VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2008-4989MedNov 13, 2008
    risk 0.39cvss 5.9epss 0.02

    The _gnutls_x509_verify_certificate function in lib/x509/verify.c in libgnutls in GnuTLS before 2.6.1 trusts certificate chains in which the last certificate is an arbitrary trusted, self-signed certificate, which allows man-in-the-middle attackers to insert a spoofed…

  • CVE-2024-2408MedJun 9, 2024
    risk 0.38cvss 5.9epss 0.01

    The openssl_private_decrypt function in PHP, when using PKCS1 padding (OPENSSL_PKCS1_PADDING, which is the default), is vulnerable to the Marvin Attack unless it is used with an OpenSSL version that includes the changes from this pull request: …

  • CVE-2024-1580MedFeb 19, 2024
    risk 0.38cvss 5.9epss 0.02

    An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d.

  • CVE-2023-5981MedNov 28, 2023
    risk 0.38cvss 5.9epss 0.01

    A vulnerability was found that the response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from response times of ciphertexts with correct PKCS#1 v1.5 padding.

  • CVE-2023-4806MedSep 18, 2023
    risk 0.38cvss 5.9epss 0.01

    A flaw has been identified in glibc. In an extremely rare situation, the getaddrinfo function may access memory that has been freed, resulting in an application crash. This issue is only exploitable when a NSS module implements only the _nss_*_gethostbyname2_r and…

  • CVE-2023-4813MedSep 12, 2023
    risk 0.38cvss 5.9epss 0.02

    A flaw has been identified in glibc. In an uncommon situation, the gaih_inet function may use memory that has been freed, resulting in an application crash. This issue is only exploitable when the getaddrinfo function is called and the hosts database in /etc/nsswitch.conf is…

  • CVE-2023-3347MedJul 20, 2023
    risk 0.38cvss 5.9epss 0.00

    A vulnerability was found in Samba's SMB2 packet signing mechanism. The SMB2 packet signing is not enforced if an admin configured "server signing = required" or for SMB2 connections to Domain Controllers where SMB2 packet signing is mandatory. This flaw allows an attacker to…

  • CVE-2023-22053MedJul 18, 2023
    risk 0.38cvss 5.9epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 5.7.42 and prior and 8.0.33 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols…

  • CVE-2023-1183MedJul 10, 2023
    risk 0.38cvss 5.0epss 0.65

    A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT command where the contents of the file could be written to a new file whose location was determined by the attacker.

  • CVE-2023-20867LowKEVJun 13, 2023
    risk 0.38cvss 3.9epss 0.14

    A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.

  • CVE-2023-28321MedMay 26, 2023
    risk 0.38cvss 5.9epss 0.02

    An improper certificate validation vulnerability exists in curl <v8.1.0 in the way it supports matching of wildcard patterns when listed as "Subject Alternative Name" in TLS server certificates. curl can be built to use its own name matching function for TLS rather than one…

  • CVE-2023-31147MedMay 25, 2023
    risk 0.38cvss 5.9epss 0.01

    c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate random numbers used for DNS query ids. This is not a CSPRNG, and it is also not seeded by srand() so will generate predictable output. Input from the…

  • CVE-2023-32570MedMay 10, 2023
    risk 0.38cvss 5.9epss 0.01

    VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit.

  • CVE-2023-27536MedMar 30, 2023
    risk 0.38cvss 5.9epss 0.02

    An authentication bypass vulnerability exists libcurl <8.0.0 in the connection reuse feature which can reuse previously established connections with incorrect user permissions due to a failure to check for changes in the CURLOPT_GSSAPI_DELEGATION option. This vulnerability…

  • CVE-2023-27535MedMar 30, 2023
    risk 0.38cvss 5.9epss 0.02

    An authentication bypass vulnerability exists in libcurl <8.0.0 in the FTP connection reuse feature that can result in wrong credentials being used during subsequent transfers. Previously created connections are kept in a connection pool for reuse if they match the current…

  • CVE-2021-20251MedMar 6, 2023
    risk 0.38cvss 5.9epss 0.01

    A flaw was found in samba. A race condition in the password lockout code may lead to the risk of brute force attacks being successful if special conditions are met.

  • CVE-2022-41854MedNov 11, 2022
    risk 0.38cvss 5.8epss 0.01

    Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of…

  • CVE-2022-39283MedOct 12, 2022
    risk 0.38cvss 5.9epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. All FreeRDP based clients when using the `/video` command line switch might read uninitialized data, decode it as audio/video and display the result. FreeRDP based server implementations are not affected. This issue…

  • CVE-2021-41159MedOct 21, 2021
    risk 0.38cvss 5.8epss 0.01

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license. All FreeRDP clients prior to version 2.4.1 using gateway connections (`/gt:rpc`) fail to validate input data. A malicious gateway might allow client memory to be written out…

  • CVE-2021-40530MedSep 6, 2021
    risk 0.38cvss 5.9epss 0.01

    The ElGamal implementation in Crypto++ through 8.5 allows plaintext recovery because, during interaction between two cryptographic libraries, a certain dangerous combination of the prime defined by the receiver's public key, the generator defined by the receiver's public key,…

Page 147 of 268