Fedora
CVEs (5,358)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46142 | Med | 0.00 | 5.5 | 0.01 | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax. | ||
| CVE-2021-46141 | Med | 0.00 | 5.5 | 0.01 | Jan 6, 2022 | An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner. | ||
| CVE-2021-45943 | Med | 0.00 | 5.5 | 0.01 | Jan 1, 2022 | GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment). | ||
| CVE-2021-45942 | Med | 0.00 | 5.5 | 0.02 | Jan 1, 2022 | OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable. | ||
| CVE-2021-45931 | Med | 0.00 | 6.5 | 0.02 | Jan 1, 2022 | HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy). | ||
| CVE-2021-45930 | Med | 0.00 | 5.5 | 0.01 | Jan 1, 2022 | Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect). | ||
| CVE-2021-45958 | Med | 0.00 | 5.5 | 0.02 | Jan 1, 2022 | UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation. | ||
| CVE-2021-4193 | Med | 0.00 | 5.5 | 0.02 | Dec 31, 2021 | vim is vulnerable to Out-of-bounds Read | ||
| CVE-2021-4192 | Hig | 0.00 | 7.8 | 0.02 | Dec 31, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4187 | Hig | 0.00 | 7.8 | 0.02 | Dec 29, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4173 | Hig | 0.00 | 7.8 | 0.02 | Dec 27, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-4166 | Hig | 0.00 | 7.1 | 0.02 | Dec 25, 2021 | vim is vulnerable to Out-of-bounds Read | ||
| CVE-2021-3622 | Med | 0.00 | 4.3 | 0.05 | Dec 23, 2021 | A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to… | ||
| CVE-2021-45469 | Hig | 0.00 | 7.8 | 0.01 | Dec 23, 2021 | In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry. | ||
| CVE-2021-45463 | Hig | 0.00 | 7.8 | 0.01 | Dec 23, 2021 | load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before… | ||
| CVE-2021-4136 | Hig | 0.00 | 7.8 | 0.02 | Dec 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-44847 | Cri | 0.00 | 9.8 | 0.04 | Dec 13, 2021 | A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially… | ||
| CVE-2021-4048 | Cri | 0.00 | 9.1 | 0.03 | Dec 8, 2021 | An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or… | ||
| CVE-2021-4069 | Hig | 0.00 | 7.8 | 0.01 | Dec 6, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-3984 | Hig | 0.00 | 7.8 | 0.01 | Dec 1, 2021 | vim is vulnerable to Heap-based Buffer Overflow |
- risk 0.00cvss 5.5epss 0.01
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriNormalizeSyntax.
- risk 0.00cvss 5.5epss 0.01
An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.
- risk 0.00cvss 5.5epss 0.01
GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).
- risk 0.00cvss 5.5epss 0.02
OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.
- risk 0.00cvss 6.5epss 0.02
HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).
- risk 0.00cvss 5.5epss 0.01
Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).
- risk 0.00cvss 5.5epss 0.02
UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.
- risk 0.00cvss 5.5epss 0.02
vim is vulnerable to Out-of-bounds Read
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Use After Free
- risk 0.00cvss 7.1epss 0.02
vim is vulnerable to Out-of-bounds Read
- risk 0.00cvss 4.3epss 0.05
A flaw was found in the hivex library. This flaw allows an attacker to input a specially crafted Windows Registry (hive) file, which would cause hivex to recursively call the _get_children() function, leading to a stack overflow. The highest threat from this vulnerability is to…
- risk 0.00cvss 7.8epss 0.01
In __f2fs_setxattr in fs/f2fs/xattr.c in the Linux kernel through 5.15.11, there is an out-of-bounds memory access when an inode has an invalid last xattr entry.
- risk 0.00cvss 7.8epss 0.01
load_cache in GEGL before 0.4.34 allows shell expansion when a pathname in a constructed command line is not escaped or filtered. This is caused by use of the system library function for execution of the ImageMagick convert fallback in magick-load. NOTE: GEGL releases before…
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 9.8epss 0.04
A stack-based buffer overflow in handle_request function in DHT.c in toxcore 0.1.9 through 0.1.11 and 0.2.0 through 0.2.12 (caused by an improper length calculation during the handling of received network packets) allows remote attackers to crash the process or potentially…
- risk 0.00cvss 9.1epss 0.03
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or…
- risk 0.00cvss 7.8epss 0.01
vim is vulnerable to Use After Free
- risk 0.00cvss 7.8epss 0.01
vim is vulnerable to Heap-based Buffer Overflow
Page 238 of 268