VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2020-29668LowDec 10, 2020
    risk 0.00cvss 3.7epss 0.02

    Sympa before 6.2.59b.2 allows remote attackers to obtain full SOAP API access by sending any arbitrary string (except one from an expired cookie) as the cookie value to authenticateAndRun.

  • CVE-2020-29661HigDec 9, 2020
    risk 0.00cvss 7.8epss 0.01

    A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.

  • CVE-2020-29660MedDec 9, 2020
    risk 0.00cvss 4.4epss 0.00

    A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_io.c and drivers/tty/tty_jobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.

  • CVE-2020-29651HigDec 9, 2020
    risk 0.00cvss 7.5epss 0.05

    A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.

  • CVE-2020-29074HigNov 25, 2020
    risk 0.00cvss 8.8epss 0.02

    scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls, which allows access by actors other than the current user.

  • CVE-2020-20740HigNov 20, 2020
    risk 0.00cvss 7.8epss 0.01

    PDFResurrect before 0.20 lack of header validation checks causes heap-buffer-overflow in pdf_get_version().

  • CVE-2020-20739MedNov 20, 2020
    risk 0.00cvss 5.3epss 0.02

    im_vips2dz in /libvips/libvips/deprecated/im_vips2dz.c in libvips before 8.8.2 has an uninitialized variable which may cause the leakage of remote server path or stack address.

  • CVE-2020-28196HigNov 6, 2020
    risk 0.00cvss 7.5epss 0.04

    MIT Kerberos 5 (aka krb5) before 1.17.2 and 1.18.x before 1.18.3 allows unbounded recursion via an ASN.1-encoded Kerberos message because the lib/krb5/asn.1/asn1_encode.c support for BER indefinite lengths lacks a recursion limit.

  • CVE-2020-28241MedNov 6, 2020
    risk 0.00cvss 6.5epss 0.02

    libmaxminddb before 1.4.3 has a heap-based buffer over-read in dump_entry_data_list in maxminddb.c.

  • CVE-2020-8037HigNov 4, 2020
    risk 0.00cvss 7.5epss 0.03

    The ppp decapsulator in tcpdump 4.9.3 can be convinced to allocate a large amount of memory.

  • CVE-2020-28036CriNov 2, 2020
    risk 0.00cvss 9.8epss 0.05

    wp-includes/class-wp-xmlrpc-server.php in WordPress before 5.5.2 allows attackers to gain privileges by using XML-RPC to comment on a post.

  • CVE-2020-28030HigNov 2, 2020
    risk 0.00cvss 7.5epss 0.02

    In Wireshark 3.2.0 to 3.2.7, the GQUIC dissector could crash. This was addressed in epan/dissectors/packet-gquic.c by correcting the implementation of offset advancement.

  • CVE-2020-27675MedOct 22, 2020
    risk 0.00cvss 4.7epss 0.00

    An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer dereference, as…

  • CVE-2020-27638HigOct 22, 2020
    risk 0.00cvss 7.5epss 0.02

    receive.c in fastd before v21 allows denial of service (assertion failure) when receiving packets with an invalid type code.

  • CVE-2020-26575HigOct 6, 2020
    risk 0.00cvss 7.5epss 0.03

    In Wireshark through 3.2.7, the Facebook Zero Protocol (aka FBZERO) dissector could enter an infinite loop. This was addressed in epan/dissectors/packet-fbzero.c by correcting the implementation of offset advancement.

  • CVE-2020-25866HigOct 6, 2020
    risk 0.00cvss 7.5epss 0.04

    In Wireshark 3.2.0 to 3.2.6 and 3.0.0 to 3.0.13, the BLIP protocol dissector has a NULL pointer dereference because a buffer was sized for compressed (not uncompressed) messages. This was addressed in epan/dissectors/packet-blip.c by allowing reasonable compression ratios and…

  • CVE-2020-25863HigOct 6, 2020
    risk 0.00cvss 7.5epss 0.05

    In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the MIME Multipart dissector could crash. This was addressed in epan/dissectors/packet-multipart.c by correcting the deallocation of invalid MIME parts.

  • CVE-2020-25862HigOct 6, 2020
    risk 0.00cvss 7.5epss 0.02

    In Wireshark 3.2.0 to 3.2.6, 3.0.0 to 3.0.13, and 2.6.0 to 2.6.20, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by changing the handling of the invalid 0xFFFF checksum.

  • CVE-2020-26572MedOct 6, 2020
    risk 0.00cvss 5.5epss 0.00

    The TCOS smart card software driver in OpenSC before 0.21.0-rc1 has a stack-based buffer overflow in tcos_decipher.

  • CVE-2020-26570MedOct 6, 2020
    risk 0.00cvss 5.5epss 0.00

    The Oberthur smart card software driver in OpenSC before 0.21.0-rc1 has a heap-based buffer overflow in sc_oberthur_read_file.

Page 246 of 268