VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2021-30606HigSep 3, 2021
    risk 0.58cvss 8.8epss 0.04

    Chromium: CVE-2021-30606 Use after free in Blink

  • CVE-2021-30599HigAug 26, 2021
    risk 0.58cvss 8.8epss 0.05

    Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2021-30598HigAug 26, 2021
    risk 0.58cvss 8.8epss 0.07

    Type confusion in V8 in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2021-30573HigAug 3, 2021
    risk 0.58cvss 8.8epss 0.06

    Use after free in GPU in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30557HigJul 2, 2021
    risk 0.58cvss 8.8epss 0.12

    Use after free in TabGroups in Google Chrome prior to 91.0.4472.114 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-33477HigMay 20, 2021
    risk 0.58cvss 8.8epss 0.04

    rxvt-unicode 9.22, rxvt 2.7.10, mrxvt 0.5.4, and Eterm 0.9.7 allow (potentially remote) code execution because of improper handling of certain escape sequences (ESC G Q). A response is terminated by a newline.

  • CVE-2021-31800CriMay 5, 2021
    risk 0.58cvss 9.8epss 0.19

    Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code…

  • CVE-2021-29472HigApr 27, 2021
    risk 0.58cvss 8.8epss 0.05

    Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed in the HgDriver if hg/Mercurial is installed on the system.…

  • CVE-2021-21225HigApr 26, 2021
    risk 0.58cvss 8.8epss 0.07

    Out of bounds memory access in V8 in Google Chrome prior to 90.0.4430.85 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-21157HigFeb 22, 2021
    risk 0.58cvss 8.8epss 0.09

    Use after free in Web Sockets in Google Chrome on Linux prior to 88.0.4324.182 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-8625HigFeb 17, 2021
    risk 0.58cvss 8.1epss 0.64

    BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid…

  • CVE-2020-25682HigJan 20, 2021
    risk 0.58cvss 8.1epss 0.71

    A flaw was found in dnsmasq before 2.83. A buffer overflow vulnerability was discovered in the way dnsmasq extract names from DNS packets before validating them with DNSSEC data. An attacker on the network, who can create valid DNS replies, could use this flaw to cause an…

  • CVE-2020-35701HigJan 11, 2021
    risk 0.58cvss 8.8epss 0.05

    An issue was discovered in Cacti 1.2.x through 1.2.16. A SQL injection vulnerability in data_debug.php allows remote authenticated attackers to execute arbitrary SQL commands via the site_id parameter. This can lead to remote code execution.

  • CVE-2020-13584HigDec 3, 2020
    risk 0.58cvss 8.8epss 0.05

    An exploitable use-after-free vulnerability exists in WebKitGTK browser version 2.30.1 x64. A specially crafted HTML web page can cause a use-after-free condition, resulting in a remote code execution. The victim needs to visit a malicious web site to trigger this vulnerability.

  • CVE-2020-24972HigAug 29, 2020
    risk 0.58cvss 8.8epss 0.05

    The Kleopatra component before 3.1.12 (and before 20.07.80) for GnuPG allows remote attackers to execute arbitrary code because openpgp4fpr: URLs are supported without safe handling of command-line options. The Qt platformpluginpath command-line option can be used to load an…

  • CVE-2020-1472MedKEVAug 17, 2020
    risk 0.58cvss 5.5epss 0.99

    An elevation of privilege vulnerability exists when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller, using the Netlogon Remote Protocol (MS-NRPC). An attacker who successfully exploited the vulnerability could run a specially…

  • CVE-2020-6468HigMay 21, 2020
    risk 0.58cvss 8.8epss 0.06

    Type confusion in V8 in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6383HigFeb 27, 2020
    risk 0.58cvss 8.8epss 0.06

    Type confusion in V8 in Google Chrome prior to 80.0.3987.116 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-9273HigFeb 20, 2020
    risk 0.58cvss 8.8epss 0.12

    In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

  • CVE-2019-13767HigJan 10, 2020
    risk 0.58cvss 8.8epss 0.16

    Use after free in media picker in Google Chrome prior to 79.0.3945.88 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

Page 21 of 268