VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2016-1900LowJan 20, 2016
    risk 0.17cvss 3.7epss 0.02

    CRLF injection vulnerability in the cgit_print_http_headers function in ui-shared.c in CGit before 0.12 allows remote attackers with permission to write to a repository to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS)…

  • CVE-2016-1899LowJan 20, 2016
    risk 0.17cvss 3.7epss 0.02

    CRLF injection vulnerability in the ui-blob handler in CGit before 0.12 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks via CRLF sequences in the mimetype parameter, as demonstrated by a…

  • CVE-2024-4855LowMay 14, 2024
    risk 0.16cvss 3.6epss 0.00

    Use after free issue in editcap could cause denial of service via crafted capture file

  • CVE-2024-4853LowMay 14, 2024
    risk 0.16cvss 3.6epss 0.00

    Memory handling issue in editcap could cause denial of service via crafted capture file

  • CVE-2024-25983LowFeb 19, 2024
    risk 0.16cvss 3.5epss 0.01

    Insufficient checks in a web service made it possible to add comments to the comments block on another user's dashboard when it was not otherwise available (e.g., on their profile page).

  • CVE-2023-7101HigKEVDec 24, 2023
    risk 0.16cvss 7.8epss 0.17

    Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type “eval”. Specifically, the issue stems…

  • CVE-2023-4016LowAug 2, 2023
    risk 0.16cvss 2.5epss 0.00

    Under some circumstances, this weakness allows a user who has access to run the “ps” utility on a machine, the ability to write almost unlimited amounts of unfiltered data into the process heap.

  • CVE-2021-29473LowApr 26, 2021
    risk 0.16cvss 2.5epss 0.02

    Exiv2 is a C++ library and a command-line utility to read, write, delete and modify Exif, IPTC, XMP and ICC image metadata. An out-of-bounds read was found in Exiv2 versions v0.27.3 and earlier. Exiv2 is a command-line utility and C++ library for reading, writing, deleting, and…

  • CVE-2021-27645LowFeb 24, 2021
    risk 0.16cvss 2.5epss 0.00

    The nameserver caching daemon (nscd) in the GNU C Library (aka glibc or libc6) 2.29 through 2.33, when processing a request for netgroup lookup, may crash due to a double-free, potentially resulting in degraded service or Denial of Service on the local system. This is related to…

  • CVE-2021-23239LowJan 12, 2021
    risk 0.16cvss 2.5epss 0.01

    The sudoedit personality of Sudo before 1.9.5 may allow a local unprivileged user to perform arbitrary directory-existence tests by winning a sudo_edit.c race condition in replacing a user-controlled directory by a symlink to an arbitrary path.

  • CVE-2020-4031LowJun 22, 2020
    risk 0.16cvss 3.5epss 0.02

    In FreeRDP before version 2.1.2, there is a use-after-free in gdi_SelectObject. All FreeRDP clients using compatibility mode with /relax-order-checks are affected. This is fixed in version 2.1.2.

  • CVE-2020-4050LowJun 12, 2020
    risk 0.16cvss 3.5epss 0.01

    In affected versions of WordPress, misuse of the `set-screen-option` filter's return value allows arbitrary user meta fields to be saved. It does require an admin to install a plugin that would misuse the filter. Once installed, it can be leveraged by low privileged users. This…

  • CVE-2020-11054LowMay 7, 2020
    risk 0.16cvss 3.5epss 0.02

    In qutebrowser versions less than 1.11.1, reloading a page with certificate errors shows a green URL. After a certificate error was overridden by the user, qutebrowser displays the URL as yellow (colors.statusbar.url.warn.fg). However, when the affected website was subsequently…

  • CVE-2016-4980LowNov 27, 2019
    risk 0.16cvss 2.5epss 0.00

    A password generation weakness exists in xquest through 2016-06-13.

  • CVE-2023-2431LowJun 16, 2023
    risk 0.15cvss 3.4epss 0.00

    A security issue was discovered in Kubelet that allows pods to bypass the seccomp profile enforcement. Pods that use localhost type for seccomp profile but specify an empty profile field, are affected by this issue. In this scenario, this vulnerability allows the pod to run in…

  • CVE-2021-3923LowMar 27, 2023
    risk 0.15cvss 2.3epss 0.00

    A flaw was found in the Linux kernel's implementation of RDMA over infiniband. An attacker with a privileged local account can leak kernel stack information when issuing commands to the /dev/infiniband/rdma_cm device node. While this access is unlikely to leak sensitive user…

  • CVE-2022-31628LowSep 28, 2022
    risk 0.15cvss 2.3epss 0.01

    In PHP versions before 7.4.31, 8.0.24 and 8.1.11, the phar uncompressor code would recursively uncompress "quines" gzip files, resulting in an infinite loop.

  • CVE-2021-44026CriKEVNov 19, 2021
    risk 0.15cvss 9.8epss 0.43

    Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.

  • CVE-2021-29510LowMay 13, 2021
    risk 0.15cvss 3.3epss 0.01

    Pydantic is a data validation and settings management using Python type hinting. In affected versions passing either `'infinity'`, `'inf'` or `float('inf')` (or their negatives) to `datetime` or `date` fields causes validation to run forever with 100% CPU usage (on one CPU).…

  • CVE-2021-23358LowMar 29, 2021
    risk 0.15cvss 3.3epss 0.04

    The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument as it is not sanitized.

Page 209 of 268