VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2021-3640HigMar 3, 2022
    risk 0.00cvss 7.0epss 0.00

    A flaw use-after-free in function sco_sock_sendmsg() of the Linux kernel HCI subsystem was found in the way user calls ioct UFFDIO_REGISTER or other way triggers race condition of the call sco_conn_del() together with the call sco_sock_sendmsg() with the expected controllable…

  • CVE-2021-4002MedMar 3, 2022
    risk 0.00cvss 4.4epss 0.01

    A memory leak flaw in the Linux kernel's hugetlbfs memory usage was found in the way the user maps some regions of memory twice using shmget() which are aligned to PUD alignment with the fault of some of the memory pages. A local user could use this flaw to get unauthorized…

  • CVE-2021-3623MedMar 2, 2022
    risk 0.00cvss 6.1epss 0.00

    A flaw was found in libtpms. The flaw can be triggered by specially-crafted TPM 2 command packets containing illegal values and may lead to an out-of-bounds access when the volatile state of the TPM 2 is marshalled/written or unmarshalled/read. The highest threat from this…

  • CVE-2022-23308HigFeb 26, 2022
    risk 0.00cvss 7.5epss 0.06

    valid.c in libxml2 before 2.9.13 has a use-after-free of ID and IDREF attributes.

  • CVE-2021-3700MedFeb 24, 2022
    risk 0.00cvss 6.4epss 0.00

    A use-after-free vulnerability was found in usbredir in versions prior to 0.11.0 in the usbredirparser_serialize() in usbredirparser/usbredirparser.c. This issue occurs when serializing large amounts of buffered write data in the case of a slow or blocked destination.

  • CVE-2021-3610HigFeb 24, 2022
    risk 0.00cvss 7.5epss 0.03

    A heap-based buffer overflow vulnerability was found in ImageMagick in versions prior to 7.0.11-14 in ReadTIFFImage() in coders/tiff.c. This issue is due to an incorrect setting of the pixel array size, which can lead to a crash and segmentation fault.

  • CVE-2019-25058HigFeb 24, 2022
    risk 0.00cvss 7.8epss 0.00

    An issue was discovered in USBGuard before 1.1.0. On systems with the usbguard-dbus daemon running, an unprivileged user could make USBGuard allow all USB devices to be connected in the future.

  • CVE-2022-0695MedFeb 24, 2022
    risk 0.00cvss 5.5epss 0.01

    Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-0476MedFeb 23, 2022
    risk 0.00cvss 5.5epss 0.01

    Denial of Service in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-0729HigFeb 23, 2022
    risk 0.00cvss 8.8epss 0.02

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4440.

  • CVE-2022-0713HigFeb 22, 2022
    risk 0.00cvss 7.1epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-0712MedFeb 22, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-0676HigFeb 22, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.4.

  • CVE-2022-0696MedFeb 21, 2022
    risk 0.00cvss 5.5epss 0.01

    NULL Pointer Dereference in GitHub repository vim/vim prior to 8.2.4428.

  • CVE-2022-0685HigFeb 20, 2022
    risk 0.00cvss 7.8epss 0.02

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4418.

  • CVE-2021-45082HigFeb 19, 2022
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in Cobbler before 3.3.1. In the templar.py file, the function check_for_invalid_imports can allow Cheetah code to import Python modules via the "#from MODULE import" substring. (Only lines beginning with #import are blocked.)

  • CVE-2022-23645MedFeb 18, 2022
    risk 0.00cvss 6.2epss 0.00

    swtpm is a libtpms-based TPM emulator with socket, character device, and Linux CUSE interface. Versions prior to 0.5.3, 0.6.2, and 0.7.1 are vulnerable to out-of-bounds read. A specially crafted header of swtpm's state, where the blobheader's hdrsize indicator has an invalid…

  • CVE-2022-25315CriFeb 18, 2022
    risk 0.00cvss 9.8epss 0.05

    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in storeRawNames.

  • CVE-2022-25314HigFeb 18, 2022
    risk 0.00cvss 7.5epss 0.05

    In Expat (aka libexpat) before 2.4.5, there is an integer overflow in copyString.

  • CVE-2022-25313MedFeb 18, 2022
    risk 0.00cvss 6.5epss 0.03

    In Expat (aka libexpat) before 2.4.5, an attacker can trigger stack exhaustion in build_model via a large nesting depth in the DTD element.

Page 235 of 268