | 0.19% | — | 13 jun 2026 | A content injection vulnerability was found in the ABRT post-create event handler scripts in libreport. The event script queries the systemd journal for log entries matching the crashed process and writes the results to… |
| CVE-2026-54230 | Alta (7.8) | 0.23% | — | 13 jun 2026 | A symlink following vulnerability was found in the ABRT post-create event handler scripts in libreport. Event scripts write output files using shell redirections without the O_NOFOLLOW flag. If the target file is… |
| CVE-2026-35094 | Media (5.5) | 0.17% | — | 1 abr 2026 | A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is… |
| CVE-2026-35093 | Alta (8.8) | 0.21% | — | 1 abr 2026 | A flaw was found in libinput. A local attacker who can place a specially crafted Lua bytecode file in certain system or user configuration directories can bypass security restrictions. This allows the attacker to run… |
| CVE-2023-4134 | Media (5.5) | 0.20% | — | 14 nov 2024 | A use-after-free vulnerability was found in the cyttsp4_core driver in the Linux kernel. This issue occurs in the device cleanup routine due to a possible rearming of the watchdog_timer from the workqueue. This could… |
| CVE-2024-3056 | Media (4.8) | 0.55% | — | 2 ago 2024 | A flaw was found in Podman. This issue may allow an attacker to create a specially crafted container that, when configured to share the same IPC with at least one other container, can create a large number of IPC… |
| CVE-2024-6293 | Alta (8.8) | 0.62% | — | 24 jun 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-6292 | Alta (8.8) | 0.61% | — | 24 jun 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-6291 | Alta (8.8) | 0.66% | — | 24 jun 2024 | Use after free in Swiftshader in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-6290 | Alta (8.8) | 0.62% | — | 24 jun 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.126 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-38277 | Media (5.4) | 0.24% | — | 18 jun 2024 | A unique key should be generated for a user's QR login key and their auto-login key, so the same key cannot be used interchangeably between the two. |
| CVE-2024-38276 | Alta (8.8) | 0.46% | — | 18 jun 2024 | Incorrect CSRF token checks resulted in multiple CSRF risks. |
| CVE-2024-38274 | Media (6.1) | 0.37% | — | 18 jun 2024 | Insufficient escaping of calendar event titles resulted in a stored XSS risk in the event deletion prompt. |
| CVE-2024-38273 | Media (5.4) | 0.43% | — | 18 jun 2024 | Insufficient capability checks meant it was possible for users to gain access to BigBlueButton join URLs they did not have permission to access. |
| CVE-2024-5847 | Alta (8.8) | 0.47% | — | 11 jun 2024 | Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) |
| CVE-2024-5846 | Alta (8.8) | 0.47% | — | 11 jun 2024 | Use after free in PDFium in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) |
| CVE-2024-5845 | Alta (8.8) | 0.46% | — | 11 jun 2024 | Use after free in Audio in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: Medium) |
| CVE-2024-5844 | Alta (8.8) | 0.54% | — | 11 jun 2024 | Heap buffer overflow in Tab Strip in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2024-5843 | Media (6.5) | 0.47% | — | 11 jun 2024 | Inappropriate implementation in Downloads in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to obfuscate security UI via a malicious file. (Chromium security severity: Medium) |
| CVE-2024-5842 | Alta (8.8) | 0.48% | — | 11 jun 2024 | Use after free in Browser UI in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform an out of bounds memory read via a crafted HTML page.… |
| CVE-2024-5841 | Alta (8.8) | 5.0% | — | 11 jun 2024 | Use after free in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2024-5840 | Media (6.5) | 0.41% | — | 11 jun 2024 | Policy bypass in CORS in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2024-5839 | Media (6.5) | 0.49% | — | 11 jun 2024 | Inappropriate Implementation in Memory Allocator in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium) |
| CVE-2024-5838 | Alta (8.8) | 0.52% | — | 11 jun 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-5837 | Alta (8.8) | 0.53% | — | 11 jun 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-5836 | Alta (8.8) | 0.50% | — | 11 jun 2024 | Inappropriate Implementation in DevTools in Google Chrome prior to 126.0.6478.54 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.… |
| CVE-2024-5835 | Alta (8.8) | 0.52% | — | 11 jun 2024 | Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page.… |
| CVE-2024-5834 | Alta (8.8) | 0.57% | — | 11 jun 2024 | Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-5833 | Alta (8.8) | 0.52% | — | 11 jun 2024 | Type Confusion in V8 in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High) |
| CVE-2024-5832 | Alta (8.8) | 0.48% | — | 11 jun 2024 | Use after free in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.