VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2023-29408MedAug 2, 2023
    risk 0.42cvss 6.5epss 0.01

    The TIFF decoder does not place a limit on the size of compressed tile data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height, and encoded size) to make the decoder decode large amounts of compressed data, consuming…

  • CVE-2023-29407MedAug 2, 2023
    risk 0.42cvss 6.5epss 0.01

    A maliciously-crafted image can cause excessive CPU consumption in decoding. A tiled image with a height of 0 and a very large width can cause excessive CPU consumption, despite the image size (width * height) appearing to be zero.

  • CVE-2022-4926MedJul 29, 2023
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Intents in Google Chrome on Android prior to 109.0.5414.119 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-37920HigJul 25, 2023
    risk 0.42cvss 7.5epss 0.01

    Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi prior to version 2023.07.22 recognizes "e-Tugra" root certificates. e-Tugra's root certificates were subject to an…

  • CVE-2023-38200HigJul 24, 2023
    risk 0.42cvss 7.5epss 0.01

    A flaw was found in Keylime. Due to their blocking nature, the Keylime registrar is subject to a remote denial of service against its SSL connections. This flaw allows an attacker to exhaust all available connections.

  • CVE-2023-36053HigJul 3, 2023
    risk 0.42cvss 7.5epss 0.03

    In Django 3.2 before 3.2.20, 4 before 4.1.10, and 4.2 before 4.2.3, EmailValidator and URLValidator are subject to a potential ReDoS (regular expression denial of service) attack via a very large number of domain name labels of emails and URLs.

  • CVE-2023-30589HigJul 1, 2023
    risk 0.42cvss 7.5epss 0.04

    The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to…

  • CVE-2023-30631HigJun 14, 2023
    risk 0.42cvss 7.5epss 0.02

    Improper Input Validation vulnerability in Apache Software Foundation Apache Traffic Server.  The configuration option proxy.config.http.push_method_enabled didn't function.  However, by default the PUSH method is blocked in the ip_allow configuration file.This issue affects…

  • CVE-2023-34969MedJun 8, 2023
    risk 0.42cvss 6.5epss 0.01

    D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to…

  • CVE-2023-33460MedJun 6, 2023
    risk 0.42cvss 6.5epss 0.01

    There's a memory leak in yajl 2.1.0 with use of yajl_tree_parse function. which will cause out-of-memory in server and cause crash.

  • CVE-2023-2283MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.01

    A vulnerability was found in libssh, where the authentication check of the connecting client can be bypassed in the`pki_verify_data_signature` function in memory allocation problems. This issue may happen if there is insufficient memory or the memory usage is limited. The…

  • CVE-2023-1667MedMay 26, 2023
    risk 0.42cvss 6.5epss 0.01

    A NULL pointer dereference was found In libssh during re-keying with algorithm guessing. This issue may allow an authenticated client to cause a denial of service.

  • CVE-2023-1729MedMay 15, 2023
    risk 0.42cvss 6.5epss 0.01

    A flaw was found in LibRaw. A heap-buffer-overflow in raw2image_ex() caused by a maliciously crafted file may lead to an application crash.

  • CVE-2023-2459MedMay 3, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in Prompts in Google Chrome prior to 113.0.5672.63 allowed a remote attacker to bypass permission restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-29530HigApr 24, 2023
    risk 0.42cvss 7.5epss 0.01

    Laminas Diactoros provides PSR HTTP Message implementations. In versions 2.18.0 and prior, 2.19.0, 2.20.0, 2.21.0, 2.22.0, 2.23.0, 2.24.0, and 2.25.0, users who create HTTP requests or responses using laminas/laminas-diactoros, when providing a newline at the start or end of a…

  • CVE-2023-21946MedApr 18, 2023
    risk 0.42cvss 6.5epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL…

  • CVE-2023-0004MedApr 12, 2023
    risk 0.42cvss 6.5epss 0.01

    A local file deletion vulnerability in Palo Alto Networks PAN-OS software enables an authenticated administrator to delete files from the local file system with elevated privileges. These files can include logs and system components that impact the integrity and availability of…

  • CVE-2023-1823MedApr 4, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in FedCM in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-1822MedApr 4, 2023
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in Navigation in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-1821MedApr 4, 2023
    risk 0.42cvss 6.5epss 0.01

    Inappropriate implementation in WebShare in Google Chrome prior to 112.0.5615.49 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)

Page 114 of 268