VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2024-22049MedJan 4, 2024
    risk 0.28cvss 5.3epss 0.01

    httparty before 0.21.0 is vulnerable to an assumed-immutable web parameter vulnerability. A remote and unauthenticated attacker can provide a crafted filename parameter during multipart/form-data uploads which could result in attacker controlled filenames being written.

  • CVE-2023-6511MedDec 6, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Autofill in Google Chrome prior to 120.0.6099.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-5859MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Picture In Picture in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted local HTML page. (Chromium security severity: Low)

  • CVE-2023-5858MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in WebApp Provider in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-5853MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-5851MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-5850MedNov 1, 2023
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Downloads in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Medium)

  • CVE-2023-43796MedOct 31, 2023
    risk 0.28cvss 5.3epss 0.01

    Synapse is an open-source Matrix homeserver Prior to versions 1.95.1 and 1.96.0rc1, cached device information of remote users can be queried from Synapse. This can be used to enumerate the remote users known to a homeserver. System administrators are encouraged to upgrade to…

  • CVE-2023-5349MedOct 30, 2023
    risk 0.28cvss 5.3epss 0.01

    A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.

  • CVE-2023-4909MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Interstitials in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-4908MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Picture in Picture in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-4907MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Intents in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate security UI via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-4906MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Autofill in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Autofill restrictions via a crafted HTML page. (Chromium security severity: Low)

  • CVE-2023-4905MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4904MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in Downloads in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to bypass Enterprise policy restrictions via a crafted download. (Chromium security severity: Medium)

  • CVE-2023-4903MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Custom Mobile Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4902MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Input in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4901MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Prompts in Google Chrome prior to 117.0.5938.62 allowed a remote attacker to potentially spoof security UI via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-4900MedSep 12, 2023
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Custom Tabs in Google Chrome on Android prior to 117.0.5938.62 allowed a remote attacker to obfuscate a permission prompt via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2023-30534MedSep 5, 2023
    risk 0.28cvss 4.3epss 0.03

    Cacti is an open source operational monitoring and fault management framework. There are two instances of insecure deserialization in Cacti version 1.2.24. While a viable gadget chain exists in Cacti’s vendor directory (phpseclib), the necessary gadgets are not included,…

Page 191 of 268