VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2021-32740HigJul 6, 2021
    risk 0.42cvss 7.5epss 0.02

    Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a…

  • CVE-2021-33503HigJun 29, 2021
    risk 0.42cvss 7.5epss 0.03

    An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected…

  • CVE-2021-29063HigJun 21, 2021
    risk 0.42cvss 7.5epss 0.04

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Mpmath v1.0.0 through v1.2.1 when the mpmathify function is called.

  • CVE-2021-0089MedJun 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Observable response discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

  • CVE-2021-0086MedJun 9, 2021
    risk 0.42cvss 6.5epss 0.00

    Observable response discrepancy in floating-point operations for some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.

  • CVE-2021-33571HigJun 8, 2021
    risk 0.42cvss 7.5epss 0.05

    In Django 2.2 before 2.2.24, 3.x before 3.1.12, and 3.2 before 3.2.4, URLValidator, validate_ipv4_address, and validate_ipv46_address do not prohibit leading zero characters in octal literals. This may allow a bypass of access control that is based on IP addresses.…

  • CVE-2021-30540MedJun 7, 2021
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in payments in Google Chrome on Android prior to 91.0.4472.77 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2021-30534MedJun 7, 2021
    risk 0.42cvss 6.5epss 0.01

    Insufficient policy enforcement in iFrameSandbox in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2021-30531MedJun 7, 2021
    risk 0.42cvss 6.5epss 0.02

    Insufficient policy enforcement in Content Security Policy in Google Chrome prior to 91.0.4472.77 allowed a remote attacker to bypass content security policy via a crafted HTML page.

  • CVE-2021-28677HigJun 2, 2021
    risk 0.42cvss 7.5epss 0.02

    An issue was discovered in Pillow before 8.2.0. For EPS data, the readline implementation used in EPSImageFile has to deal with any combination of \r and \n as line endings. It used an accidentally quadratic method of accumulating lines while looking for a line ending. A…

  • CVE-2021-28676HigJun 2, 2021
    risk 0.42cvss 7.5epss 0.03

    An issue was discovered in Pillow before 8.2.0. For FLI data, FliDecode did not properly check that the block advance was non-zero, potentially leading to an infinite loop on load.

  • CVE-2019-12067MedJun 2, 2021
    risk 0.42cvss 6.5epss 0.00

    The ahci_commit_buf function in ide/ahci.c in QEMU allows attackers to cause a denial of service (NULL dereference) when the command header 'ad->cur_cmd' is null.

  • CVE-2021-33194HigMay 26, 2021
    risk 0.42cvss 7.5epss 0.07

    golang.org/x/net before v0.0.0-20210520170846-37e1c6afe023 allows attackers to cause a denial of service (infinite loop) via crafted ParseFragment input.

  • CVE-2021-3524MedMay 17, 2021
    risk 0.42cvss 6.5epss 0.02

    A flaw was found in the Red Hat Ceph Storage RadosGW (Ceph Object Gateway) in versions before 14.2.21. The vulnerability is related to the injection of HTTP headers via a CORS ExposeHeader tag. The newline character in the ExposeHeader tag in the CORS configuration file…

  • CVE-2020-25713MedMay 13, 2021
    risk 0.42cvss 6.5epss 0.02

    A malformed input file can lead to a segfault due to an out of bounds array access in raptor_xml_writer_start_element_common.

  • CVE-2021-20277HigMay 12, 2021
    risk 0.42cvss 7.5epss 0.04

    A flaw was found in Samba's libldb. Multiple, consecutive leading spaces in an LDAP attribute can lead to an out-of-bounds memory write, leading to a crash of the LDAP server process handling the request. The highest threat from this vulnerability is to system availability.

  • CVE-2021-31542HigMay 5, 2021
    risk 0.42cvss 7.5epss 0.05

    In Django 2.2 before 2.2.21, 3.1 before 3.1.9, and 3.2 before 3.2.1, MultiPartParser, UploadedFile, and FieldFile allowed directory traversal via uploaded files with suitably crafted file names.

  • CVE-2021-21229MedApr 30, 2021
    risk 0.42cvss 6.5epss 0.01

    Incorrect security UI in downloads in Google Chrome on Android prior to 90.0.4430.93 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2020-15225HigApr 29, 2021
    risk 0.42cvss 7.5epss 0.02

    django-filter is a generic system for filtering Django QuerySets based on user selections. In django-filter before version 2.4.0, automatically generated `NumberFilter` instances, whose value was later converted to an integer, were subject to potential DoS from maliciously input…

  • CVE-2021-21222MedApr 26, 2021
    risk 0.42cvss 6.5epss 0.02

    Heap buffer overflow in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.

Page 122 of 268