VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2019-19072MedNov 18, 2019
    risk 0.22cvss 4.4epss 0.00

    A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c in the Linux kernel through 5.3.11 allows attackers to cause a denial of service (memory consumption), aka CID-96c5c6e6a5b6.

  • CVE-2019-2614MedApr 23, 2019
    risk 0.22cvss 4.4epss 0.03

    Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.6.43 and prior, 5.7.25 and prior and 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with network…

  • CVE-2026-35094LowApr 1, 2026
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in libinput. An attacker capable of deploying a Lua plugin file in specific system directories can exploit a dangling pointer vulnerability. This occurs when a garbage collection cleanup function is called, leaving a pointer that can then be printed to system…

  • CVE-2024-28180MedMar 9, 2024
    risk 0.21cvss 4.3epss 0.02

    Package jose aims to provide an implementation of the Javascript Object Signing and Encryption set of standards. An attacker could send a JWE containing compressed data that used large amounts of memory and CPU when decompressed by Decrypt or DecryptMulti. Those functions now…

  • CVE-2024-25982MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.

  • CVE-2024-25981MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    Separate Groups mode restrictions were not honored when performing a forum export, which would export forum data for all groups. By default this only provided additional access to non-editing teachers.

  • CVE-2024-25980MedFeb 19, 2024
    risk 0.21cvss 4.3epss 0.01

    Separate Groups mode restrictions were not honored in the H5P attempts report, which would display users from other groups. By default this only provided additional access to non-editing teachers.

  • CVE-2024-1048LowFeb 6, 2024
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in the grub2-set-bootflag utility of grub2. After the fix of CVE-2019-14865, grub2-set-bootflag will create a temporary file with the new grubenv content and rename it to the original grubenv file. If the program is killed before the rename operation, the…

  • CVE-2023-5546MedNov 9, 2023
    risk 0.21cvss 4.3epss 0.01

    ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk.

  • CVE-2023-39999MedOct 13, 2023
    risk 0.21cvss 4.3epss 0.01

    Exposure of Sensitive Information to an Unauthorized Actor in WordPress from 6.3 through 6.3.1, from 6.2 through 6.2.2, from 6.1 through 6.13, from 6.0 through 6.0.5, from 5.9 through 5.9.7, from 5.8 through 5.8.7, from 5.7 through 5.7.9, from 5.6 through 5.6.11, from 5.5…

  • CVE-2023-39194LowOct 9, 2023
    risk 0.21cvss 3.2epss 0.00

    A flaw was found in the XFRM subsystem in the Linux kernel. The specific flaw exists within the processing of state filters, which can result in a read past the end of an allocated buffer. This flaw allows a local privileged (CAP_NET_ADMIN) attacker to trigger an out-of-bounds…

  • CVE-2023-40587MedAug 25, 2023
    risk 0.21cvss 4.3epss 0.01

    Pyramid is an open source Python web framework. A path traversal vulnerability in Pyramid versions 2.0.0 and 2.0.1 impacts users of Python 3.11 that are using a Pyramid static view with a full filesystem path and have a `index.html` file that is located exactly one directory…

  • CVE-2023-22840LowAug 11, 2023
    risk 0.21cvss 3.3epss 0.00

    Improper neutralization in software for the Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable denial of service via local access.

  • CVE-2023-1386LowJul 24, 2023
    risk 0.21cvss 3.3epss 0.00

    A flaw was found in the 9p passthrough filesystem (9pfs) implementation in QEMU. When a local user in the guest writes an executable file with SUID or SGID, none of these privileged bits are correctly dropped. As a result, in rare circumstances, this flaw could be used by…

  • CVE-2023-2602LowJun 6, 2023
    risk 0.21cvss 3.3epss 0.00

    A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.

  • CVE-2023-28336MedMar 23, 2023
    risk 0.21cvss 4.3epss 0.01

    Insufficient filtering of grade report history made it possible for teachers to access the names of users they could not otherwise access.

  • CVE-2018-14628MedJan 17, 2023
    risk 0.21cvss 4.3epss 0.01

    An information leak vulnerability was discovered in Samba's LDAP server. Due to missing access control checks, an authenticated but unprivileged attacker could discover the names and preserved attributes of deleted objects in the LDAP store.

  • CVE-2022-3171MedOct 12, 2022
    risk 0.21cvss 4.3epss 0.01

    A parsing issue with binary data in protobuf-java core and lite versions prior to 3.21.7, 3.20.3, 3.19.6 and 3.16.3 can lead to a denial of service attack. Inputs containing multiple instances of non-repeated embedded messages with repeated or unknown fields causes objects to be…

  • CVE-2021-4217LowAug 24, 2022
    risk 0.21cvss 3.3epss 0.01

    A flaw was found in unzip. The vulnerability occurs due to improper handling of Unicode strings, which can lead to a null pointer dereference. This flaw allows an attacker to input a specially crafted zip file, leading to a crash or code execution.

  • CVE-2020-14394LowAug 17, 2022
    risk 0.21cvss 3.2epss 0.00

    An infinite loop flaw was found in the USB xHCI controller emulation of QEMU while computing the length of the Transfer Request Block (TRB) Ring. This flaw allows a privileged guest user to hang the QEMU process on the host, resulting in a denial of service.

Page 205 of 268