VYPR

Extra Packages For Enterprise Linux

by Fedoraproject

CVEs (76)

  • CVE-2022-2294HigKEVJul 28, 2022
    risk 0.81cvss 8.8epss 0.70

    Heap buffer overflow in WebRTC in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2023-34152CriMay 30, 2023
    risk 0.64cvss 9.8epss 0.08

    A vulnerability was found in ImageMagick. This security flaw cause a remote code execution vulnerability in OpenBlob with --enable-pipes configured.

  • CVE-2022-4170CriDec 9, 2022
    risk 0.64cvss 9.8epss 0.02

    The rxvt-unicode package is vulnerable to a remote code execution, in the Perl background extension, when an attacker can control the data written to the user's terminal and certain options are set.

  • CVE-2022-40315CriSep 30, 2022
    risk 0.64cvss 9.8epss 0.01

    A limited SQL injection risk was identified in the "browse list of users" site administration page.

  • CVE-2021-45079CriJan 31, 2022
    risk 0.59cvss 9.1epss 0.03

    In strongSwan before 5.9.5, a malicious responder can send an EAP-Success message too early without actually authenticating the client and (in the case of EAP methods with mutual authentication and EAP-only authentication for IKEv2) even without server authentication.

  • CVE-2022-2296HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Chrome OS Shell in Google Chrome on Chrome OS prior to 103.0.5060.114 allowed a remote attacker who convinced a user to engage in specific user interactions to potentially exploit heap corruption via direct UI interactions.

  • CVE-2022-2295HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 103.0.5060.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2163HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Cast UI and Toolbar in Google Chrome prior to 103.0.5060.134 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via UI interaction.

  • CVE-2022-2158HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21897HigSep 8, 2021
    risk 0.57cvss 8.8epss 0.03

    A code execution vulnerability exists in the DL_Dxf::handleLWPolylineData functionality of Ribbonsoft dxflib 3.17.0. A specially-crafted .dxf file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

  • CVE-2021-38714HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.03

    In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

  • CVE-2023-34432HigJul 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A heap buffer overflow vulnerability was found in sox, in the lsx_readbuf function at sox/src/formats_i.c:98:16. This flaw can lead to a denial of service, code execution, or information disclosure.

  • CVE-2023-34318HigJul 10, 2023
    risk 0.51cvss 7.8epss 0.00

    A heap buffer overflow vulnerability was found in sox, in the startread function at sox/src/hcom.c:160:41. This flaw can lead to a denial of service, code execution, or information disclosure.

  • CVE-2023-34153HigMay 30, 2023
    risk 0.51cvss 7.8epss 0.03

    A vulnerability was found in ImageMagick. This security flaw causes a shell command injection vulnerability via video:vsync or video:pixel-format options in VIDEO encoding/decoding.

  • CVE-2022-0546HigFeb 24, 2022
    risk 0.51cvss 7.8epss 0.01

    A missing bounds check in the image loader used in Blender 3.x and 2.93.8 leads to out-of-bounds heap access, allowing an attacker to cause denial of service, memory corruption or potentially code execution.

  • CVE-2022-0983HigMar 25, 2022
    risk 0.50cvss 8.8epss 0.01

    An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

  • CVE-2021-43559HigNov 22, 2021
    risk 0.50cvss 8.8epss 0.01

    A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

  • CVE-2022-28327HigApr 20, 2022
    risk 0.49cvss 7.5epss 0.04

    The generic P-256 feature in crypto/elliptic in Go before 1.17.9 and 1.18.x before 1.18.1 allows a panic via long scalar input.

  • CVE-2022-27191HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.04

    The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

  • CVE-2022-0725HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.

Page 1 of 4