Fedora
CVEs (5,358)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3996 | Med | 0.00 | 5.5 | 0.01 | Aug 23, 2022 | A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like… | ||
| CVE-2021-3995 | Med | 0.00 | 5.5 | 0.01 | Aug 23, 2022 | A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a… | ||
| CVE-2021-3975 | Med | 0.00 | 6.5 | 0.02 | Aug 23, 2022 | A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the… | ||
| CVE-2022-2946 | Hig | 0.00 | 7.8 | 0.01 | Aug 23, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0246. | ||
| CVE-2021-3905 | Hig | 0.00 | 7.5 | 0.02 | Aug 23, 2022 | A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments. | ||
| CVE-2021-3839 | Hig | 0.00 | 7.5 | 0.02 | Aug 23, 2022 | A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability. | ||
| CVE-2021-3670 | Med | 0.00 | 6.5 | 0.02 | Aug 23, 2022 | MaxQueryDuration not honoured in Samba AD DC LDAP | ||
| CVE-2021-31566 | Hig | 0.00 | 7.8 | 0.00 | Aug 23, 2022 | An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to… | ||
| CVE-2021-23177 | Hig | 0.00 | 7.8 | 0.00 | Aug 23, 2022 | An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local… | ||
| CVE-2022-25761 | Hig | 0.00 | 7.5 | 0.01 | Aug 23, 2022 | The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this… | ||
| CVE-2021-28861 | Hig | 0.00 | 7.4 | 0.03 | Aug 23, 2022 | Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html… | ||
| CVE-2022-2923 | Med | 0.00 | 5.5 | 0.01 | Aug 22, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240. | ||
| CVE-2021-3659 | Med | 0.00 | 5.5 | 0.00 | Aug 22, 2022 | A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system… | ||
| CVE-2022-2889 | Hig | 0.00 | 7.8 | 0.01 | Aug 19, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0225. | ||
| CVE-2022-2862 | Hig | 0.00 | 7.8 | 0.01 | Aug 17, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0221. | ||
| CVE-2022-2849 | Hig | 0.00 | 7.8 | 0.00 | Aug 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220. | ||
| CVE-2022-2845 | Hig | 0.00 | 7.8 | 0.01 | Aug 17, 2022 | Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218. | ||
| CVE-2022-2817 | Hig | 0.00 | 7.8 | 0.01 | Aug 15, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0213. | ||
| CVE-2022-2816 | Hig | 0.00 | 7.8 | 0.01 | Aug 15, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212. | ||
| CVE-2022-2819 | Hig | 0.00 | 7.8 | 0.01 | Aug 15, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211. |
- risk 0.00cvss 5.5epss 0.01
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows a local user on a vulnerable system to unmount other users' filesystems that are either world-writable themselves (like…
- risk 0.00cvss 5.5epss 0.01
A logic error was found in the libmount library of util-linux in the function that allows an unprivileged user to unmount a FUSE filesystem. This flaw allows an unprivileged local attacker to unmount FUSE filesystems that belong to certain other users who have a UID that is a…
- risk 0.00cvss 6.5epss 0.02
A use-after-free flaw was found in libvirt. The qemuMonitorUnregister() function in qemuProcessHandleMonitorEOF is called using multiple threads without being adequately protected by a monitor lock. This flaw could be triggered by the virConnectGetAllDomainStats API when the…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0246.
- risk 0.00cvss 7.5epss 0.02
A memory leak was found in Open vSwitch (OVS) during userspace IP fragmentation processing. An attacker could use this flaw to potentially exhaust available memory by keeping sending packet fragments.
- risk 0.00cvss 7.5epss 0.02
A flaw was found in the vhost library in DPDK. Function vhost_user_set_inflight_fd() does not validate `msg->payload.inflight.num_queues`, possibly causing out-of-bounds memory read/write. Any software using DPDK vhost library may crash as a result of this vulnerability.
- risk 0.00cvss 6.5epss 0.02
MaxQueryDuration not honoured in Samba AD DC LDAP
- risk 0.00cvss 7.8epss 0.00
An improper link resolution flaw can occur while extracting an archive leading to changing modes, times, access control lists, and flags of a file outside of the archive. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to…
- risk 0.00cvss 7.8epss 0.00
An improper link resolution flaw while extracting an archive can lead to changing the access control list (ACL) of the target of the link. An attacker may provide a malicious archive to a victim user, who would trigger this flaw when trying to extract the archive. A local…
- risk 0.00cvss 7.5epss 0.01
The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this…
- risk 0.00cvss 7.4epss 0.03
Python 3.x through 3.10 has an open redirection vulnerability in lib/http/server.py due to no protection against multiple (/) at the beginning of URI path which may leads to information disclosure. NOTE: this is disputed by a third party because the http.server.html…
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240.
- risk 0.00cvss 5.5epss 0.00
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way the user closes the LR-WPAN connection. This flaw allows a local user to crash the system. The highest threat from this vulnerability is to system…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0225.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0221.
- risk 0.00cvss 7.8epss 0.00
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0220.
- risk 0.00cvss 7.8epss 0.01
Improper Validation of Specified Quantity in Input in GitHub repository vim/vim prior to 9.0.0218.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0213.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
Page 228 of 268