Fedora
CVEs (5,359)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-3550 | Med | 0.00 | 5.5 | 0.02 | Oct 17, 2022 | A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of… | ||
| CVE-2022-42722 | Med | 0.00 | 5.5 | 0.01 | Oct 14, 2022 | In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices. | ||
| CVE-2022-42721 | Med | 0.00 | 5.5 | 0.01 | Oct 14, 2022 | A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code. | ||
| CVE-2022-42720 | Hig | 0.00 | 7.8 | 0.01 | Oct 14, 2022 | Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code. | ||
| CVE-2022-41674 | Hig | 0.00 | 8.1 | 0.04 | Oct 14, 2022 | An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c. | ||
| CVE-2022-42719 | Hig | 0.00 | 8.8 | 0.01 | Oct 13, 2022 | A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code. | ||
| CVE-2022-41556 | Hig | 0.00 | 7.5 | 0.03 | Oct 6, 2022 | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of… | ||
| CVE-2022-3352 | Hig | 0.00 | 7.8 | 0.00 | Sep 29, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0614. | ||
| CVE-2022-39264 | Hig | 0.00 | 8.6 | 0.01 | Sep 28, 2022 | nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a… | ||
| CVE-2022-3324 | Hig | 0.00 | 7.8 | 0.01 | Sep 27, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598. | ||
| CVE-2022-3297 | Hig | 0.00 | 7.8 | 0.01 | Sep 25, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0579. | ||
| CVE-2022-3296 | Hig | 0.00 | 7.8 | 0.01 | Sep 25, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577. | ||
| CVE-2022-3278 | Med | 0.00 | 5.5 | 0.01 | Sep 23, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552. | ||
| CVE-2022-41322 | Hig | 0.00 | 7.8 | 0.00 | Sep 23, 2022 | In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. | ||
| CVE-2022-3256 | Hig | 0.00 | 7.8 | 0.00 | Sep 22, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0530. | ||
| CVE-2022-3213 | Med | 0.00 | 5.5 | 0.00 | Sep 19, 2022 | A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service. | ||
| CVE-2022-3235 | Hig | 0.00 | 7.8 | 0.00 | Sep 18, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0490. | ||
| CVE-2022-40768 | Med | 0.00 | 5.5 | 0.00 | Sep 18, 2022 | drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. | ||
| CVE-2022-3234 | Hig | 0.00 | 7.8 | 0.01 | Sep 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483. | ||
| CVE-2022-39209 | Hig | 0.00 | 7.5 | 0.02 | Sep 15, 2022 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.… |
- risk 0.00cvss 5.5epss 0.02
A vulnerability classified as critical was found in X.org Server. Affected by this vulnerability is the function _GetCountedString of the file xkb/xkb.c. The manipulation leads to buffer overflow. It is recommended to apply a patch to fix this issue. The associated identifier of…
- risk 0.00cvss 5.5epss 0.01
In the Linux kernel 5.8 through 5.19.x before 5.19.16, local attackers able to inject WLAN frames into the mac80211 stack could cause a NULL pointer dereference denial-of-service attack against the beacon protection of P2P devices.
- risk 0.00cvss 5.5epss 0.01
A list management bug in BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to corrupt a linked list and, in turn, potentially execute code.
- risk 0.00cvss 7.8epss 0.01
Various refcounting bugs in the multi-BSS handling in the mac80211 stack in the Linux kernel 5.1 through 5.19.x before 5.19.16 could be used by local attackers (able to inject WLAN frames) to trigger use-after-free conditions to potentially execute code.
- risk 0.00cvss 8.1epss 0.04
An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
- risk 0.00cvss 8.8epss 0.01
A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.
- risk 0.00cvss 7.5epss 0.03
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of…
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0614.
- risk 0.00cvss 8.6epss 0.01
nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a…
- risk 0.00cvss 7.8epss 0.01
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0598.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0579.
- risk 0.00cvss 7.8epss 0.01
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0577.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.
- risk 0.00cvss 7.8epss 0.00
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0530.
- risk 0.00cvss 5.5epss 0.00
A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0490.
- risk 0.00cvss 5.5epss 0.00
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
- risk 0.00cvss 7.5epss 0.02
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.…
Page 226 of 268