VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2023-0494HigMar 27, 2023
    risk 0.00cvss 7.8epss 0.01

    A vulnerability was found in X.Org. This issue occurs due to a dangling pointer in DeepCopyPointerClasses that can be exploited by ProcXkbSetDeviceInfo() and ProcXkbGetDeviceInfo() to read and write into freed memory. This can lead to local privilege elevation on systems where…

  • CVE-2023-1513LowMar 23, 2023
    risk 0.00cvss 3.3epss 0.00

    A flaw was found in KVM. When calling the KVM_GET_DEBUGREGS ioctl, on 32-bit systems, there might be some uninitialized portions of the kvm_debugregs structure that could be copied to userspace, causing an information leak.

  • CVE-2023-1264MedMar 7, 2023
    risk 0.00cvss 5.5epss 0.00

    NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.1392.

  • CVE-2022-4645MedMar 3, 2023
    risk 0.00cvss 6.8epss 0.00

    LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.

  • CVE-2023-1127HigMar 1, 2023
    risk 0.00cvss 7.8epss 0.00

    Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.

  • CVE-2023-0361HigFeb 15, 2023
    risk 0.00cvss 7.4epss 0.01

    A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the…

  • CVE-2022-46663HigFeb 7, 2023
    risk 0.00cvss 7.5epss 0.01

    In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.

  • CVE-2023-25193HigFeb 4, 2023
    risk 0.00cvss 7.5epss 0.02

    hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

  • CVE-2022-47021HigJan 20, 2023
    risk 0.00cvss 7.8epss 0.00

    A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.

  • CVE-2023-23589MedJan 14, 2023
    risk 0.00cvss 6.5epss 0.01

    The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

  • CVE-2023-23457MedJan 12, 2023
    risk 0.00cvss 5.3epss 0.00

    A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.

  • CVE-2023-23456MedJan 12, 2023
    risk 0.00cvss 5.3epss 0.00

    A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

  • CVE-2023-0049HigJan 4, 2023
    risk 0.00cvss 7.8epss 0.00

    Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.1143.

  • CVE-2022-3109HigDec 16, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.

  • CVE-2022-46391MedDec 4, 2022
    risk 0.00cvss 6.1epss 0.01

    AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.

  • CVE-2022-4172MedNov 29, 2022
    risk 0.00cvss 6.5epss 0.00

    An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory…

  • CVE-2022-45934HigNov 27, 2022
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.

  • CVE-2022-45152CriNov 25, 2022
    risk 0.00cvss 9.1epss 0.01

    A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An…

  • CVE-2022-39346LowNov 25, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud…

  • CVE-2022-4141HigNov 25, 2022
    risk 0.00cvss 7.8epss 0.00

    Heap based buffer overflow in vim/vim 9.0.0946 and below by allowing an attacker to CTRL-W gf in the expression used in the RHS of the substitute command.

Page 224 of 268