VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-4645MedMar 3, 2023
    risk 0.00cvss 6.8epss 0.00

    LibTIFF 4.4.0 has an out-of-bounds read in tiffcp in tools/tiffcp.c:948, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit e8131125.

  • CVE-2023-1127HigMar 1, 2023
    risk 0.00cvss 7.8epss 0.00

    Divide By Zero in GitHub repository vim/vim prior to 9.0.1367.

  • CVE-2023-0361HigFeb 15, 2023
    risk 0.00cvss 7.4epss 0.01

    A timing side-channel in the handling of RSA ClientKeyExchange messages was discovered in GnuTLS. This side-channel can be sufficient to recover the key encrypted in the RSA ciphertext across a network in a Bleichenbacher style attack. To achieve a successful decryption the…

  • CVE-2022-46663HigFeb 7, 2023
    risk 0.00cvss 7.5epss 0.01

    In GNU Less before 609, crafted data can result in "less -R" not filtering ANSI escape sequences sent to the terminal.

  • CVE-2023-25193HigFeb 4, 2023
    risk 0.00cvss 7.5epss 0.02

    hb-ot-layout-gsubgpos.hh in HarfBuzz through 6.0.0 allows attackers to trigger O(n^2) growth via consecutive marks during the process of looking back for base glyphs when attaching marks.

  • CVE-2022-47021HigJan 20, 2023
    risk 0.00cvss 7.8epss 0.00

    A null pointer dereference issue was discovered in functions op_get_data and op_open1 in opusfile.c in xiph opusfile 0.9 thru 0.12 allows attackers to cause denial of service or other unspecified impacts.

  • CVE-2023-23589MedJan 14, 2023
    risk 0.00cvss 6.5epss 0.01

    The SafeSocks option in Tor before 0.4.7.13 has a logic error in which the unsafe SOCKS4 protocol can be used but not the safe SOCKS4a protocol, aka TROVE-2022-002.

  • CVE-2023-23457MedJan 12, 2023
    risk 0.00cvss 5.3epss 0.00

    A Segmentation fault was found in UPX in PackLinuxElf64::invert_pt_dynamic() in p_lx_elf.cpp. An attacker with a crafted input file allows invalid memory address access that could lead to a denial of service.

  • CVE-2023-23456MedJan 12, 2023
    risk 0.00cvss 5.3epss 0.00

    A heap-based buffer overflow issue was discovered in UPX in PackTmt::pack() in p_tmt.cpp file. The flow allows an attacker to cause a denial of service (abort) via a crafted file.

  • CVE-2022-3109HigDec 16, 2022
    risk 0.00cvss 7.5epss 0.01

    An issue was discovered in the FFmpeg package, where vp3_decode_frame in libavcodec/vp3.c lacks check of the return value of av_malloc() and will cause a null pointer dereference, impacting availability.

  • CVE-2022-46391MedDec 4, 2022
    risk 0.00cvss 6.1epss 0.01

    AWStats 7.x through 7.8 allows XSS in the hostinfo plugin due to printing a response from Net::XWhois without proper checks.

  • CVE-2022-4172MedNov 29, 2022
    risk 0.00cvss 6.5epss 0.00

    An integer overflow and buffer overflow issues were found in the ACPI Error Record Serialization Table (ERST) device of QEMU in the read_erst_record() and write_erst_record() functions. Both issues may allow the guest to overrun the host buffer allocated for the ERST memory…

  • CVE-2022-45934HigNov 27, 2022
    risk 0.00cvss 7.8epss 0.01

    An issue was discovered in the Linux kernel through 6.0.10. l2cap_config_req in net/bluetooth/l2cap_core.c has an integer wraparound via L2CAP_CONF_REQ packets.

  • CVE-2022-45152CriNov 25, 2022
    risk 0.00cvss 9.1epss 0.01

    A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An…

  • CVE-2022-39346LowNov 25, 2022
    risk 0.00cvss 3.5epss 0.01

    Nextcloud server is an open source personal cloud server. Affected versions of nextcloud server did not properly limit user display names which could allow a malicious users to overload the backing database and cause a denial of service. It is recommended that the Nextcloud…

  • CVE-2022-45873MedNov 23, 2022
    risk 0.00cvss 5.5epss 0.00

    systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put…

  • CVE-2022-44789HigNov 23, 2022
    risk 0.00cvss 8.8epss 0.02

    A logical issue in O_getOwnPropertyDescriptor() in Artifex MuJS 1.0.0 through 1.3.x before 1.3.2 allows an attacker to achieve Remote Code Execution through memory corruption, via the loading of a crafted JavaScript file.

  • CVE-2022-45866MedNov 23, 2022
    risk 0.00cvss 5.3epss 0.01

    qpress before PierreLvx/qpress 20220819 and before version 11.3, as used in Percona XtraBackup and other products, allows directory traversal via ../ in a .qp file.

  • CVE-2022-45151MedNov 23, 2022
    risk 0.00cvss 5.4epss 0.01

    The stored-XSS vulnerability was discovered in Moodle which exists due to insufficient sanitization of user-supplied data in several "social" user profile fields. An attacker could inject and execute arbitrary HTML and script code in user's browser in context of vulnerable…

  • CVE-2022-45150MedNov 23, 2022
    risk 0.00cvss 6.1epss 0.01

    A reflected cross-site scripting vulnerability was discovered in Moodle. This flaw exists due to insufficient sanitization of user-supplied data in policy tool. An attacker can trick the victim to open a specially crafted link that executes an arbitrary HTML and script code in…

Page 244 of 268