Fedora
CVEs (5,358)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0417 | Hig | 0.00 | 7.8 | 0.02 | Feb 1, 2022 | Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0419 | Med | 0.00 | 5.5 | 0.01 | Feb 1, 2022 | NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0. | ||
| CVE-2022-0413 | Hig | 0.00 | 7.8 | 0.01 | Jan 30, 2022 | Use After Free in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-0408 | Hig | 0.00 | 7.8 | 0.02 | Jan 30, 2022 | Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-24122 | Hig | 0.00 | 7.8 | 0.01 | Jan 29, 2022 | kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace. | ||
| CVE-2022-0393 | Hig | 0.00 | 7.1 | 0.01 | Jan 28, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 8.2. | ||
| CVE-2022-23990 | Hig | 0.00 | 7.5 | 0.04 | Jan 26, 2022 | Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function. | ||
| CVE-2022-21658 | Hig | 0.00 | 7.3 | 0.01 | Jan 20, 2022 | Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling… | ||
| CVE-2022-0238 | Med | 0.00 | 4.3 | 0.01 | Jan 16, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-46022 | Med | 0.00 | 5.5 | 0.01 | Jan 14, 2022 | An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. | ||
| CVE-2021-46019 | Med | 0.00 | 5.5 | 0.01 | Jan 14, 2022 | An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash. | ||
| CVE-2022-23222 | Hig | 0.00 | 7.8 | 0.02 | Jan 14, 2022 | kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types. | ||
| CVE-2022-21682 | Hig | 0.00 | 7.7 | 0.02 | Jan 13, 2022 | Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that… | ||
| CVE-2022-0197 | Hig | 0.00 | 8.8 | 0.01 | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2022-0196 | Hig | 0.00 | 8.8 | 0.01 | Jan 13, 2022 | phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF) | ||
| CVE-2021-43860 | Hig | 0.00 | 8.2 | 0.01 | Jan 12, 2022 | Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the… | ||
| CVE-2022-0173 | Med | 0.00 | 5.5 | 0.01 | Jan 11, 2022 | radare2 is vulnerable to Out-of-bounds Read | ||
| CVE-2022-0158 | Low | 0.00 | 3.3 | 0.02 | Jan 10, 2022 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2022-0157 | Med | 0.00 | 5.4 | 0.01 | Jan 10, 2022 | phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | ||
| CVE-2022-0156 | Med | 0.00 | 5.5 | 0.02 | Jan 10, 2022 | vim is vulnerable to Use After Free |
- risk 0.00cvss 7.8epss 0.02
Heap-based Buffer Overflow GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository radareorg/radare2 prior to 5.6.0.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.02
Stack-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.8epss 0.01
kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
- risk 0.00cvss 7.1epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 8.2.
- risk 0.00cvss 7.5epss 0.04
Expat (aka libexpat) before 2.4.4 has an integer overflow in the doProlog function.
- risk 0.00cvss 7.3epss 0.01
Rust is a multi-paradigm, general-purpose programming language designed for performance and safety, especially safe concurrency. The Rust Security Response WG was notified that the `std::fs::remove_dir_all` standard library function is vulnerable a race condition enabling…
- risk 0.00cvss 4.3epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 5.5epss 0.01
An Use-After-Free vulnerability in rec_mset_elem_destroy() at rec-mset.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
- risk 0.00cvss 5.5epss 0.01
An untrusted pointer dereference in rec_db_destroy() at rec-db.c of GNU Recutils v1.8.90 can lead to a segmentation fault or application crash.
- risk 0.00cvss 7.8epss 0.02
kernel/bpf/verifier.c in the Linux kernel through 5.15.14 allows local users to gain privileges because of the availability of pointer arithmetic via certain *_OR_NULL pointer types.
- risk 0.00cvss 7.7epss 0.02
Flatpak is a Linux application sandboxing and distribution framework. A path traversal vulnerability affects versions of Flatpak prior to 1.12.3 and 1.10.6. flatpak-builder applies `finish-args` last in the build. At this point the build directory will have the full access that…
- risk 0.00cvss 8.8epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 8.8epss 0.01
phoronix-test-suite is vulnerable to Cross-Site Request Forgery (CSRF)
- risk 0.00cvss 8.2epss 0.01
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.12.3 and 1.10.6, Flatpak doesn't properly validate that the permissions displayed to the user for an app at install time match the actual permissions granted to the app at runtime, in the…
- risk 0.00cvss 5.5epss 0.01
radare2 is vulnerable to Out-of-bounds Read
- risk 0.00cvss 3.3epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 5.4epss 0.01
phoronix-test-suite is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
- risk 0.00cvss 5.5epss 0.02
vim is vulnerable to Use After Free
Page 237 of 268