VYPR

Extra Packages For Enterprise Linux

by Fedoraproject

CVEs (50)

  • CVE-2023-4256MedDec 21, 2023
    risk 0.36cvss 5.5epss 0.00

    Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local…

  • CVE-2020-27842MedJan 5, 2021
    risk 0.36cvss 5.5epss 0.01

    There's a flaw in openjpeg's t2 encoder in versions prior to 2.4.0. An attacker who is able to provide crafted input to be processed by openjpeg could cause a null pointer dereference. The highest impact of this flaw is to application availability.

  • CVE-2023-51766MedDec 24, 2023
    risk 0.35cvss 5.3epss 0.01

    Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because…

  • CVE-2023-5550MedNov 9, 2023
    risk 0.35cvss 6.5epss 0.01

    In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.

  • CVE-2024-0232MedJan 16, 2024
    risk 0.31cvss 4.7epss 0.00

    A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a…

  • CVE-2023-38253MedJul 14, 2023
    risk 0.31cvss 4.7epss 0.00

    An out-of-bounds read flaw was found in w3m, in the growbuf_to_Str function in indep.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.

  • CVE-2023-38252MedJul 14, 2023
    risk 0.31cvss 4.7epss 0.00

    An out-of-bounds read flaw was found in w3m, in the Strnew_size function in Str.c. This issue may allow an attacker to cause a denial of service through a crafted HTML file.

  • CVE-2023-1289MedMar 23, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was discovered in ImageMagick where a specially created SVG file loads itself and causes a segmentation fault. This flaw allows a remote attacker to pass a specially crafted SVG file that leads to a segmentation fault, generating many trash files in "/tmp,"…

  • CVE-2022-40316MedSep 30, 2022
    risk 0.28cvss 4.3epss 0.01

    The H5P activity attempts report did not filter by groups, which in separate groups mode could reveal information to non-editing teachers about attempts/users in groups they should not have access to.

  • CVE-2023-5540MedNov 9, 2023
    risk 0.24cvss 4.7epss 0.02

    A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

  • CVE-2023-5539MedNov 9, 2023
    risk 0.24cvss 4.7epss 0.02

    A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.

  • CVE-2020-27818LowDec 8, 2020
    risk 0.22cvss 3.3epss 0.01

    A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.

  • CVE-2023-5551LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Separate Groups mode restrictions were not honoured in the forum summary report, which would display users from other groups.

  • CVE-2023-5549LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    Insufficient web service capability checks made it possible to move categories a user had permission to manage, to a parent category they did not have the capability to manage.

  • CVE-2023-5545LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.01

    H5P metadata automatically populated the author with the user's username, which could be sensitive information.

  • CVE-2023-5542LowNov 9, 2023
    risk 0.14cvss 3.3epss 0.00

    Students in "Only see own membership" groups could see other students in the group, which should be hidden.

  • CVE-2023-4255MedDec 21, 2023
    risk 0.00cvss 5.5epss 0.00

    An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to…

  • CVE-2023-5341MedNov 19, 2023
    risk 0.00cvss 6.2epss 0.00

    A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.

  • CVE-2023-5543LowNov 9, 2023
    risk 0.00cvss 3.3epss 0.00

    When duplicating a BigBlueButton activity, the original meeting ID was also duplicated instead of using a new ID for the new activity. This could provide unintended access to the original meeting.

  • CVE-2023-34475MedJun 16, 2023
    risk 0.00cvss 5.5epss 0.00

    A heap use after free issue was discovered in ImageMagick's ReplaceXmpValue() function in MagickCore/profile.c. An attacker could trick user to open a specially crafted file to convert, triggering an heap-use-after-free write error, allowing an application to crash, resulting in…