VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2023-3824CriAug 11, 2023
    risk 0.62cvss 9.4epss 0.22

    In PHP version 8.0.* before 8.0.30,  8.1.* before 8.1.22, and 8.2.* before 8.2.8, when loading phar file, while reading PHAR directory entries, insufficient length checking may lead to a stack buffer overflow, leading potentially to memory corruption or RCE.

  • CVE-2023-38180HigKEVAug 8, 2023
    risk 0.62cvss 7.5epss 0.14

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2022-22721CriMar 14, 2022
    risk 0.62cvss 9.1epss 0.42

    If LimitXMLRequestBody is set to allow request bodies larger than 350MB (defaults to 1M) on 32 bit systems an integer overflow happens which later causes out of bounds writes. This issue affects Apache HTTP Server 2.4.52 and earlier.

  • CVE-2022-0097CriFeb 12, 2022
    risk 0.62cvss 9.6epss 0.01

    Inappropriate implementation in DevTools in Google Chrome prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to to potentially allow extension to escape the sandbox via a crafted HTML page.

  • CVE-2021-38013CriDec 23, 2021
    risk 0.62cvss 9.6epss 0.01

    Heap buffer overflow in fingerprint recognition in Google Chrome on ChromeOS prior to 96.0.4664.45 allowed a remote attacker who had compromised a WebUI renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-38002CriNov 23, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Web Transport in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-30571CriAug 3, 2021
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21151CriFeb 22, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Payments in Google Chrome prior to 88.0.4324.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21150CriFeb 22, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Downloads in Google Chrome on Windows prior to 88.0.4324.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21146CriFeb 9, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Navigation in Google Chrome prior to 88.0.4324.146 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21142CriFeb 9, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in Payments in Google Chrome on Mac prior to 88.0.4324.146 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2021-21111CriJan 8, 2021
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in WebUI in Google Chrome prior to 87.0.4280.141 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2021-21107CriJan 8, 2021
    risk 0.62cvss 9.6epss 0.01

    Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2020-6469CriMay 21, 2020
    risk 0.62cvss 9.6epss 0.01

    Insufficient policy enforcement in developer tools in Google Chrome prior to 83.0.4103.61 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension.

  • CVE-2020-11100HigApr 2, 2020
    risk 0.62cvss 8.8epss 0.61

    In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.

  • CVE-2024-25111HigMar 6, 2024
    risk 0.61cvss 8.6epss 0.65

    Squid is a web proxy cache. Starting in version 3.5.27 and prior to version 6.8, Squid may be vulnerable to a Denial of Service attack against HTTP Chunked decoder due to an uncontrolled recursion bug. This problem allows a remote attacker to cause Denial of Service when sending…

  • CVE-2023-6702HigDec 14, 2023
    risk 0.61cvss 8.8epss 0.44

    Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-4357HigAug 15, 2023
    risk 0.61cvss 8.8epss 0.47

    Insufficient validation of untrusted input in XML in Google Chrome prior to 116.0.5845.96 allowed a remote attacker to bypass file access restrictions via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2022-2010CriJul 28, 2022
    risk 0.61cvss 9.3epss 0.01

    Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

  • CVE-2019-14234CriAug 9, 2019
    risk 0.61cvss 9.8epss 0.48

    An issue was discovered in Django 1.11.x before 1.11.23, 2.1.x before 2.1.11, and 2.2.x before 2.2.4. Due to an error in shallow key transformation, key and index lookups for django.contrib.postgres.fields.JSONField, and key lookups for django.contrib.postgres.fields.HStoreField,…

Page 16 of 268