VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2021-30612HigSep 3, 2021
    risk 0.57cvss 8.8epss 0.03

    Chromium: CVE-2021-30612 Use after free in WebRTC

  • CVE-2021-30611HigSep 3, 2021
    risk 0.57cvss 8.8epss 0.03

    Chromium: CVE-2021-30611 Use after free in WebRTC

  • CVE-2021-30604HigAug 26, 2021
    risk 0.57cvss 8.8epss 0.03

    Use after free in ANGLE in Google Chrome prior to 92.0.4515.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30602HigAug 26, 2021
    risk 0.57cvss 8.8epss 0.02

    Use after free in WebRTC in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to visit a malicious website to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30601HigAug 26, 2021
    risk 0.57cvss 8.8epss 0.02

    Use after free in Extensions API in Google Chrome prior to 92.0.4515.159 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30600HigAug 26, 2021
    risk 0.57cvss 8.8epss 0.03

    Use after free in Printing in Google Chrome prior to 92.0.4515.159 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30592HigAug 26, 2021
    risk 0.57cvss 8.8epss 0.02

    Out of bounds write in Tab Groups in Google Chrome prior to 92.0.4515.131 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory write via a crafted HTML page.

  • CVE-2021-30591HigAug 26, 2021
    risk 0.57cvss 8.8epss 0.03

    Use after free in File System API in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30590HigAug 26, 2021
    risk 0.57cvss 8.8epss 0.03

    Heap buffer overflow in Bookmarks in Google Chrome prior to 92.0.4515.131 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30953HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.02

    An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30951HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.02

    A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30936HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.02

    A use after free issue was addressed with improved memory management. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30934HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.03

    A buffer overflow issue was addressed with improved memory handling. This issue is fixed in tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS 15.2 and iPadOS 15.2, watchOS 8.3. Processing maliciously crafted web content may lead to arbitrary code execution.

  • CVE-2021-30851HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.02

    A memory corruption vulnerability was addressed with improved locking. This issue is fixed in Safari 15, tvOS 15, watchOS 8, iOS 15 and iPadOS 15. Processing maliciously crafted web content may lead to code execution.

  • CVE-2021-38714HigAug 24, 2021
    risk 0.57cvss 8.8epss 0.03

    In Plib through 1.85, there is an integer overflow vulnerability that could result in arbitrary code execution. The vulnerability is found in ssgLoadTGA() function in src/ssg/ssgLoadTGA.cxx file.

  • CVE-2021-39141HigAug 23, 2021
    risk 0.57cvss 8.5epss 0.16

    XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker to load and execute arbitrary code from a remote host only by manipulating the processed input stream. No user is affected, who followed…

  • CVE-2021-30588HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.02

    Type confusion in V8 in Google Chrome prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30586HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in dialog box handling in Windows in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30585HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in sensor handling in Google Chrome on Windows prior to 92.0.4515.107 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2021-30581HigAug 3, 2021
    risk 0.57cvss 8.8epss 0.01

    Use after free in DevTools in Google Chrome prior to 92.0.4515.107 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.

Page 37 of 268