VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-24735LowApr 27, 2022
    risk 0.00cvss 3.9epss 0.02

    Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execute with the (potentially higher) privileges of another…

  • CVE-2022-1507MedApr 27, 2022
    risk 0.00cvss 5.5epss 0.01

    chafa: NULL Pointer Dereference in function gif_internal_decode_frame at libnsgif.c:599 allows attackers to cause a denial of service (crash) via a crafted input file. in GitHub repository hpjansson/chafa prior to 1.10.2. chafa: NULL Pointer Dereference in function…

  • CVE-2022-27239HigApr 27, 2022
    risk 0.00cvss 7.8epss 0.01

    In cifs-utils through 6.14, a stack-based buffer overflow when parsing the mount.cifs ip= command-line argument could lead to local attackers gaining root privileges.

  • CVE-2022-24883HigApr 26, 2022
    risk 0.00cvss 7.4epss 0.02

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). Prior to version 2.7.0, server side authentication against a `SAM` file might be successful for invalid credentials if the server has configured an invalid `SAM` file path. FreeRDP based clients are not…

  • CVE-2022-24882CriApr 26, 2022
    risk 0.00cvss 9.1epss 0.03

    FreeRDP is a free implementation of the Remote Desktop Protocol (RDP). In versions prior to 2.7.0, NT LAN Manager (NTLM) authentication does not properly abort when someone provides and empty password value. This issue affects FreeRDP based RDP Server implementations. RDP…

  • CVE-2022-1420MedApr 21, 2022
    risk 0.00cvss 5.5epss 0.01

    Use of Out-of-range Pointer Offset in GitHub repository vim/vim prior to 8.2.4774.

  • CVE-2022-1381HigApr 18, 2022
    risk 0.00cvss 7.8epss 0.03

    global heap buffer overflow in skip_range in GitHub repository vim/vim prior to 8.2.4763. This vulnerability is capable of crashing software, Bypass Protection Mechanism, Modify Memory, and possible remote execution

  • CVE-2022-1231MedApr 15, 2022
    risk 0.00cvss 6.1epss 0.02

    XSS via Embedded SVG in SVG Diagram Format in GitHub repository plantuml/plantuml prior to 1.2022.4. Stored XSS in the context of the diagram embedder. Depending on the actual context, this ranges from stealing secrets to account hijacking or even to code execution for example…

  • CVE-2022-28048HigApr 15, 2022
    risk 0.00cvss 8.8epss 0.02

    STB v2.27 was discovered to contain an integer shift of invalid size in the component stbi__jpeg_decode_block_prog_ac.

  • CVE-2022-28042HigApr 15, 2022
    risk 0.00cvss 8.8epss 0.02

    stb_image.h v2.27 was discovered to contain an heap-based use-after-free via the function stbi__jpeg_huff_decode.

  • CVE-2022-28041MedApr 15, 2022
    risk 0.00cvss 6.5epss 0.02

    stb_image.h v2.27 was discovered to contain an integer overflow via the function stbi__jpeg_decode_block_prog_dc. This vulnerability allows attackers to cause a Denial of Service (DoS) via unspecified vectors.

  • CVE-2022-1328MedApr 14, 2022
    risk 0.00cvss 4.3epss 0.02

    Buffer Overflow in uudecoder in Mutt affecting all versions starting from 0.94.13 before 2.2.3 allows read past end of input line

  • CVE-2022-28805CriApr 8, 2022
    risk 0.00cvss 9.1epss 0.03

    singlevar in lparser.c in Lua from (including) 5.4.0 up to (excluding) 5.4.4 lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.

  • CVE-2022-28796HigApr 8, 2022
    risk 0.00cvss 7.0epss 0.00

    jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.

  • CVE-2022-27650HigApr 4, 2022
    risk 0.00cvss 7.5epss 0.01

    A flaw was found in crun where containers were incorrectly started with non-empty default permissions. A vulnerability was found in Moby (Docker Engine) where containers were started incorrectly with non-empty inheritable Linux process capabilities. This flaw allows an attacker…

  • CVE-2022-28390HigApr 3, 2022
    risk 0.00cvss 7.8epss 0.00

    ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel through 5.17.1 has a double free.

  • CVE-2022-28389MedApr 3, 2022
    risk 0.00cvss 5.5epss 0.00

    mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.

  • CVE-2022-28388MedApr 3, 2022
    risk 0.00cvss 5.5epss 0.00

    usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.

  • CVE-2022-1160HigMar 30, 2022
    risk 0.00cvss 7.8epss 0.01

    heap buffer overflow in get_one_sourceline in GitHub repository vim/vim prior to 8.2.4647.

  • CVE-2022-1154HigMar 30, 2022
    risk 0.00cvss 7.8epss 0.01

    Use after free in utf_ptr2char in GitHub repository vim/vim prior to 8.2.4646.

Page 250 of 268