Fedora
CVEs (5,359)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46668 | Med | 0.36 | 5.5 | 0.00 | Feb 1, 2022 | MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures. | ||
| CVE-2021-46667 | Med | 0.36 | 5.5 | 0.00 | Feb 1, 2022 | MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash. | ||
| CVE-2021-46665 | Med | 0.36 | 5.5 | 0.00 | Feb 1, 2022 | MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations. | ||
| CVE-2021-46664 | Med | 0.36 | 5.5 | 0.00 | Feb 1, 2022 | MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr. | ||
| CVE-2021-46663 | Med | 0.36 | 5.5 | 0.00 | Feb 1, 2022 | MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements. | ||
| CVE-2021-46661 | Med | 0.36 | 5.5 | 0.00 | Feb 1, 2022 | MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE). | ||
| CVE-2022-24130 | Med | 0.36 | 5.5 | 0.02 | Jan 31, 2022 | xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text. | ||
| CVE-2021-46659 | Med | 0.36 | 5.5 | 0.01 | Jan 29, 2022 | MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW. | ||
| CVE-2022-23034 | Med | 0.36 | 5.5 | 0.00 | Jan 25, 2022 | A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of mappings. When both are in use for any individual mapping,… | ||
| CVE-2021-45343 | Med | 0.36 | 5.5 | 0.01 | Jan 25, 2022 | In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document. | ||
| CVE-2022-21301 | Med | 0.36 | 5.5 | 0.02 | Jan 19, 2022 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.… | ||
| CVE-2021-46021 | Med | 0.36 | 5.5 | 0.01 | Jan 14, 2022 | An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. | ||
| CVE-2021-44647 | Med | 0.36 | 5.5 | 0.00 | Jan 11, 2022 | Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service. | ||
| CVE-2022-21663 | Med | 0.36 | 6.6 | 0.04 | Jan 6, 2022 | WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in… | ||
| CVE-2021-4183 | Med | 0.36 | 5.5 | 0.01 | Dec 30, 2021 | Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file | ||
| CVE-2021-45293 | Med | 0.36 | 5.5 | 0.01 | Dec 21, 2021 | A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet. | ||
| CVE-2021-42376 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input. | ||
| CVE-2021-42375 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input. | ||
| CVE-2021-42373 | Med | 0.36 | 5.5 | 0.00 | Nov 15, 2021 | A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given | ||
| CVE-2020-23903 | Med | 0.36 | 5.5 | 0.01 | Nov 10, 2021 | A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. |
- risk 0.36cvss 5.5epss 0.00
MariaDB through 10.5.9 allows an application crash via certain long SELECT DISTINCT statements that improperly interact with storage-engine resource limitations for temporary data structures.
- risk 0.36cvss 5.5epss 0.00
MariaDB before 10.6.5 has a sql_lex.cc integer overflow, leading to an application crash.
- risk 0.36cvss 5.5epss 0.00
MariaDB through 10.5.9 allows a sql_parse.cc application crash because of incorrect used_tables expectations.
- risk 0.36cvss 5.5epss 0.00
MariaDB through 10.5.9 allows an application crash in sub_select_postjoin_aggr for a NULL value of aggr.
- risk 0.36cvss 5.5epss 0.00
MariaDB through 10.5.13 allows a ha_maria::extra application crash via certain SELECT statements.
- risk 0.36cvss 5.5epss 0.00
MariaDB through 10.5.9 allows an application crash in find_field_in_tables and find_order_in_list via an unused common table expression (CTE).
- risk 0.36cvss 5.5epss 0.02
xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.
- risk 0.36cvss 5.5epss 0.01
MariaDB before 10.7.2 allows an application crash because it does not recognize that SELECT_LEX::nest_level is local to each VIEW.
- risk 0.36cvss 5.5epss 0.00
A PV guest could DoS Xen while unmapping a grant To address XSA-380, reference counting was introduced for grant mappings for the case where a PV guest would have the IOMMU enabled. PV guests can request two forms of mappings. When both are in use for any individual mapping,…
- risk 0.36cvss 5.5epss 0.01
In LibreCAD 2.2.0, a NULL pointer dereference in the HATCH handling of libdxfrw allows an attacker to crash the application using a crafted DXF document.
- risk 0.36cvss 5.5epss 0.02
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server.…
- risk 0.36cvss 5.5epss 0.01
An Use-After-Free vulnerability in rec_record_destroy() at rec-record.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
- risk 0.36cvss 5.5epss 0.00
Lua v5.4.3 and above are affected by SEGV by type confusion in funcnamefromcode function in ldebug.c which can cause a local denial of service.
- risk 0.36cvss 6.6epss 0.04
WordPress is a free and open-source content management system written in PHP and paired with a MariaDB database. On a multisite, users with Super Admin role can bypass explicit/additional hardening under certain conditions through object injection. This has been patched in…
- risk 0.36cvss 5.5epss 0.01
Crash in the pcapng file parser in Wireshark 3.6.0 allows denial of service via crafted capture file
- risk 0.36cvss 5.5epss 0.01
A Denial of Service vulnerability exists in Binaryen 103 due to an Invalid memory address dereference in wasm::WasmBinaryBuilder::visitLet.
- risk 0.36cvss 5.5epss 0.00
A NULL pointer dereference in Busybox's hush applet leads to denial of service when processing a crafted shell command, due to missing validation after a \x03 delimiter character. This may be used for DoS under very rare conditions of filtered command input.
- risk 0.36cvss 5.5epss 0.00
An incorrect handling of a special element in Busybox's ash applet leads to denial of service when processing a crafted shell command, due to the shell mistaking specific characters for reserved characters. This may be used for DoS under rare conditions of filtered command input.
- risk 0.36cvss 5.5epss 0.00
A NULL pointer dereference in Busybox's man applet leads to denial of service when a section name is supplied but no page argument is given
- risk 0.36cvss 5.5epss 0.01
A Divide by Zero vulnerability in the function static int read_samples of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.
Page 155 of 268