VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2018-1000852MedDec 20, 2018
    risk 0.00cvss 6.5epss 0.03

    FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_capability_request that can result in The RDP server can read the client's memory..…

  • CVE-2018-19841MedDec 4, 2018
    risk 0.00cvss 5.5epss 0.03

    The function WavpackVerifySingleBlock in open_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (out-of-bounds read and application crash) via a crafted WavPack Lossless Audio file, as demonstrated by wvunpack.

  • CVE-2018-19840MedDec 4, 2018
    risk 0.00cvss 5.5epss 0.05

    The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.

  • CVE-2018-19497MedNov 29, 2018
    risk 0.00cvss 6.5epss 0.02

    In The Sleuth Kit (TSK) through 4.6.4, hfs_cat_traverse in tsk/fs/hfs.c does not properly determine when a key length is too large, which allows attackers to cause a denial of service (SEGV on unknown address with READ memory access in a tsk_getu16 call in hfs_dir_open_meta_cb…

  • CVE-2018-14599CriAug 24, 2018
    risk 0.00cvss 9.8epss 0.05

    An issue was discovered in libX11 through 1.6.5. The function XListExtensions in ListExt.c is vulnerable to an off-by-one error caused by malicious server responses, leading to DoS or possibly unspecified other impact.

  • CVE-2018-14598HigAug 24, 2018
    risk 0.00cvss 7.5epss 0.04

    An issue was discovered in XListExtensions in ListExt.c in libX11 through 1.6.5. A malicious server can send a reply in which the first string overflows, causing a variable to be set to NULL that will be freed later on, leading to DoS (segmentation fault).

  • CVE-2018-7262HigMar 19, 2018
    risk 0.00cvss 7.5epss 0.03

    In Ceph before 12.2.3 and 13.x through 13.0.1, the rgw_civetweb.cc RGWCivetWeb::init_env function in radosgw doesn't handle malformed HTTP headers properly, allowing for denial of service.

  • CVE-2018-5730LowMar 6, 2018
    risk 0.00cvss 3.8epss 0.02

    MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to circumvent a DN containership check by supplying both a "linkdn" and "containerdn" database argument, or by supplying a DN string which is a left extension of a…

  • CVE-2018-5729MedMar 6, 2018
    risk 0.00cvss 4.7epss 0.03

    MIT krb5 1.6 or later allows an authenticated kadmin with permission to add principals to an LDAP Kerberos database to cause a denial of service (NULL pointer dereference) or bypass a DN container check by supplying tagged data that is internal to the database module.

  • CVE-2017-15365HigJan 25, 2018
    risk 0.00cvss 8.8epss 0.03

    sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition…

  • CVE-2017-15129MedJan 9, 2018
    risk 0.00cvss 4.7epss 0.00

    A use-after-free vulnerability was found in network namespaces code affecting the Linux kernel before 4.14.11. The function get_net_ns_by_id() in net/core/net_namespace.c does not check for the net::count value after it has found a peer network in netns_ids idr, which could lead…

  • CVE-2015-7223Dec 16, 2015
    risk 0.00cvss epss 0.02

    The WebExtension APIs in Mozilla Firefox before 43.0 allow remote attackers to gain privileges, and possibly obtain sensitive information or conduct cross-site scripting (XSS) attacks, via a crafted web site.

  • CVE-2015-7222Dec 16, 2015
    risk 0.00cvss epss 0.04

    Integer underflow in the Metadata::setData function in MetaData.cpp in libstagefright in Mozilla Firefox before 43.0 and Firefox ESR 38.x before 38.5 allows remote attackers to execute arbitrary code or cause a denial of service (incorrect memory allocation and application…

  • CVE-2015-7221Dec 16, 2015
    risk 0.00cvss epss 0.05

    Buffer overflow in the nsDeque::GrowCapacity function in xpcom/glue/nsDeque.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact by triggering a deque size change.

  • CVE-2015-7220Dec 16, 2015
    risk 0.00cvss epss 0.05

    Buffer overflow in the XDRBuffer::grow function in js/src/vm/Xdr.cpp in Mozilla Firefox before 43.0 might allow remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code.

  • CVE-2015-7219Dec 16, 2015
    risk 0.00cvss epss 0.03

    The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a malformed PushPromise frame that triggers decompressed-buffer length miscalculation and incorrect…

  • CVE-2015-7218Dec 16, 2015
    risk 0.00cvss epss 0.03

    The HTTP/2 implementation in Mozilla Firefox before 43.0 allows remote attackers to cause a denial of service (integer underflow, assertion failure, and application exit) via a single-byte header frame that triggers incorrect memory allocation.

  • CVE-2015-7217Dec 16, 2015
    risk 0.00cvss epss 0.03

    The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the TGA decoder, which allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted Truevision TGA image.

  • CVE-2015-7216Dec 16, 2015
    risk 0.00cvss epss 0.02

    The gdk-pixbuf configuration in Mozilla Firefox before 43.0 on Linux GNOME platforms incorrectly enables the JasPer decoder, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted JPEG 2000 image.

  • CVE-2015-7215Dec 16, 2015
    risk 0.00cvss epss 0.03

    The importScripts function in the Web Workers API implementation in Mozilla Firefox before 43.0 allows remote attackers to bypass the Same Origin Policy by triggering use of the no-cors mode in the fetch API to attempt resource access that throws an exception, leading to…

Page 254 of 268