VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2021-30614HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30614 Heap buffer overflow in TabStrip

  • CVE-2021-30613HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30613 Use after free in Base internals

  • CVE-2021-30610HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30610 Use after free in Extensions API

  • CVE-2021-30609HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30609 Use after free in Sign-In

  • CVE-2021-30608HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30608 Use after free in Web Share

  • CVE-2021-30607HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30607 Use after free in Permissions

  • CVE-2021-30606HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30606 Use after free in Blink

  • CVE-2021-30599HigAug 26, 2021
    risk 0.58cvss 8.8epss 0.05

    Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2021-30598HigAug 26, 2021
    risk 0.58cvss 8.8epss 0.07

    Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2021-30573HigAug 3, 2021
    risk 0.58cvss 8.8epss 0.06

    Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30557HigJul 2, 2021
    risk 0.58cvss 8.8epss 0.12

    Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-33477HigMay 20, 2021
    risk 0.58cvss 8.8epss 0.04

    rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.

  • CVE-2021-31800CriMay 5, 2021
    risk 0.58cvss 9.8epss 0.19

    Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code…

  • CVE-2021-29472HigApr 27, 2021
    risk 0.58cvss 8.8epss 0.05

    Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed in the HgDriver if hg/Mercurial is installed on the system.…

  • CVE-2021-21225HigApr 26, 2021
    risk 0.58cvss 8.8epss 0.07

    Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21157HigFeb 22, 2021
    risk 0.58cvss 8.8epss 0.09

    Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-8625HigFeb 17, 2021
    risk 0.58cvss 8.1epss 0.64

    BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid…

  • CVE-2020-25682HigJan 20, 2021
    risk 0.58cvss 8.1epss 0.71

    A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. An attacker on the network, who can create valid DNS replies, could use this flaw to cause an…

  • CVE-2020-35701HigJan 11, 2021
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.

  • CVE-2020-13584HigDec 3, 2020
    risk 0.58cvss 8.8epss 0.05

    An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs to visit a malicious web site to trigger this vulnerability.

Page 21 of 268