VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-1632MedSep 1, 2022
    risk 0.42cvss 6.5epss 0.00

    An Improper Certificate Validation attack was found in Openshift. A re-encrypt Route with destinationCACertificate explicitly set to the default serviceCA skips internal Service TLS certificate validation. This flaw allows an attacker to exploit an invalid certificate, resulting…

  • CVE-2021-3826MedSep 1, 2022
    risk 0.42cvss 6.5epss 0.01

    Heap/stack buffer overflow in the dlang_lname function in d-demangle.c in libiberty allows attackers to potentially cause a denial of service (segmentation fault and crash) via a crafted mangled symbol.

  • CVE-2021-35937MedAug 25, 2022
    risk 0.42cvss 6.4epss 0.00

    A race condition vulnerability was found in rpm. A local unprivileged user could use this flaw to bypass the checks that were introduced in response to CVE-2017-7500 and CVE-2017-7501, potentially gaining root privileges. The highest threat from this vulnerability is to data…

  • CVE-2022-37428MedAug 23, 2022
    risk 0.42cvss 6.5epss 0.01

    PowerDNS Recursor up to and including 4.5.9, 4.6.2 and 4.7.1, when protobuf logging is enabled, has Improper Cleanup upon a Thrown Exception, leading to a denial of service (daemon crash) via a DNS query that leads to an answer with specific properties.

  • CVE-2022-2622MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient validation of untrusted input in Safe Browsing in Google Chrome on Windows prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a crafted file.

  • CVE-2022-2618MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient validation of untrusted input in Internals in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to bypass download restrictions via a malicious file .

  • CVE-2022-2616MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in Extensions API in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to spoof the contents of the Omnibox (URL bar) via a crafted Chrome Extension.

  • CVE-2022-2615MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Cookies in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-2612MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Side-channel information leakage in Keyboard input in Google Chrome prior to 104.0.5112.79 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.

  • CVE-2022-2610MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in Background Fetch in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

  • CVE-2022-2605MedAug 12, 2022
    risk 0.42cvss 6.5epss 0.01

    Out of bounds read in Dawn in Google Chrome prior to 104.0.5112.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-25763HigAug 10, 2022
    risk 0.42cvss 7.5epss 0.02

    Improper Input Validation vulnerability in HTTP/2 request validation of Apache Traffic Server allows an attacker to create smuggle or cache poison attacks. This issue affects Apache Traffic Server 8.0.0 to 9.1.2.

  • CVE-2022-35922HigAug 1, 2022
    risk 0.42cvss 7.5epss 0.02

    Rust-WebSocket is a WebSocket (RFC6455) library written in Rust. In versions prior to 0.26.5 untrusted websocket connections can cause an out-of-memory (OOM) process abort in a client or a server. The root cause of the issue is during dataframe parsing. Affected versions would…

  • CVE-2022-30699MedAug 1, 2022
    risk 0.42cvss 6.5epss 0.01

    NLnet Labs Unbound, up to and including version 1.16.1, is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a rogue domain name when the cached delegation information is about to…

  • CVE-2022-30698MedAug 1, 2022
    risk 0.42cvss 6.5epss 0.01

    NLnet Labs Unbound, up to and including version 1.16.1 is vulnerable to a novel type of the "ghost domain names" attack. The vulnerability works by targeting an Unbound instance. Unbound is queried for a subdomain of a rogue domain name. The rogue nameserver returns delegation…

  • CVE-2022-34526MedJul 29, 2022
    risk 0.42cvss 6.5epss 0.02

    A stack overflow was discovered in the _TIFFVGetField function of Tiffsplit v4.4.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted TIFF file parsed by the "tiffsplit" or "tiffcrop" utilities.

  • CVE-2022-2160MedJul 28, 2022
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in DevTools in Google Chrome on Windows prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from a user's local files via a crafted HTML page.

  • CVE-2022-34749HigJul 25, 2022
    risk 0.42cvss 7.5epss 0.01

    In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

  • CVE-2022-23825MedJul 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

  • CVE-2022-31129HigJul 6, 2022
    risk 0.42cvss 7.5epss 0.05

    moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried…

Page 117 of 268