VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2023-39516MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39515MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the cacti's database. These data will be viewed by…

  • CVE-2023-39514MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39513MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39512MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability which allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39510MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39366MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data stored in the _cacti_'s database. These data will be viewed by…

  • CVE-2023-39360MedSep 5, 2023
    risk 0.40cvss 6.1epss 0.01

    Cacti is an open source operational monitoring and fault management framework.Affected versions are subject to a Stored Cross-Site-Scripting (XSS) Vulnerability allows an authenticated user to poison data. The vulnerability is found in `graphs_new.php`. Several validations are…

  • CVE-2023-32627MedJul 10, 2023
    risk 0.40cvss 6.2epss 0.00

    A floating point exception vulnerability was found in sox, in the read_samples function at sox/src/voc.c:334:18. This flaw can lead to a denial of service.

  • CVE-2023-26590MedJul 10, 2023
    risk 0.40cvss 6.2epss 0.00

    A floating point exception vulnerability was found in sox, in the lsx_aiffstartwrite function at sox/src/aiff.c:622:58. This flaw can lead to a denial of service.

  • CVE-2023-22298MedJan 17, 2023
    risk 0.40cvss 6.1epss 0.01

    Open redirect vulnerability in pgAdmin 4 versions prior to v6.14 allows a remote unauthenticated attacker to redirect a user to an arbitrary web site and conduct a phishing attack by having a user to access a specially crafted URL.

  • CVE-2023-22911MedJan 10, 2023
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MediaWiki before 1.35.9, 1.36.x through 1.38.x before 1.38.5, and 1.39.x before 1.39.1. E-Widgets does widget replacement in HTML attributes, which can lead to XSS, because widget authors often do not expect that their widget is executed in an HTML…

  • CVE-2022-46175HigDec 24, 2022
    risk 0.40cvss 7.1epss 0.09

    JSON5 is an extension to the popular JSON file format that aims to be easier to write and maintain by hand (e.g. for config files). The `parse` method of the JSON5 library before and including versions 1.0.1 and 2.2.1 does not restrict parsing of keys named `__proto__`, allowing…

  • CVE-2021-33640MedDec 19, 2022
    risk 0.40cvss 6.2epss 0.01

    After tar_close(), libtar.c releases the memory pointed to by pointer t. After tar_close() is called in the list() function, it continues to use pointer t: free_longlink_longname(t->th_buf) . As a result, the released memory is used (use-after-free).

  • CVE-2022-37967HigNov 9, 2022
    risk 0.40cvss 7.2epss 0.05

    Windows Kerberos Elevation of Privilege Vulnerability

  • CVE-2022-42799MedNov 1, 2022
    risk 0.40cvss 6.1epss 0.01

    The issue was addressed with improved UI handling. This issue is fixed in tvOS 16.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Visiting a malicious website may lead to user interface spoofing.

  • CVE-2014-0147MedSep 29, 2022
    risk 0.40cvss 6.2epss 0.00

    Qemu before 1.6.2 block diver for the various disk image formats used by Bochs and for the QCOW version 2 format, are vulnerable to a possible crash caused by signed data types or a logic error while creating QCOW2 snapshots, which leads to incorrectly calling update_refcount()…

  • CVE-2022-1355MedAug 31, 2022
    risk 0.40cvss 6.1epss 0.01

    A stack buffer overflow flaw was found in Libtiffs' tiffcp.c in main() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffcp tool, triggering a stack buffer overflow issue, possibly corrupting the memory, and causing a crash that leads to a denial of…

  • CVE-2022-34912MedJul 2, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MediaWiki before 1.37.3 and 1.38.x before 1.38.1. The contributions-title, used on Special:Contributions, is used as page title without escaping. Hence, in a non-default configuration where a username contains HTML entities, it won't be escaped.

  • CVE-2022-34911MedJul 2, 2022
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in MediaWiki before 1.35.7, 1.36.x and 1.37.x before 1.37.3, and 1.38.x before 1.38.1. XSS can occur in configurations that allow a JavaScript payload in a username. After account creation, when it sets the page title to "Welcome" followed by the…

Page 139 of 268