VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2022-2158HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Type confusion in V8 in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2157HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Interest groups in Google Chrome prior to 103.0.5060.53 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2156HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Core in Google Chrome prior to 103.0.5060.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2011HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in ANGLE in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2008HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Double free in WebGL in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-2007HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebGPU in Google Chrome prior to 102.0.5005.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-33745HigJul 26, 2022
    risk 0.57cvss 8.8epss 0.00

    insufficient TLB flush for x86 PV guests in shadow mode For migration as well as to work around kernels unaware of L1TF (see XSA-273), PV guests may be run in shadow paging mode. To address XSA-401, code was moved inside a function in Xen. This code movement missed a variable…

  • CVE-2022-32511CriJun 6, 2022
    risk 0.57cvss 9.8epss 0.02

    jmespath.rb (aka JMESPath for Ruby) before 1.6.1 uses JSON.load in a situation where JSON.parse is preferable.

  • CVE-2022-31799CriJun 2, 2022
    risk 0.57cvss 9.8epss 0.02

    Bottle before 0.12.20 mishandles errors during early request binding.

  • CVE-2022-30600CriMay 18, 2022
    risk 0.57cvss 9.8epss 0.05

    A flaw was found in moodle where logic used to count failed login attempts could result in the account lockout threshold being bypassed.

  • CVE-2022-30599CriMay 18, 2022
    risk 0.57cvss 9.8epss 0.01

    A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.

  • CVE-2022-29501HigMay 5, 2022
    risk 0.57cvss 8.8epss 0.03

    SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Escalation of Privileges and code execution.

  • CVE-2022-29500HigMay 5, 2022
    risk 0.57cvss 8.8epss 0.02

    SchedMD Slurm 21.08.x through 20.11.x has Incorrect Access Control that leads to Information Disclosure.

  • CVE-2021-4093HigFeb 18, 2022
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in the KVM's AMD code for supporting the Secure Encrypted Virtualization-Encrypted State (SEV-ES). A KVM guest using SEV-ES can trigger out-of-bounds reads and writes in the host kernel via a malicious VMGEXIT for a string I/O instruction (for example, outs or…

  • CVE-2020-25722HigFeb 18, 2022
    risk 0.57cvss 8.8epss 0.02

    Multiple flaws were found in the way samba AD DC implemented access and conformance checking of stored data. An attacker could use this flaw to cause total domain compromise.

  • CVE-2020-25718HigFeb 18, 2022
    risk 0.57cvss 8.8epss 0.02

    A flaw was found in the way samba, as an Active Directory Domain Controller, is able to support an RODC (read-only domain controller). This would allow an RODC to print administrator tickets.

  • CVE-2022-0115HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Uninitialized use in File API in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

  • CVE-2022-0107HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in File Manager API in Google Chrome on Chrome OS prior to 97.0.4692.71 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0106HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in Autofill in Google Chrome prior to 97.0.4692.71 allowed a remote attacker who convinced a user to perform specific user gesture to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2022-0105HigFeb 12, 2022
    risk 0.57cvss 8.8epss 0.01

    Use after free in PDF Accessibility in Google Chrome prior to 97.0.4692.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Page 33 of 268