VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-3140MedOct 11, 2022
    risk 0.41cvss 6.3epss 0.06

    LibreOffice supports Office URI Schemes to enable browser integration of LibreOffice with MS SharePoint server. An additional scheme 'vnd.libreoffice.command' specific to LibreOffice was added. In the affected versions of LibreOffice links using that scheme could be constructed…

  • CVE-2022-21797HigSep 26, 2022
    risk 0.41cvss 7.3epss 0.02

    The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.

  • CVE-2022-3190MedSep 13, 2022
    risk 0.41cvss 6.3epss 0.02

    Infinite loop in the F5 Ethernet Trailer protocol dissector in Wireshark 3.6.0 to 3.6.7 and 3.4.0 to 3.4.15 allows denial of service via packet injection or crafted capture file

  • CVE-2022-2164MedJul 28, 2022
    risk 0.41cvss 6.3epss 0.01

    Inappropriate implementation in Extensions API in Google Chrome prior to 103.0.5060.53 allowed an attacker who convinced a user to install a malicious extension to bypass discretionary access control via a crafted HTML page.

  • CVE-2022-29217HigMay 24, 2022
    risk 0.41cvss 7.4epss 0.01

    PyJWT is a Python implementation of RFC 7519. PyJWT supports multiple different JWT signing algorithms. With JWT, an attacker submitting the JWT token can choose the used signing algorithm. The PyJWT library requires that the application chooses what algorithms are supported.…

  • CVE-2022-0586MedFeb 14, 2022
    risk 0.41cvss 6.3epss 0.02

    Infinite loop in RTMPT protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

  • CVE-2022-0583MedFeb 14, 2022
    risk 0.41cvss 6.3epss 0.02

    Crash in the PVFS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

  • CVE-2022-0582MedFeb 14, 2022
    risk 0.41cvss 6.3epss 0.02

    Unaligned access in the CSN.1 protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

  • CVE-2022-0581MedFeb 14, 2022
    risk 0.41cvss 6.3epss 0.02

    Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file

  • CVE-2021-40403MedFeb 4, 2022
    risk 0.41cvss 6.3epss 0.01

    An information disclosure vulnerability exists in the pick-and-place rotation parsing functionality of Gerbv 2.7.0 and dev (commit b5f1eacd), and Gerbv forked 2.8.0. A specially-crafted pick-and-place file can exploit the missing initialization of a structure to leak memory…

  • CVE-2022-23133MedJan 13, 2022
    risk 0.41cvss 6.3epss 0.01

    An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire…

  • CVE-2022-21664HigJan 6, 2022
    risk 0.41cvss 7.4epss 0.04

    WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. Due to lack of proper sanitization in one of the classes, there's potential for unintended SQL queries to be executed. This has been patched in WordPress version…

  • CVE-2021-4186MedDec 30, 2021
    risk 0.41cvss 6.3epss 0.02

    Crash in the Gryphon dissector in Wireshark 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-44420HigDec 8, 2021
    risk 0.41cvss 7.3epss 0.02

    In Django 2.2 before 2.2.25, 3.1 before 3.1.14, and 3.2 before 3.2.10, HTTP requests for URLs with trailing newlines could bypass upstream access control based on URL paths.

  • CVE-2021-37695HigAug 13, 2021
    risk 0.41cvss 7.3epss 0.01

    ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Fake Objects](https://ckeditor.com/cke4/addon/fakeobjects) package. The vulnerability allowed to inject malformed Fake Objects HTML, which could…

  • CVE-2021-21347MedMar 23, 2021
    risk 0.41cvss 6.1epss 0.14

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is…

  • CVE-2021-21344MedMar 23, 2021
    risk 0.41cvss 5.3epss 0.76

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is…

  • CVE-2021-21289HigFeb 2, 2021
    risk 0.41cvss 7.4epss 0.04

    Mechanize is an open-source ruby library that makes automated web interaction easy. In Mechanize from version 2.0.0 and before version 2.7.7 there is a command injection vulnerability. Affected versions of mechanize allow for OS commands to be injected using several classes'…

  • CVE-2020-26258MedDec 16, 2020
    risk 0.41cvss 6.3epss 0.82

    XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.15, a Server-Side Forgery Request vulnerability can be activated when unmarshalling. The vulnerability may allow a remote attacker to request data from internal resources that are…

  • CVE-2020-25653MedNov 26, 2020
    risk 0.41cvss 6.3epss 0.00

    A race condition vulnerability was found in the way the spice-vdagentd daemon handled new client connections. This flaw may allow an unprivileged local guest user to become the active agent for spice-vdagentd, possibly resulting in a denial of service or information leakage from…

Page 137 of 268