Skip to main content

Vendor archive

fedoraproject CVEs

Beta · best-effort

5,417 CVEs tagged to vendor fedoraproject472 Critical, 2,338 High, 2,343 Medium, 264 Low, 0 Unrated.

CVE-2024-24568

Published Feb 26, 2024

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get b…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-23839

Published Feb 26, 2024

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap u…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23837

Published Feb 26, 2024

LibHTP is a security-aware parser for the HTTP protocol. Crafted traffic can cause excessive processing time of HTTP headers, leading to denial of service. This issue is addressed…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-23836

Published Feb 26, 2024

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to versions 6.0.16 and 7.0.3, an attacker can craft tra…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27318

Published Feb 23, 2024

Versions of the package onnx before and including 1.15.0 are vulnerable to Directory Traversal as the external_data field of the tensor proto can have a path to the file which is…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-25629

Published Feb 23, 2024

c-ares is a C library for asynchronous DNS requests. `ares__read_line()` is used to parse local configuration files such as `/etc/resolv.conf`, `/etc/nsswitch.conf`, the `HOSTALIA…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-24479

Published Feb 21, 2024

A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-24476

Published Feb 21, 2024

A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1676

Published Feb 21, 2024

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security sever…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1675

Published Feb 21, 2024

Insufficient policy enforcement in Download in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass filesystem restrictions via a crafted HTML page. (Chromium…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1674

Published Feb 21, 2024

Inappropriate implementation in Navigation in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1673

Published Feb 21, 2024

Use after free in Accessibility in Google Chrome prior to 122.0.6261.57 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption v…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1672

Published Feb 21, 2024

Inappropriate implementation in Content Security Policy in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to bypass content security policy via a crafted HTML page…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-1670

Published Feb 21, 2024

Use after free in Mojo in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-1669

Published Feb 21, 2024

Out of bounds memory access in Blink in Google Chrome prior to 122.0.6261.57 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium se…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 251-275 of 5,417 CVEsPage 11 of 217