VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2020-14344MedAug 5, 2020
    risk 0.44cvss 6.7epss 0.00

    An integer overflow leading to a heap-buffer overflow was found in The X Input Method (XIM) client was implemented in libX11 before version 1.6.10. As per upstream this is security relevant when setuid programs call XIM client functions while running with elevated privileges. No…

  • CVE-2020-9498MedJul 2, 2020
    risk 0.44cvss 6.7epss 0.01

    Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing…

  • CVE-2020-10379HigJun 25, 2020
    risk 0.44cvss 7.8epss 0.01

    In Pillow before 7.1.0, there are two Buffer Overflows in libImaging/TiffDecode.c.

  • CVE-2020-13776MedJun 3, 2020
    risk 0.44cvss 6.7epss 0.00

    systemd through v245 mishandles numerical usernames such as ones composed of decimal digits or 0x followed by hex digits, as demonstrated by use of root privileges when privileges of the 0x0 user account were intended. NOTE: this issue exists because of an incomplete fix for…

  • CVE-2020-11077MedMay 22, 2020
    risk 0.44cvss 6.8epss 0.03

    In Puma (RubyGem) before 4.3.5 and 3.12.6, a client could smuggle a request through a proxy, causing the proxy to send a response back to another unknown client. If the proxy uses persistent connections and the client adds another request in via HTTP pipelining, the proxy may…

  • CVE-2020-1927MedApr 2, 2020
    risk 0.44cvss 6.1epss 0.57

    In Apache HTTP Server 2.4.0 to 2.4.41, redirects configured with mod_rewrite that were intended to be self-referential might be fooled by encoded newlines and redirect instead to an an unexpected URL within the request URL.

  • CVE-2020-10684HigMar 24, 2020
    risk 0.44cvss 7.9epss 0.00

    A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker…

  • CVE-2019-19769MedDec 12, 2019
    risk 0.44cvss 6.7epss 0.01

    In the Linux kernel 5.3.10, there is a use-after-free (read) in the perf_trace_lock_acquire function (related to include/trace/events/lock.h).

  • CVE-2019-19579MedDec 4, 2019
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device (and assignable-add is not used), because of an incomplete fix for CVE-2019-18424. XSA-302 relies on the…

  • CVE-2013-4251HigNov 4, 2019
    risk 0.44cvss 7.8epss 0.00

    The scipy.weave component in SciPy before 0.12.1 creates insecure temporary directories.

  • CVE-2019-18424MedOct 31, 2019
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered in Xen through 4.12.x allowing attackers to gain host OS privileges via DMA in a situation where an untrusted domain has access to a physical device. This occurs because passed through PCI devices may corrupt host memory after deassignment. When a PCI…

  • CVE-2019-18218HigOct 21, 2019
    risk 0.44cvss 7.8epss 0.02

    cdf_read_property_info in cdf.c in file through 5.37 does not restrict the number of CDF_VECTOR elements, which allows a heap-based buffer overflow (4-byte out-of-bounds write).

  • CVE-2019-9854HigSep 6, 2019
    risk 0.44cvss 7.8epss 0.02

    LibreOffice has a feature where documents can specify that pre-installed macros can be executed on various script events such as mouse-over, document-open etc. Access is intended to be restricted to scripts under the share/Scripts/python, user/Scripts/python sub-directories of…

  • CVE-2019-3839HigMay 16, 2019
    risk 0.44cvss 7.8epss 0.02

    It was found that in ghostscript some privileged operators remained accessible from various places after the CVE-2019-6116 fix. A specially crafted PostScript file could use this flaw in order to, for example, have access to the file system outside of the constrains imposed by…

  • CVE-2019-7221HigMar 21, 2019
    risk 0.44cvss 7.8epss 0.01

    The KVM implementation in the Linux kernel through 4.20.5 has a Use-after-Free.

  • CVE-2019-8379HigFeb 17, 2019
    risk 0.44cvss 7.8epss 0.01

    An issue was discovered in AdvanceCOMP through 2.1. A NULL pointer dereference exists in the function be_uint32_read() located in endianrw.h. It can be triggered by sending a crafted file to a binary. It allows an attacker to cause a Denial of Service (Segmentation fault) or…

  • CVE-2014-7272HigMar 8, 2018
    risk 0.44cvss 7.8epss 0.00

    Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to gain root privileges because code running as root performs write operations within a user home directory, and this user may have created links in advance (exploitation requires the user to win a race…

  • CVE-2014-7271HigMar 8, 2018
    risk 0.44cvss 7.8epss 0.00

    Simple Desktop Display Manager (SDDM) before 0.10.0 allows local users to log in as user "sddm" without authentication.

  • CVE-2014-3219HigFeb 9, 2018
    risk 0.44cvss 7.8epss 0.00

    fish before 2.1.1 allows local users to write to arbitrary files via a symlink attack on (1) /tmp/fishd.log.%s, (2) /tmp/.pac-cache.$USER, (3) /tmp/.yum-cache.$USER, or (4) /tmp/.rpm-cache.$USER.

  • CVE-2014-9114HigMar 31, 2017
    risk 0.44cvss 7.8epss 0.01

    Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.

Page 107 of 268