Fedora
CVEs (5,358)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-44225 | Med | 0.00 | 5.4 | 0.01 | Nov 26, 2021 | In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable… | ||
| CVE-2021-3973 | Hig | 0.00 | 7.8 | 0.02 | Nov 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3968 | Hig | 0.00 | 8.0 | 0.02 | Nov 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3974 | Hig | 0.00 | 7.8 | 0.01 | Nov 19, 2021 | vim is vulnerable to Use After Free | ||
| CVE-2021-44025 | Med | 0.00 | 6.1 | 0.01 | Nov 19, 2021 | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message. | ||
| CVE-2021-43976 | Med | 0.00 | 4.6 | 0.01 | Nov 17, 2021 | In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic). | ||
| CVE-2021-43975 | Med | 0.00 | 6.7 | 0.01 | Nov 17, 2021 | In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value. | ||
| CVE-2021-43616 | Cri | 0.00 | 9.0 | 0.03 | Nov 13, 2021 | The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was… | ||
| CVE-2021-3928 | Hig | 0.00 | 7.8 | 0.01 | Nov 5, 2021 | vim is vulnerable to Use of Uninitialized Variable | ||
| CVE-2021-3927 | Hig | 0.00 | 7.8 | 0.02 | Nov 5, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3756 | Cri | 0.00 | 9.8 | 0.01 | Oct 29, 2021 | libmysofa is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-3903 | Hig | 0.00 | 7.8 | 0.01 | Oct 27, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-42716 | Hig | 0.00 | 7.1 | 0.01 | Oct 21, 2021 | An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service… | ||
| CVE-2021-42715 | Med | 0.00 | 5.5 | 0.01 | Oct 21, 2021 | An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted… | ||
| CVE-2021-42327 | Med | 0.00 | 6.7 | 0.01 | Oct 21, 2021 | dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no checks on size within… | ||
| CVE-2021-42739 | Med | 0.00 | 6.7 | 0.00 | Oct 20, 2021 | The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking. | ||
| CVE-2021-3872 | Hig | 0.00 | 7.8 | 0.01 | Oct 19, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-38562 | Hig | 0.00 | 7.5 | 0.02 | Oct 18, 2021 | Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm. | ||
| CVE-2021-3875 | Med | 0.00 | 5.5 | 0.02 | Oct 15, 2021 | vim is vulnerable to Heap-based Buffer Overflow | ||
| CVE-2021-41133 | Hig | 0.00 | 8.8 | 0.00 | Oct 8, 2021 | Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other… |
- risk 0.00cvss 5.4epss 0.01
In Keepalived through 2.2.4, the D-Bus policy does not sufficiently restrict the message destination, allowing any user to inspect and manipulate any property. This leads to access-control bypass in some situations in which an unrelated D-Bus system service has a settable…
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 8.0epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 7.8epss 0.01
vim is vulnerable to Use After Free
- risk 0.00cvss 6.1epss 0.01
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to XSS in handling an attachment's filename extension when displaying a MIME type warning message.
- risk 0.00cvss 4.6epss 0.01
In the Linux kernel through 5.15.2, mwifiex_usb_recv in drivers/net/wireless/marvell/mwifiex/usb.c allows an attacker (who can connect a crafted USB device) to cause a denial of service (skb_over_panic).
- risk 0.00cvss 6.7epss 0.01
In the Linux kernel through 5.15.2, hw_atl_utils_fw_rpc_wait in drivers/net/ethernet/aquantia/atlantic/hw_atl/hw_atl_utils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value.
- risk 0.00cvss 9.0epss 0.03
The npm ci command in npm 7.x and 8.x through 8.1.3 proceeds with an installation even if dependency information in package-lock.json differs from package.json. This behavior is inconsistent with the documentation, and makes it easier for attackers to install malware that was…
- risk 0.00cvss 7.8epss 0.01
vim is vulnerable to Use of Uninitialized Variable
- risk 0.00cvss 7.8epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 9.8epss 0.01
libmysofa is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 7.8epss 0.01
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 7.1epss 0.01
An issue was discovered in stb stb_image.h 2.27. The PNM loader incorrectly interpreted 16-bit PGM files as 8-bit when converting to RGBA, leading to a buffer overflow when later reinterpreting the result as a 16-bit buffer. An attacker could potentially have crashed a service…
- risk 0.00cvss 5.5epss 0.01
An issue was discovered in stb stb_image.h 1.33 through 2.27. The HDR loader parsed truncated end-of-file RLE scanlines as an infinite sequence of zero-length runs. An attacker could potentially have caused denial of service in applications using stb_image by submitting crafted…
- risk 0.00cvss 6.7epss 0.01
dp_link_settings_write in drivers/gpu/drm/amd/display/amdgpu_dm/amdgpu_dm_debugfs.c in the Linux kernel through 5.14.14 allows a heap-based buffer overflow by an attacker who can write a string to the AMD GPU display drivers debug filesystem. There are no checks on size within…
- risk 0.00cvss 6.7epss 0.00
The firewire subsystem in the Linux kernel through 5.14.13 has a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandles bounds checking.
- risk 0.00cvss 7.8epss 0.01
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 7.5epss 0.02
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a timing attack against lib/RT/REST2/Middleware/Auth.pm.
- risk 0.00cvss 5.5epss 0.02
vim is vulnerable to Heap-based Buffer Overflow
- risk 0.00cvss 8.8epss 0.00
Flatpak is a system for building, distributing, and running sandboxed desktop applications on Linux. In versions prior to 1.10.4 and 1.12.0, Flatpak apps with direct access to AF_UNIX sockets such as those used by Wayland, Pipewire or pipewire-pulse can trick portals and other…
Page 239 of 268