Fedora
CVEs (5,358)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-42781 | Med | 0.00 | 5.3 | 0.03 | Apr 18, 2022 | Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library. | ||
| CVE-2021-42780 | Med | 0.00 | 5.3 | 0.02 | Apr 18, 2022 | A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library. | ||
| CVE-2021-42779 | Med | 0.00 | 5.3 | 0.02 | Apr 18, 2022 | A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid. | ||
| CVE-2021-42778 | Med | 0.00 | 5.3 | 0.02 | Apr 18, 2022 | A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo. | ||
| CVE-2022-1381 | Hig | 0.00 | 7.8 | 0.03 | Apr 18, 2022 | global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution | ||
| CVE-2022-1231 | Med | 0.00 | 6.1 | 0.02 | Apr 15, 2022 | XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example… | ||
| CVE-2022-28048 | Hig | 0.00 | 8.8 | 0.02 | Apr 15, 2022 | STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac. | ||
| CVE-2022-28042 | Hig | 0.00 | 8.8 | 0.02 | Apr 15, 2022 | stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode. | ||
| CVE-2022-28041 | Med | 0.00 | 6.5 | 0.02 | Apr 15, 2022 | stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors. | ||
| CVE-2022-1328 | Med | 0.00 | 4.3 | 0.02 | Apr 14, 2022 | Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line | ||
| CVE-2022-28805 | Cri | 0.00 | 9.1 | 0.03 | Apr 8, 2022 | singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code. | ||
| CVE-2022-28796 | Hig | 0.00 | 7.0 | 0.00 | Apr 8, 2022 | jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition. | ||
| CVE-2022-27650 | Hig | 0.00 | 7.5 | 0.01 | Apr 4, 2022 | A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker… | ||
| CVE-2022-28390 | Hig | 0.00 | 7.8 | 0.00 | Apr 3, 2022 | ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free. | ||
| CVE-2022-28389 | Med | 0.00 | 5.5 | 0.00 | Apr 3, 2022 | mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free. | ||
| CVE-2022-28388 | Med | 0.00 | 5.5 | 0.00 | Apr 3, 2022 | usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free. | ||
| CVE-2022-1160 | Hig | 0.00 | 7.8 | 0.01 | Mar 30, 2022 | heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647. | ||
| CVE-2022-1154 | Hig | 0.00 | 7.8 | 0.01 | Mar 30, 2022 | Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646. | ||
| CVE-2022-27920 | Med | 0.00 | 6.1 | 0.01 | Mar 25, 2022 | libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0. | ||
| CVE-2022-0500 | Hig | 0.00 | 7.8 | 0.00 | Mar 25, 2022 | A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system. |
- risk 0.00cvss 5.3epss 0.03
Heap buffer overflow issues were found in Opensc before version 0.22.0 in pkcs15-oberthur.c that could potentially crash programs using the library.
- risk 0.00cvss 5.3epss 0.02
A use after return issue was found in Opensc before version 0.22.0 in insert_pin function that could potentially crash programs using the library.
- risk 0.00cvss 5.3epss 0.02
A heap use after free issue was found in Opensc before version 0.22.0 in sc_file_valid.
- risk 0.00cvss 5.3epss 0.02
A heap double free issue was found in Opensc before version 0.22.0 in sc_pkcs15_free_tokeninfo.
- risk 0.00cvss 7.8epss 0.03
global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution
- risk 0.00cvss 6.1epss 0.02
XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example…
- risk 0.00cvss 8.8epss 0.02
STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.
- risk 0.00cvss 8.8epss 0.02
stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.
- risk 0.00cvss 6.5epss 0.02
stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.
- risk 0.00cvss 4.3epss 0.02
Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line
- risk 0.00cvss 9.1epss 0.03
singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
- risk 0.00cvss 7.0epss 0.00
jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
- risk 0.00cvss 7.5epss 0.01
A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker…
- risk 0.00cvss 7.8epss 0.00
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.
- risk 0.00cvss 5.5epss 0.00
mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
- risk 0.00cvss 5.5epss 0.00
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
- risk 0.00cvss 7.8epss 0.01
heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.
- risk 0.00cvss 7.8epss 0.01
Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.
- risk 0.00cvss 6.1epss 0.01
libkiwix 10.0.0 and 10.0.1 allows XSS in the built-in webserver functionality via the search suggestions URL parameter. This is fixed in 10.1.0.
- risk 0.00cvss 7.8epss 0.00
A flaw was found in unrestricted eBPF usage by the BPF_BTF_LOAD, leading to a possible out-of-bounds memory write in the Linux kernel’s BPF subsystem due to the way a user loads BTF. This flaw allows a local user to crash or escalate their privileges on the system.
Page 233 of 268