Vulnerabilities > Fedoraproject > Fedora > 39

DATE CVE VULNERABILITY TITLE RISK
2024-05-15 CVE-2024-4947 Type Confusion vulnerability in multiple products
Type Confusion in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
network
low complexity
google fedoraproject CWE-843
critical
9.6
2024-05-15 CVE-2024-4948 Use After Free vulnerability in multiple products
Use after free in Dawn in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-416
6.5
2024-05-15 CVE-2024-4949 Use After Free vulnerability in multiple products
Use after free in V8 in Google Chrome prior to 125.0.6422.60 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google fedoraproject CWE-416
6.5
2024-05-15 CVE-2024-4950 Improper Restriction of Rendered UI Layers or Frames vulnerability in multiple products
Inappropriate implementation in Downloads in Google Chrome prior to 125.0.6422.60 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page.
network
low complexity
google fedoraproject CWE-1021
6.5
2024-05-14 CVE-2024-4761 Out-of-bounds Write vulnerability in multiple products
Out of bounds write in V8 in Google Chrome prior to 124.0.6367.207 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
network
low complexity
google fedoraproject CWE-787
8.8
2024-05-14 CVE-2024-4854 Infinite Loop vulnerability in multiple products
MONGO and ZigBee TLV dissector infinite loops in Wireshark 4.2.0 to 4.2.4, 4.0.0 to 4.0.14, and 3.6.0 to 3.6.22 allow denial of service via packet injection or crafted capture file
network
low complexity
fedoraproject wireshark CWE-835
7.5
2024-05-14 CVE-2024-4671 Use After Free vulnerability in multiple products
Use after free in Visuals in Google Chrome prior to 124.0.6367.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
network
low complexity
google fedoraproject CWE-416
critical
9.6
2024-05-14 CVE-2024-34340 Incorrect Comparison vulnerability in multiple products
Cacti provides an operational monitoring and fault management framework.
network
low complexity
cacti fedoraproject CWE-697
critical
9.1
2024-05-14 CVE-2024-31443 Cross-site Scripting vulnerability in multiple products
Cacti provides an operational monitoring and fault management framework.
network
low complexity
cacti fedoraproject CWE-79
5.4
2024-05-14 CVE-2024-31444 Cross-site Scripting vulnerability in multiple products
Cacti provides an operational monitoring and fault management framework.
network
low complexity
cacti fedoraproject CWE-79
5.4