VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-30974MedMay 18, 2022
    risk 0.36cvss 5.5epss 0.01

    compile in regexp.c in Artifex MuJS through 1.2.0 results in stack consumption because of unlimited recursion, a different issue than CVE-2019-11413.

  • CVE-2022-28506MedApr 25, 2022
    risk 0.36cvss 5.5epss 0.01

    There is a heap-buffer-overflow in GIFLIB 5.2.1 function DumpScreen2RGB() in gif2rgb.c:298:45.

  • CVE-2022-26356MedApr 5, 2022
    risk 0.36cvss 5.6epss 0.00

    Racy interactions between dirty vram tracking and paging log dirty hypercalls Activation of log dirty mode done by XEN_DMOP_track_dirty_vram (was named HVMOP_track_dirty_vram before Xen 4.9) is racy with ongoing log dirty hypercalls. A suitably timed call to…

  • CVE-2022-24191MedApr 4, 2022
    risk 0.36cvss 5.5epss 0.01

    In HTMLDOC 1.9.14, an infinite loop in the gif_read_lzw function can lead to a pointer arbitrarily pointing to heap memory and resulting in a buffer overflow.

  • CVE-2022-1122MedMar 29, 2022
    risk 0.36cvss 5.5epss 0.01

    A flaw was found in the opj2_decompress program in openjpeg2 2.4.0 in the way it handles an input directory with a large number of files. When it fails to allocate a buffer to store the filenames of the input directory, it calls free() on an uninitialized pointer, leading to a…

  • CVE-2022-27943MedMar 26, 2022
    risk 0.36cvss 5.5epss 0.01

    libiberty/rust-demangle.c in GNU GCC 11.2 allows stack consumption in demangle_const, as demonstrated by nm-new.

  • CVE-2022-27939MedMar 26, 2022
    risk 0.36cvss 5.5epss 0.01

    tcprewrite in Tcpreplay 4.4.1 has a reachable assertion in get_layer4_v6 in common/get.c.

  • CVE-2021-3933MedMar 25, 2022
    risk 0.36cvss 5.5epss 0.01

    An integer overflow could occur when OpenEXR processes a crafted file on systems where size_t < 64 bits. This could cause an invalid bytesPerLine and maxBytesPerLine value, which could lead to problems with application stability or lead to other attack paths.

  • CVE-2021-4148MedMar 23, 2022
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in the Linux kernel's block_invalidatepage in fs/buffer.c in the filesystem. A missing sanity check may allow a local attacker with user privilege to cause a denial of service (DOS) problem.

  • CVE-2022-0924MedMar 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Out-of-bounds Read error in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 408976c4.

  • CVE-2022-0909MedMar 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Divide By Zero error in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f8d0f9aa.

  • CVE-2022-0907MedMar 11, 2022
    risk 0.36cvss 5.5epss 0.01

    Unchecked Return Value to NULL Pointer Dereference in tiffcrop in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f2b656e2.

  • CVE-2022-0865MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.01

    Reachable Assertion in tiffcp in libtiff 4.3.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit 5e180045.

  • CVE-2021-4095MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    A NULL pointer dereference was found in the Linux kernel's KVM when dirty ring logging is enabled without an active vCPU context. An unprivileged local attacker on the host may use this flaw to cause a kernel oops condition and thus a denial of service by issuing a…

  • CVE-2021-4023MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the io-workqueue implementation in the Linux kernel versions prior to 5.15-rc1. The kernel can panic when an improper cancellation operation triggers the submission of new io-uring operations during a shortage of free space. This flaw allows a local user with…

  • CVE-2021-44269MedMar 10, 2022
    risk 0.36cvss 5.5epss 0.01

    An out of bounds read was found in Wavpack 5.4.0 in processing *.WAV files. This issue triggered in function WavpackPackSamples of file src/pack_utils.c, tainted variable cnt is too large, that makes pointer sptr read beyond heap bound.

  • CVE-2021-4115MedFeb 21, 2022
    risk 0.36cvss 5.5epss 0.01

    There is a flaw in polkit which can allow an unprivileged user to cause polkit to crash, due to process file descriptor exhaustion. The highest threat from this vulnerability is to availability. NOTE: Polkit process outage duration is tied to the failing process being reaped and…

  • CVE-2021-20320MedFeb 18, 2022
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in s390 eBPF JIT in bpf_jit_insn in arch/s390/net/bpf_jit_comp.c in the Linux kernel. In this flaw, a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem.

  • CVE-2022-0530MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.02

    A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

  • CVE-2022-0529MedFeb 9, 2022
    risk 0.36cvss 5.5epss 0.02

    A flaw was found in Unzip. The vulnerability occurs during the conversion of a wide string to a local string that leads to a heap of out-of-bound write. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

Page 154 of 268