VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2020-6403MedFeb 11, 2020
    risk 0.28cvss 4.3epss 0.02

    Incorrect implementation in Omnibox in Google Chrome on iOS prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2020-6396MedFeb 11, 2020
    risk 0.28cvss 4.3epss 0.02

    Inappropriate implementation in Skia in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

  • CVE-2020-6392MedFeb 11, 2020
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

  • CVE-2020-6391MedFeb 11, 2020
    risk 0.28cvss 4.3epss 0.01

    Insufficient validation of untrusted input in Blink in Google Chrome prior to 80.0.3987.87 allowed a local attacker to bypass content security policy via a crafted HTML page.

  • CVE-2019-13763MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in payments in Google Chrome prior to 79.0.3945.79 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page.

  • CVE-2019-13761MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2019-13759MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in interstitials in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2019-13758MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in navigation in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2019-13757MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in Omnibox in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

  • CVE-2019-13756MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.01

    Incorrect security UI in printing in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

  • CVE-2019-13755MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to disable extensions via a crafted HTML page.

  • CVE-2019-13754MedDec 10, 2019
    risk 0.28cvss 4.3epss 0.02

    Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page.

  • CVE-2013-4411MedDec 3, 2019
    risk 0.28cvss 4.3epss 0.01

    Review Board: URL processing gives unauthorized users access to review lists

  • CVE-2019-18678MedNov 26, 2019
    risk 0.28cvss 5.3epss 0.11

    An issue was discovered in Squid 3.x and 4.x through 4.8. It allows attackers to smuggle HTTP requests through frontend software to a Squid instance that splits the HTTP Request pipeline differently. The resulting Response messages corrupt caches (between a client and Squid)…

  • CVE-2012-1161MedNov 14, 2019
    risk 0.28cvss 4.3epss 0.01

    Moodle before 2.2.2: Course information leak via hidden courses being displayed in tag search results

  • CVE-2012-1158MedNov 14, 2019
    risk 0.28cvss 4.3epss 0.01

    Moodle before 2.2.2 has a course information leak in gradebook where users are able to see hidden grade items in export

  • CVE-2012-0049MedNov 7, 2019
    risk 0.28cvss 4.3epss 0.01

    OpenTTD before 1.1.5 contains a Denial of Service (slow read attack) that prevents users from joining the server.

  • CVE-2013-1930MedOct 31, 2019
    risk 0.28cvss 4.3epss 0.01

    MantisBT 1.2.12 before 1.2.15 allows authenticated users to by the workflow restriction and close issues.

  • CVE-2019-15587MedOct 22, 2019
    risk 0.28cvss 5.4epss 0.02

    In the Loofah gem for Ruby through v2.3.0 unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.

  • CVE-2019-16910MedSep 26, 2019
    risk 0.28cvss 5.3epss 0.02

    Arm Mbed TLS before 2.19.0 and Arm Mbed Crypto before 2.0.0, when deterministic ECDSA is enabled, use an RNG with insufficient entropy for blinding, which might allow an attacker to recover a private key via side-channel attacks if a victim signs the same message many times.…

Page 198 of 268