VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-36109MedSep 9, 2022
    risk 0.28cvss 5.3epss 0.01

    Moby is an open-source project created by Docker to enable software containerization. A bug was found in Moby (Docker Engine) where supplementary groups are not set up properly. If an attacker has direct access to a container and manipulates their supplementary group access,…

  • CVE-2022-2619MedAug 12, 2022
    risk 0.28cvss 4.3epss 0.00

    Insufficient validation of untrusted input in Settings in Google Chrome prior to 104.0.5112.79 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted HTML page.

  • CVE-2022-2611MedAug 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Fullscreen API in Google Chrome on Android prior to 104.0.5112.79 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-2165MedJul 28, 2022
    risk 0.28cvss 4.3epss 0.01

    Insufficient data validation in URL formatting in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2022-29526MedJun 23, 2022
    risk 0.28cvss 5.3epss 0.03

    Go before 1.17.10 and 1.18.x before 1.18.2 has Incorrect Privilege Assignment. When called with a non-zero flags parameter, the Faccessat function could incorrectly report that a file is accessible.

  • CVE-2022-30597MedMay 18, 2022
    risk 0.28cvss 5.3epss 0.01

    A flaw was found in moodle where the description user field was not hidden when being set as a hidden user field.

  • CVE-2022-30596MedMay 18, 2022
    risk 0.28cvss 5.4epss 0.01

    A flaw was found in moodle where ID numbers displayed when bulk allocating markers to assignments required additional sanitizing to prevent a stored XSS risk.

  • CVE-2021-28544MedApr 12, 2022
    risk 0.28cvss 4.3epss 0.03

    Apache Subversion SVN authz protected copyfrom paths regression Subversion servers reveal 'copyfrom' paths that should be hidden according to configured path-based authorization (authz) rules. When a node has been copied from a protected location, users with access to the copy…

  • CVE-2022-24728MedMar 16, 2022
    risk 0.28cvss 5.4epss 0.01

    CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. A vulnerability has been discovered in the core HTML processing module and may affect all plugins used by CKEditor 4 prior to version 4.18.0. The vulnerability allows someone to inject malformed HTML bypassing…

  • CVE-2021-44141MedFeb 21, 2022
    risk 0.28cvss 4.3epss 0.01

    All versions of Samba prior to 4.15.5 are vulnerable to a malicious client using a server symlink to determine if a file or directory exists in an area of the server file system not exported under the share definition. SMB1 with unix extensions has to be enabled in order for…

  • CVE-2022-0585MedFeb 18, 2022
    risk 0.28cvss 4.3epss 0.02

    Large loops in multiple protocol dissectors in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allow denial of service via packet injection or crafted capture file

  • CVE-2022-0118MedFeb 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in WebShare in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially hide the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-0116MedFeb 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Inappropriate implementation in Compositing in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-0112MedFeb 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Browser UI in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to display missing URL or incorrect URL via a crafted URL.

  • CVE-2022-0110MedFeb 12, 2022
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2022-21245MedJan 19, 2022
    risk 0.28cvss 4.3epss 0.01

    Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple…

  • CVE-2022-21673MedJan 18, 2022
    risk 0.28cvss 4.3epss 0.02

    Grafana is an open-source platform for monitoring and observability. In affected versions when a data source has the Forward OAuth Identity feature enabled, sending a query to that datasource with an API token (and no other user credentials) will forward the OAuth Identity of…

  • CVE-2021-45452MedJan 5, 2022
    risk 0.28cvss 5.3epss 0.02

    Storage.save in Django 2.2 before 2.2.26, 3.2 before 3.2.11, and 4.0 before 4.0.1 allows directory traversal if crafted filenames are directly passed to it.

  • CVE-2021-38020MedDec 23, 2021
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in contacts picker in Google Chrome on Android prior to 96.0.4664.45 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2021-41800MedOct 11, 2021
    risk 0.28cvss 5.3epss 0.02

    MediaWiki before 1.36.2 allows a denial of service (resource consumption because of lengthy query processing time). Visiting Special:Contributions can sometimes result in a long running SQL query because PoolCounter protection is mishandled.

Page 193 of 268