VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2022-0629HigFeb 17, 2022
    risk 0.00cvss 7.8epss 0.02

    Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-25258MedFeb 16, 2022
    risk 0.00cvss 4.6epss 0.01

    An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory…

  • CVE-2022-0559CriFeb 16, 2022
    risk 0.00cvss 9.8epss 0.01

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-25235CriFeb 16, 2022
    risk 0.00cvss 9.8epss 0.05

    xmltok_impl.c in Expat (aka libexpat) before 2.4.5 lacks certain validation of encoding, such as checks for whether a UTF-8 character is valid in a certain context.

  • CVE-2022-21698HigFeb 15, 2022
    risk 0.00cvss 7.5epss 0.06

    client_golang is the instrumentation library for Go applications in Prometheus, and the promhttp package in client_golang provides tooling around HTTP servers and clients. In client_golang prior to version 1.11.1, HTTP server is susceptible to a Denial of Service through…

  • CVE-2022-0571MedFeb 14, 2022
    risk 0.00cvss 6.1epss 0.01

    Cross-site Scripting (XSS) - Reflected in GitHub repository phoronix-test-suite/phoronix-test-suite prior to 10.8.2.

  • CVE-2022-0562MedFeb 11, 2022
    risk 0.00cvss 5.5epss 0.01

    Null source pointer passed as an argument to memcpy() function within TIFFReadDirectory() in tif_dirread.c in libtiff versions from 4.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, a fix is available with commit…

  • CVE-2022-0561MedFeb 11, 2022
    risk 0.00cvss 5.5epss 0.01

    Null source pointer passed as an argument to memcpy() function within TIFFFetchStripThing() in tif_dirread.c in libtiff versions from 3.9.0 to 4.3.0 could lead to Denial of Service via crafted TIFF file. For users that compile libtiff from sources, the fix is available with…

  • CVE-2022-24958HigFeb 11, 2022
    risk 0.00cvss 7.8epss 0.00

    drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev->buf release.

  • CVE-2022-0554HigFeb 10, 2022
    risk 0.00cvss 7.8epss 0.02

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.

  • CVE-2022-21713MedFeb 8, 2022
    risk 0.00cvss 4.3epss 0.01

    Grafana is an open-source platform for monitoring and observability. Affected versions of Grafana expose multiple API endpoints which do not properly handle user authorization. `/teams/:teamId` will allow an authenticated attacker to view unintended data by querying for the…

  • CVE-2022-21703MedFeb 8, 2022
    risk 0.00cvss 6.3epss 0.02

    Grafana is an open-source platform for monitoring and observability. Affected versions are subject to a cross site request forgery vulnerability which allows attackers to elevate their privileges by mounting cross-origin attacks against authenticated high-privilege Grafana users…

  • CVE-2022-0523HigFeb 8, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-0522HigFeb 8, 2022
    risk 0.00cvss 7.1epss 0.01

    Access of Memory Location Before Start of Buffer in NPM radare2.js prior to 5.6.2.

  • CVE-2022-0521HigFeb 8, 2022
    risk 0.00cvss 7.1epss 0.01

    Access of Memory Location After End of Buffer in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-0520HigFeb 8, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in NPM radare2.js prior to 5.6.2.

  • CVE-2022-0519HigFeb 8, 2022
    risk 0.00cvss 7.1epss 0.01

    Buffer Access with Incorrect Length Value in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-0518HigFeb 8, 2022
    risk 0.00cvss 7.1epss 0.01

    Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.6.2.

  • CVE-2022-23613HigFeb 7, 2022
    risk 0.00cvss 7.8epss 0.00

    xrdp is an open source remote desktop protocol (RDP) server. In affected versions an integer underflow leading to a heap overflow in the sesman server allows any unauthenticated attacker which is able to locally access a sesman server to execute code as root. This vulnerability…

  • CVE-2022-0443HigFeb 2, 2022
    risk 0.00cvss 7.8epss 0.01

    Use After Free in GitHub repository vim/vim prior to 8.2.

Page 236 of 268