Fedora
CVEs (5,359)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-0336 | Hig | 0.00 | 8.8 | 0.02 | Aug 29, 2022 | The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on… | ||
| CVE-2022-3016 | Hig | 0.00 | 7.8 | 0.01 | Aug 28, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0286. | ||
| CVE-2022-0216 | Med | 0.00 | 4.4 | 0.00 | Aug 26, 2022 | A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest… | ||
| CVE-2022-2982 | Hig | 0.00 | 7.8 | 0.01 | Aug 25, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0260. | ||
| CVE-2022-2980 | Med | 0.00 | 5.5 | 0.01 | Aug 25, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259. | ||
| CVE-2022-2938 | Hig | 0.00 | 7.8 | 0.00 | Aug 23, 2022 | A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects. | ||
| CVE-2022-25761 | Hig | 0.00 | 7.5 | 0.01 | Aug 23, 2022 | The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this… | ||
| CVE-2022-2923 | Med | 0.00 | 5.5 | 0.01 | Aug 22, 2022 | NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240. | ||
| CVE-2022-2889 | Hig | 0.00 | 7.8 | 0.01 | Aug 19, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0225. | ||
| CVE-2022-2862 | Hig | 0.00 | 7.8 | 0.01 | Aug 17, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0221. | ||
| CVE-2022-2817 | Hig | 0.00 | 7.8 | 0.01 | Aug 15, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0.0213. | ||
| CVE-2022-2816 | Hig | 0.00 | 7.8 | 0.01 | Aug 15, 2022 | Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212. | ||
| CVE-2022-2819 | Hig | 0.00 | 7.8 | 0.01 | Aug 15, 2022 | Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211. | ||
| CVE-2022-37451 | Hig | 0.00 | 7.5 | 0.03 | Aug 6, 2022 | Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc. | ||
| CVE-2022-2553 | Med | 0.00 | 6.5 | 0.01 | Jul 28, 2022 | The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster. | ||
| CVE-2022-35653 | Med | 0.00 | 6.1 | 0.05 | Jul 25, 2022 | A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script… | ||
| CVE-2022-35651 | Med | 0.00 | 6.1 | 0.01 | Jul 25, 2022 | A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's… | ||
| CVE-2021-46829 | Hig | 0.00 | 7.8 | 0.01 | Jul 24, 2022 | GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit… | ||
| CVE-2022-32323 | Hig | 0.00 | 7.3 | 0.01 | Jul 14, 2022 | AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660. | ||
| CVE-2022-2289 | Hig | 0.00 | 7.8 | 0.01 | Jul 3, 2022 | Use After Free in GitHub repository vim/vim prior to 9.0. |
- risk 0.00cvss 8.8epss 0.02
The Samba AD DC includes checks when adding service principals names (SPNs) to an account to ensure that SPNs do not alias with those already in the database. Some of these checks are able to be bypassed if an account modification re-adds an SPN that was previously present on…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0286.
- risk 0.00cvss 4.4epss 0.00
A use-after-free vulnerability was found in the LSI53C895A SCSI Host Bus Adapter emulation of QEMU. The flaw occurs while processing repeated messages to cancel the current SCSI request via the lsi_do_msgout function. This flaw allows a malicious privileged user within the guest…
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0260.
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0259.
- risk 0.00cvss 7.8epss 0.00
A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by default, it could allow an attacker to crash the system or have other memory-corruption side effects.
- risk 0.00cvss 7.5epss 0.01
The package open62541/open62541 before 1.2.5, from 1.3-rc1 and before 1.3.1 are vulnerable to Denial of Service (DoS) due to a missing limitation on the number of received chunks - per single session or in total for all concurrent sessions. An attacker can exploit this…
- risk 0.00cvss 5.5epss 0.01
NULL Pointer Dereference in GitHub repository vim/vim prior to 9.0.0240.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0225.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0221.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.0213.
- risk 0.00cvss 7.8epss 0.01
Out-of-bounds Read in GitHub repository vim/vim prior to 9.0.0212.
- risk 0.00cvss 7.8epss 0.01
Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0211.
- risk 0.00cvss 7.5epss 0.03
Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
- risk 0.00cvss 6.5epss 0.01
The authfile directive in the booth config file is ignored, preventing use of authentication in communications from node to node. As a result, nodes that do not have the correct authentication key are not prevented from communicating with other nodes in the cluster.
- risk 0.00cvss 6.1epss 0.05
A reflected XSS issue was identified in the LTI module of Moodle. The vulnerability exists due to insufficient sanitization of user-supplied data in the LTI module. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script…
- risk 0.00cvss 6.1epss 0.01
A stored XSS and blind SSRF vulnerability was found in Moodle, occurs due to insufficient sanitization of user-supplied data in the SCORM track details. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary HTML and script code in user's…
- risk 0.00cvss 7.8epss 0.01
GNOME GdkPixbuf (aka GDK-PixBuf) before 2.42.8 allows a heap-based buffer overflow when compositing or clearing frames in GIF files, as demonstrated by io-gif-animation.c composite_frame. This overflow is controllable and could be abused for code execution, especially on 32-bit…
- risk 0.00cvss 7.3epss 0.01
AutoTrace v0.40.0 was discovered to contain a heap overflow via the ReadImage function at input-bmp.c:660.
- risk 0.00cvss 7.8epss 0.01
Use After Free in GitHub repository vim/vim prior to 9.0.
Page 247 of 268