VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2024-0223HigJan 4, 2024
    risk 0.58cvss 8.8epss 0.10

    Heap buffer overflow in ANGLE in Google Chrome prior to 120.0.6099.199 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-5482HigNov 1, 2023
    risk 0.58cvss 8.8epss 0.07

    Insufficient data validation in USB in Google Chrome prior to 119.0.6045.105 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-43115HigSep 18, 2023
    risk 0.58cvss 8.8epss 0.05

    In Artifex Ghostscript through 10.01.2, gdevijs.c in GhostPDL can lead to remote code execution via crafted PostScript documents because they can switch to the IJS device, or change the IjsServer parameter, after SAFER has been activated. NOTE: it is a documented risk that the…

  • CVE-2023-4430HigAug 23, 2023
    risk 0.58cvss 8.8epss 0.09

    Use after free in Vulkan in Google Chrome prior to 116.0.5845.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-3432CriJun 27, 2023
    risk 0.58cvss 10.0epss 0.01

    Server-Side Request Forgery (SSRF) in GitHub repository plantuml/plantuml prior to 1.2023.9.

  • CVE-2023-3217HigJun 13, 2023
    risk 0.58cvss 8.8epss 0.13

    Use after free in WebXR in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-3215HigJun 13, 2023
    risk 0.58cvss 8.8epss 0.14

    Use after free in WebRTC in Google Chrome prior to 114.0.5735.133 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-2723HigMay 16, 2023
    risk 0.58cvss 8.8epss 0.15

    Use after free in DevTools in Google Chrome prior to 113.0.5672.126 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

  • CVE-2023-22809HigJan 18, 2023
    risk 0.58cvss 7.8epss 0.55

    In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to…

  • CVE-2021-41556CriJul 28, 2022
    risk 0.58cvss 10.0epss 0.03

    sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of the squirrel script…

  • CVE-2022-24724HigMar 3, 2022
    risk 0.58cvss 8.8epss 0.05

    cmark-gfm is GitHub's extended version of the C reference implementation of CommonMark. Prior to versions 0.29.0.gfm.3 and 0.28.3.gfm.21, an integer overflow in cmark-gfm's table row parsing `table.c:row_from_string` may lead to heap memory corruption when parsing tables who's…

  • CVE-2022-24407HigFeb 24, 2022
    risk 0.58cvss 8.8epss 0.04

    In Cyrus SASL 2.1.17 through 2.1.27 before 2.1.28, plugins/sql.c does not escape the password for a SQL INSERT or UPDATE statement.

  • CVE-2021-45341HigJan 25, 2022
    risk 0.58cvss 8.8epss 0.07

    A buffer overflow vulnerability in CDataMoji of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.

  • CVE-2021-30625HigOct 8, 2021
    risk 0.58cvss 8.8epss 0.10

    Use after free in Selection API in Google Chrome prior to 93.0.4577.82 allowed a remote attacker who convinced the user the visit a malicious website to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30624HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30624 Use after free in Autofill

  • CVE-2021-30623HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30623 Use after free in Bookmarks

  • CVE-2021-30622HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30622 Use after free in WebApp Installs

  • CVE-2021-30620HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30620 Insufficient policy enforcement in Blink

  • CVE-2021-30618HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30618 Inappropriate implementation in DevTools

  • CVE-2021-30616HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30616 Use after free in Media

Page 20 of 268