Fedora
CVEs (5,359)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-42719 | Hig | 0.00 | 8.8 | 0.01 | Oct 13, 2022 | A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code. | ||
| CVE-2022-41556 | Hig | 0.00 | 7.5 | 0.04 | Oct 6, 2022 | A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of… | ||
| CVE-2022-3352 | Hig | 0.00 | 7.8 | 0.01 | Sep 29, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0614. | ||
| CVE-2022-39264 | Hig | 0.00 | 8.6 | 0.01 | Sep 28, 2022 | nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a… | ||
| CVE-2022-3278 | Med | 0.00 | 5.5 | 0.01 | Sep 23, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552. | ||
| CVE-2022-41322 | Hig | 0.00 | 7.8 | 0.01 | Sep 23, 2022 | In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. | ||
| CVE-2022-3213 | Med | 0.00 | 5.5 | 0.00 | Sep 19, 2022 | A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service. | ||
| CVE-2022-3235 | Hig | 0.00 | 7.8 | 0.01 | Sep 18, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0490. | ||
| CVE-2022-40768 | Med | 0.00 | 5.5 | 0.00 | Sep 18, 2022 | drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. | ||
| CVE-2022-3234 | Hig | 0.00 | 7.8 | 0.01 | Sep 17, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483. | ||
| CVE-2022-39209 | Hig | 0.00 | 7.5 | 0.02 | Sep 15, 2022 | cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.… | ||
| CVE-2022-40674 | Hig | 0.00 | 8.1 | 0.02 | Sep 14, 2022 | libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. | ||
| CVE-2022-40673 | Hig | 0.00 | 7.8 | 0.00 | Sep 14, 2022 | KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache. | ||
| CVE-2022-3123 | Med | 0.00 | 6.1 | 0.01 | Sep 5, 2022 | Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a. | ||
| CVE-2022-3099 | Hig | 0.00 | 7.8 | 0.00 | Sep 3, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0360. | ||
| CVE-2022-39170 | Hig | 0.00 | 8.8 | 0.01 | Sep 2, 2022 | libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c. | ||
| CVE-2022-3028 | Hig | 0.00 | 7.0 | 0.00 | Aug 31, 2022 | A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory… | ||
| CVE-2022-2153 | Med | 0.00 | 5.5 | 0.00 | Aug 31, 2022 | A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific… | ||
| CVE-2022-1354 | Med | 0.00 | 5.5 | 0.01 | Aug 31, 2022 | A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service. | ||
| CVE-2022-0367 | Hig | 0.00 | 7.8 | 0.00 | Aug 29, 2022 | A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. |
- risk 0.00cvss 8.8epss 0.01
A use-after-free in the mac80211 stack when parsing a multi-BSSID element in the Linux kernel 5.2 through 5.19.x before 5.19.16 could be used by attackers (able to inject WLAN frames) to crash the kernel and potentially execute code.
- risk 0.00cvss 7.5epss 0.04
A resource leak in gw_backend.c in lighttpd 1.4.56 through 1.4.66 could lead to a denial of service (connection-slot exhaustion) after a large amount of anomalous TCP behavior by clients. It is related to RDHUP mishandling in certain HTTP/1.1 chunked situations. Use of…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0614.
- risk 0.00cvss 8.6epss 0.01
nheko is a desktop client for the Matrix communication application. All versions below 0.10.2 are vulnerable homeservers inserting malicious secrets, which could lead to man-in-the-middle attacks. Users can upgrade to version 0.10.2 to protect against this issue. As a…
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0552.
- risk 0.00cvss 7.8epss 0.01
In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.
- risk 0.00cvss 5.5epss 0.00
A heap buffer overflow issue was found in ImageMagick. When an application processes a malformed TIFF file, it could lead to undefined behavior or a crash causing a denial of service.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0490.
- risk 0.00cvss 5.5epss 0.00
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0483.
- risk 0.00cvss 7.5epss 0.02
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaustion and subsequent denial of service.…
- risk 0.00cvss 8.1epss 0.02
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
- risk 0.00cvss 7.8epss 0.00
KDiskMark before 3.1.0 lacks authorization checking for D-Bus methods such as Helper::flushPageCache.
- risk 0.00cvss 6.1epss 0.01
Cross-site Scripting (XSS) - Reflected in GitHub repository splitbrain/dokuwiki prior to 2022-07-31a.
- risk 0.00cvss 7.8epss 0.00
Use After Free in GitHub repository vim/vim prior to 9.0.0360.
- risk 0.00cvss 8.8epss 0.01
libdwarf 0.4.1 has a double free in _dwarf_exec_frame_instr in dwarf_frame.c.
- risk 0.00cvss 7.0epss 0.00
A race condition was found in the Linux kernel's IP framework for transforming packets (XFRM subsystem) when multiple calls to xfrm_probe_algs occurred simultaneously. This flaw could allow a local attacker to potentially trigger an out-of-bounds write or leak kernel heap memory…
- risk 0.00cvss 5.5epss 0.00
A flaw was found in the Linux kernel’s KVM when attempting to set a SynIC IRQ. This issue makes it possible for a misbehaving VMM to write to SYNIC/STIMER MSRs, causing a NULL pointer dereference. This flaw allows an unprivileged local attacker on the host to issue specific…
- risk 0.00cvss 5.5epss 0.01
A heap buffer overflow flaw was found in Libtiffs' tiffinfo.c in TIFFReadRawDataStriped() function. This flaw allows an attacker to pass a crafted TIFF file to the tiffinfo tool, triggering a heap buffer overflow issue and causing a crash that leads to a denial of service.
- risk 0.00cvss 7.8epss 0.00
A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c.
Page 246 of 268