VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2016-2312MedDec 23, 2016
    risk 0.44cvss 6.8epss 0.00

    Turning all screens off in Plasma-workspace and kscreenlocker while the lock screen is shown can result in the screen being unlocked when turning a screen on again.

  • CVE-2016-3096HigJun 3, 2016
    risk 0.44cvss 7.8epss 0.00

    The create_script function in the lxc_container module in Ansible before 1.9.6-1 and 2.x before 2.0.2.0 allows local users to write to arbitrary files or gain privileges via a symlink attack on (1) /opt/.lxc-attach-script, (2) the archived container in the archive_path…

  • CVE-2016-2270MedFeb 19, 2016
    risk 0.44cvss 6.8epss 0.01

    Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.

  • CVE-2023-46842MedMay 16, 2024
    risk 0.43cvss 6.5epss 0.09

    Unlike 32-bit PV guests, HVM guests may switch freely between 64-bit and other modes. This in particular means that they may set registers used to pass 32-bit-mode hypercall arguments to values outside of the range 32-bit code would be able to set them to. When processing of…

  • CVE-2023-1073MedMar 27, 2023
    risk 0.43cvss 6.6epss 0.00

    A memory corruption flaw was found in the Linux kernel’s human interface device (HID) subsystem in how a user inserts a malicious USB device. This flaw allows a local user to crash or potentially escalate their privileges on the system.

  • CVE-2022-3437MedJan 12, 2023
    risk 0.43cvss 6.5epss 0.04

    A heap-based buffer overflow vulnerability was found in Samba within the GSSAPI unwrap_des() and unwrap_des3() routines of Heimdal. The DES and Triple-DES decryption routines in the Heimdal GSSAPI library allow a length-limited write buffer overflow on malloc() allocated memory…

  • CVE-2022-35957MedSep 20, 2022
    risk 0.43cvss 6.6epss 0.01

    Grafana is an open-source platform for monitoring and observability. Versions prior to 9.1.6 and 8.5.13 are vulnerable to an escalation from admin to server admin when auth proxy is used, allowing an admin to take over the server admin account and gain full control of the…

  • CVE-2022-29900MedJul 12, 2022
    risk 0.43cvss 6.5epss 0.04

    Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

  • CVE-2022-27776MedJun 2, 2022
    risk 0.43cvss 6.5epss 0.04

    A insufficiently protected credentials vulnerability in fixed in curl 7.83.0 might leak authentication or cookie header data on HTTP redirects to the same host but another port number.

  • CVE-2022-1015MedApr 29, 2022
    risk 0.43cvss 6.6epss 0.01

    A flaw was found in the Linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem. This flaw allows a local user to cause an out-of-bounds write issue.

  • CVE-2022-24713HigMar 8, 2022
    risk 0.43cvss 7.5epss 0.14

    regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide…

  • CVE-2022-23134LowKEVJan 13, 2022
    risk 0.43cvss 3.7epss 0.85

    After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

  • CVE-2021-41183MedOct 26, 2021
    risk 0.43cvss 6.5epss 0.09

    jQuery-UI is the official jQuery user interface library. Prior to version 1.13.0, accepting the value of various `*Text` options of the Datepicker widget from untrusted sources may execute untrusted code. The issue is fixed in jQuery UI 1.13.0. The values passed to various…

  • CVE-2021-30621MedSep 3, 2021
    risk 0.43cvss 6.5epss 0.03

    Chromium: CVE-2021-30621 UI Spoofing in Autofill

  • CVE-2021-30619MedSep 3, 2021
    risk 0.43cvss 6.5epss 0.03

    Chromium: CVE-2021-30619 UI Spoofing in Autofill

  • CVE-2021-30617MedSep 3, 2021
    risk 0.43cvss 6.5epss 0.04

    Chromium: CVE-2021-30617 Policy bypass in Blink

  • CVE-2021-30615MedSep 3, 2021
    risk 0.43cvss 6.5epss 0.06

    Chromium: CVE-2021-30615 Cross-origin data leak in Navigation

  • CVE-2021-3634MedAug 31, 2021
    risk 0.43cvss 6.5epss 0.05

    A flaw has been found in libssh in versions prior to 0.9.6. The SSH protocol keeps track of two shared secrets during the lifetime of the session. One of them is called secret_hash and the other session_id. Initially, both of them are the same, but after key re-exchange,…

  • CVE-2021-39140MedAug 23, 2021
    risk 0.43cvss 6.5epss 0.06

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to allocate 100% CPU time on the target system depending on CPU type or parallel execution of such a payload resulting in a denial of…

  • CVE-2021-30582MedAug 3, 2021
    risk 0.43cvss 6.5epss 0.05

    Inappropriate implementation in Animation in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

Page 108 of 268