VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-45873MedNov 23, 2022
    risk 0.00cvss 5.5epss 0.00

    systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put…

  • CVE-2022-44789HigNov 23, 2022
    risk 0.00cvss 8.8epss 0.02

    A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

  • CVE-2022-45866MedNov 23, 2022
    risk 0.00cvss 5.3epss 0.01

    qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file.

  • CVE-2022-45151MedNov 23, 2022
    risk 0.00cvss 5.4epss 0.01

    The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable…

  • CVE-2022-45150MedNov 23, 2022
    risk 0.00cvss 6.1epss 0.01

    A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in…

  • CVE-2022-45149MedNov 23, 2022
    risk 0.00cvss 5.4epss 0.00

    A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the…

  • CVE-2022-39319MedNov 16, 2022
    risk 0.00cvss 4.6epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in the `urbdrc` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has…

  • CVE-2022-39318MedNov 16, 2022
    risk 0.00cvss 4.8epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input validation in `urbdrc` channel. A malicious server can trick a FreeRDP based client to crash with division by zero. This issue has been addressed in version 2.9.0. All…

  • CVE-2022-41877MedNov 16, 2022
    risk 0.00cvss 4.6epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing input length validation in `drive` channel. A malicious server can trick a FreeRDP based client to read out of bound data and send it back to the server. This issue has been…

  • CVE-2022-39347LowNov 16, 2022
    risk 0.00cvss 2.6epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. Affected versions of FreeRDP are missing path canonicalization and base path check for `drive` channel. A malicious server can trick a FreeRDP based client to read files outside the shared directory. This issue has…

  • CVE-2022-39316MedNov 16, 2022
    risk 0.00cvss 4.8epss 0.01

    FreeRDP is a free remote desktop protocol library and clients. In affected versions there is an out of bound read in ZGFX decoder component of FreeRDP. A malicious server can trick a FreeRDP based client to read out of bound data and try to decode it likely resulting in a crash.…

  • CVE-2022-45062CriNov 9, 2022
    risk 0.00cvss 9.8epss 0.01

    In Xfce xfce4-settings before 4.16.4 and 4.17.x before 4.17.1, there is an argument injection vulnerability in xfce4-mime-helper.

  • CVE-2022-3821MedNov 8, 2022
    risk 0.00cvss 5.5epss 0.00

    An off-by-one Error issue was discovered in Systemd in format_timespan() function of time-util.c. An attacker could supply specific values for time and accuracy that leads to buffer overrun in format_timespan(), leading to a Denial of Service.

  • CVE-2022-3705MedOct 26, 2022
    risk 0.00cvss 5.0epss 0.01

    A vulnerability was found in vim and classified as problematic. Affected by this issue is the function qf_update_buffer of the file quickfix.c of the component autocmd Handler. The manipulation leads to use after free. The attack may be launched remotely. Upgrading to version…

  • CVE-2022-43680HigOct 24, 2022
    risk 0.00cvss 7.5epss 0.02

    In libexpat through 2.4.9, there is a use-after free caused by overeager destruction of a shared DTD in XML_ExternalEntityParserCreate in out-of-memory situations.

  • CVE-2021-46848CriOct 24, 2022
    risk 0.00cvss 9.1epss 0.02

    GNU Libtasn1 before 4.19.0 has an ETYPE_OK off-by-one array size check that affects asn1_encode_simple_der.

  • CVE-2022-3640MedOct 21, 2022
    risk 0.00cvss 5.5epss 0.01

    A vulnerability, which was classified as critical, was found in Linux Kernel. Affected is the function l2cap_conn_del of the file net/bluetooth/l2cap_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this…

  • CVE-2022-41751HigOct 17, 2022
    risk 0.00cvss 7.8epss 0.00

    Jhead 3.06.0.1 allows attackers to execute arbitrary OS commands by placing them in a JPEG filename and then using the regeneration -rgt50 option.

  • CVE-2022-3165MedOct 17, 2022
    risk 0.00cvss 6.5epss 0.01

    An integer underflow issue was found in the QEMU VNC server while processing ClientCutText messages in the extended format. A malicious client could use this flaw to make QEMU unresponsive by sending a specially crafted payload message, resulting in a denial of service.

  • CVE-2022-3551LowOct 17, 2022
    risk 0.00cvss 3.5epss 0.02

    A vulnerability, which was classified as problematic, has been found in X.org Server. Affected by this issue is the function ProcXkbGetKbdByName of the file xkb/xkb.c. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. The identifier of…

Page 225 of 268