Vulnerabilities > Fedoraproject > High

DATE CVE VULNERABILITY TITLE RISK
2023-07-11 CVE-2023-33170 Race Condition vulnerability in multiple products
ASP.NET and Visual Studio Security Feature Bypass Vulnerability
network
high complexity
microsoft fedoraproject CWE-362
8.1
2023-07-11 CVE-2023-36824 Incorrect Calculation of Buffer Size vulnerability in multiple products
Redis is an in-memory database that persists on disk.
network
low complexity
redis fedoraproject CWE-131
8.8
2023-07-11 CVE-2023-3354 NULL Pointer Dereference vulnerability in multiple products
A flaw was found in the QEMU built-in VNC server.
network
low complexity
qemu redhat fedoraproject CWE-476
7.5
2023-07-11 CVE-2023-3269 Use After Free vulnerability in multiple products
A vulnerability exists in the memory management subsystem of the Linux kernel.
local
low complexity
linux redhat fedoraproject CWE-416
7.8
2023-07-10 CVE-2023-34432 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16.
7.8
2023-07-10 CVE-2023-34318 Out-of-bounds Write vulnerability in multiple products
A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41.
local
low complexity
sox-project redhat fedoraproject CWE-787
7.8
2023-07-06 CVE-2023-35934 Information Exposure vulnerability in multiple products
yt-dlp is a command-line program to download videos from video sites.
8.2
2023-07-05 CVE-2023-31248 Use After Free vulnerability in multiple products
Linux Kernel nftables Use-After-Free Local Privilege Escalation Vulnerability; `nft_chain_lookup_byid()` failed to check whether a chain was active and CAP_NET_ADMIN is in any user or network namespace
local
low complexity
linux fedoraproject debian canonical CWE-416
7.8
2023-07-05 CVE-2023-35001 Out-of-bounds Write vulnerability in multiple products
Linux Kernel nftables Out-Of-Bounds Read/Write Vulnerability; nft_byteorder poorly handled vm register contents when CAP_NET_ADMIN is in any user or network namespace
local
low complexity
linux debian fedoraproject netapp CWE-787
7.8
2023-07-03 CVE-2023-36053 In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.
network
low complexity
djangoproject debian fedoraproject
7.5