VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2021-46141MedJan 6, 2022
    risk 0.00cvss 5.5epss 0.01

    An issue was discovered in uriparser before 0.9.6. It performs invalid free operations in uriFreeUriMembers and uriMakeOwner.

  • CVE-2021-45943MedJan 1, 2022
    risk 0.00cvss 5.5epss 0.01

    GDAL 3.3.0 through 3.4.0 has a heap-based buffer overflow in PCIDSK::CPCIDSKFile::ReadFromFile (called from PCIDSK::CPCIDSKSegment::ReadFromFile and PCIDSK::CPCIDSKBinarySegment::CPCIDSKBinarySegment).

  • CVE-2021-45942MedJan 1, 2022
    risk 0.00cvss 5.5epss 0.02

    OpenEXR 3.1.x before 3.1.4 has a heap-based buffer overflow in Imf_3_1::LineCompositeTask::execute (called from IlmThread_3_1::NullThreadPoolProvider::addTask and IlmThread_3_1::ThreadPool::addGlobalTask). NOTE: db217f2 may be inapplicable.

  • CVE-2021-45931MedJan 1, 2022
    risk 0.00cvss 6.5epss 0.02

    HarfBuzz 2.9.0 has an out-of-bounds write in hb_bit_set_invertible_t::set (called from hb_sparseset_t<hb_bit_set_invertible_t>::set and hb_set_copy).

  • CVE-2021-45930MedJan 1, 2022
    risk 0.00cvss 5.5epss 0.01

    Qt SVG in Qt 5.0.0 through 5.15.2 and 6.0.0 through 6.2.1 has an out-of-bounds write in QtPrivate::QCommonArrayOps<QPainterPath::Element>::growAppend (called from QPainterPath::addPath and QPathClipper::intersect).

  • CVE-2021-45958MedJan 1, 2022
    risk 0.00cvss 5.5epss 0.02

    UltraJSON (aka ujson) through 5.1.0 has a stack-based buffer overflow in Buffer_AppendIndentUnchecked (called from encode). Exploitation can, for example, use a large amount of indentation.

  • CVE-2015-7223Dec 16, 2015
    risk 0.00cvss —epss 0.02

    The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.

  • CVE-2015-7222Dec 16, 2015
    risk 0.00cvss —epss 0.04

    Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application…

  • CVE-2015-7221Dec 16, 2015
    risk 0.00cvss —epss 0.05

    Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a deque size change.

  • CVE-2015-7220Dec 16, 2015
    risk 0.00cvss —epss 0.05

    Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.

  • CVE-2015-7219Dec 16, 2015
    risk 0.00cvss —epss 0.03

    The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a malformed PushPromise frame that triggers decompressed-buffer length miscalculation and incorrect…

  • CVE-2015-7218Dec 16, 2015
    risk 0.00cvss —epss 0.03

    The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.

  • CVE-2015-7217Dec 16, 2015
    risk 0.00cvss —epss 0.03

    The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.

  • CVE-2015-7216Dec 16, 2015
    risk 0.00cvss —epss 0.02

    The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 image.

  • CVE-2015-7215Dec 16, 2015
    risk 0.00cvss —epss 0.03

    The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to…

  • CVE-2015-7214Dec 16, 2015
    risk 0.00cvss —epss 0.06

    Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allow remote attackers to bypass the Same Origin Policy via data: and view-source: URIs.

  • CVE-2015-7213Dec 16, 2015
    risk 0.00cvss —epss 0.04

    Integer overflow in the MPEG4Extractor::readMetaData function in MPEG4Extractor.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 on 64-bit platforms allows remote attackers to execute arbitrary code via a crafted MP4 video file that triggers…

  • CVE-2015-7212Dec 16, 2015
    risk 0.00cvss —epss 0.04

    Integer overflow in the mozilla::layers::BufferTextureClient::AllocateForSurface function in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering a graphics operation that requires a large texture allocation.

  • CVE-2015-7211Dec 16, 2015
    risk 0.00cvss —epss 0.03

    Mozilla Firefox before 43.0 mishandles the # (number sign) character in a data: URI, which allows remote attackers to spoof web sites via unspecified vectors.

  • CVE-2015-7210Dec 16, 2015
    risk 0.00cvss —epss 0.04

    Use-after-free vulnerability in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code by triggering attempted use of a data channel that has been closed by a WebRTC function.

Page 254 of 268