VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-1706MedMay 17, 2022
    risk 0.00cvss 6.5epss 0.01

    A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is…

  • CVE-2022-1769HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.00

    Buffer Over-read in GitHub repository vim/vim prior to 8.2.4974.

  • CVE-2022-1733HigMay 17, 2022
    risk 0.00cvss 7.8epss 0.01

    Heap-based Buffer Overflow in GitHub repository vim/vim prior to 8.2.4968.

  • CVE-2022-1587CriMay 16, 2022
    risk 0.00cvss 9.1epss 0.03

    An out-of-bounds read vulnerability was discovered in the PCRE2 library in the get_recurse_data_length() function of the pcre2_jit_compile.c file. This issue affects recursions in JIT-compiled regular expressions caused by duplicate data transfers.

  • CVE-2022-1586CriMay 16, 2022
    risk 0.00cvss 9.1epss 0.03

    An out-of-bounds read vulnerability was discovered in the PCRE2 library in the compile_xclass_matchingpath() function of the pcre2_jit_compile.c file. This involves a unicode property matching issue in JIT-compiled regular expressions. The issue occurs because the character was…

  • CVE-2022-30767CriMay 16, 2022
    risk 0.00cvss 9.8epss 0.03

    nfs_lookup_reply in net/nfs.c in Das U-Boot through 2022.04 (and through 2022.07-rc2) has an unbounded memcpy with a failed length check, leading to a buffer overflow. NOTE: this issue exists because of an incorrect fix for CVE-2019-14196.

  • CVE-2022-1379CriMay 14, 2022
    risk 0.00cvss 9.1epss 0.02

    URL Restriction Bypass in GitHub repository plantuml/plantuml prior to V1.2022.5. An attacker can abuse this to bypass URL restrictions that are imposed by the different security profiles and achieve server side request forgery (SSRF). This allows accessing restricted internal…

  • CVE-2022-1623MedMay 11, 2022
    risk 0.00cvss 5.5epss 0.01

    LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.

  • CVE-2022-1622MedMay 11, 2022
    risk 0.00cvss 5.5epss 0.02

    LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.

  • CVE-2022-1629HigMay 10, 2022
    risk 0.00cvss 7.8epss 0.02

    Buffer Over-read in function find_next_quote in GitHub repository vim/vim prior to 8.2.4925. This vulnerabilities are capable of crashing software, Modify Memory, and possible remote execution

  • CVE-2022-1621HigMay 10, 2022
    risk 0.00cvss 7.8epss 0.02

    Heap buffer overflow in vim_strncpy find_word in GitHub repository vim/vim prior to 8.2.4919. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

  • CVE-2022-24903HigMay 6, 2022
    risk 0.00cvss 8.1epss 0.04

    Rsyslog is a rocket-fast system for log processing. Modules for TCP syslog reception have a potential heap buffer overflow when octet-counted framing is used. This can result in a segfault or some other malfunction. As of our understanding, this vulnerability can not be used for…

  • CVE-2022-24884CriMay 6, 2022
    risk 0.00cvss 10.0epss 0.01

    ecdsautils is a tiny collection of programs used for ECDSA (keygen, sign, verify). `ecdsa_verify_[prepare_]legacy()` does not check whether the signature values `r` and `s` are non-zero. A signature consisting only of zeroes is always considered valid, making it trivial to forge…

  • CVE-2022-30292CriMay 4, 2022
    risk 0.00cvss 10.0epss 0.04

    Heap-based buffer overflow in sqbaselib.cpp in SQUIRREL 3.2 due to lack of a certain sq_reservestack call.

  • CVE-2022-28487HigMay 4, 2022
    risk 0.00cvss 7.5epss 0.02

    Tcpreplay version 4.4.1 contains a memory leakage flaw in fix_ipv6_checksums() function. The highest threat from this vulnerability is to data confidentiality.

  • CVE-2022-27470HigMay 4, 2022
    risk 0.00cvss 7.8epss 0.01

    SDL_ttf v2.0.18 and below was discovered to contain an arbitrary memory write via the function TTF_RenderText_Solid(). This vulnerability is triggered via a crafted TTF file.

  • CVE-2022-29824MedMay 3, 2022
    risk 0.00cvss 6.5epss 0.04

    In libxml2 before 2.9.14, several buffer handling functions in buf.c (xmlBuf*) and tree.c (xmlBuffer*) don't check for integer overflows. This can result in out-of-bounds memory writes. Exploitation requires a victim to open a crafted, multi-gigabyte XML file. Other software…

  • CVE-2022-1227HigApr 29, 2022
    risk 0.00cvss 8.8epss 0.04

    A privilege escalation flaw was found in Podman. This flaw allows an attacker to publish a malicious image to a public registry. Once this image is downloaded by a potential victim, the vulnerability is triggered after a user runs the 'podman top' command. This action gives the…

  • CVE-2022-29869MedApr 28, 2022
    risk 0.00cvss 5.3epss 0.02

    cifs-utils through 6.14, with verbose logging, can cause an information leak when a file contains = (equal sign) characters but is not a valid credentials file.

  • CVE-2022-24736LowApr 27, 2022
    risk 0.00cvss 3.3epss 0.01

    Redis is an in-memory database that persists on disk. Prior to versions 6.2.7 and 7.0.0, an attacker attempting to load a specially crafted Lua script can cause NULL pointer dereference which will result with a crash of the redis-server process. The problem is fixed in Redis…

Page 249 of 268