VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2020-6520HigJul 22, 2020
    risk 0.57cvss 8.8epss 0.03

    Buffer overflow in Skia in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6518HigJul 22, 2020
    risk 0.57cvss 8.8epss 0.03

    Use after free in developer tools in Google Chrome prior to 84.0.4147.89 allowed a remote attacker who had convinced the user to use developer tools to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6517HigJul 22, 2020
    risk 0.57cvss 8.8epss 0.03

    Heap buffer overflow in history in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6515HigJul 22, 2020
    risk 0.57cvss 8.8epss 0.03

    Use after free in tab strip in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6513HigJul 22, 2020
    risk 0.57cvss 8.8epss 0.03

    Heap buffer overflow in PDFium in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2020-6512HigJul 22, 2020
    risk 0.57cvss 8.8epss 0.03

    Type Confusion in V8 in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-14001CriJul 17, 2020
    risk 0.57cvss 9.8epss 0.05

    The kramdown gem before 2.3.0 for Ruby processes the template option inside Kramdown documents by default, which allows unintended read access (such as template="/etc/passwd") or unintended embedded Ruby code execution (such as a string that begins with template="string://<%=…

  • CVE-2020-15565HigJul 7, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing x86 Intel HVM guest OS users to cause a host OS denial of service or possibly gain privileges because of insufficient cache write-back under VT-d. When page tables are shared between IOMMU and CPU, changes to them require…

  • CVE-2017-9105HigJun 18, 2020
    risk 0.57cvss 8.8epss 0.04

    An issue was discovered in adns before 1.5.2. It corrupts a pointer when a nameserver speaks first because of a wrong number of pointer dereferences. This bug may well be exploitable as a remote code execution.

  • CVE-2020-14295HigJun 17, 2020
    risk 0.57cvss 7.2epss 0.86

    A SQL injection issue in color.php in Cacti 1.2.12 allows an admin to inject SQL via the filter parameter. This can lead to remote command execution because the product accepts stacked queries.

  • CVE-2020-13379HigJun 3, 2020
    risk 0.57cvss 8.2epss 1.00

    The avatar feature in Grafana 3.0.1 through 7.0.1 has an SSRF Incorrect Access Control issue. This vulnerability allows any unauthenticated user/client to make Grafana send HTTP requests to any URL and return its result to the user/client. This can be used to gain information…

  • CVE-2020-6474HigMay 21, 2020
    risk 0.57cvss 8.8epss 0.02

    Use after free in Blink in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6467HigMay 21, 2020
    risk 0.57cvss 8.8epss 0.02

    Use after free in WebRTC in Google Chrome prior to 83.0.4103.61 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6463HigMay 21, 2020
    risk 0.57cvss 8.8epss 0.03

    Use after free in ANGLE in Google Chrome prior to 81.0.4044.122 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-11793HigApr 17, 2020
    risk 0.57cvss 8.8epss 0.03

    A use-after-free issue exists in WebKitGTK before 2.28.1 and WPE WebKit before 2.28.1 via crafted web content that allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash).

  • CVE-2020-11741HigApr 14, 2020
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in xenoprof in Xen through 4.13.x, allowing guest OS users (with active profiling) to obtain sensitive information about other guests, cause a denial of service, or possibly gain privileges. For guests for which "active" profiling was enabled by the…

  • CVE-2020-6455HigApr 13, 2020
    risk 0.57cvss 8.8epss 0.02

    Out of bounds read in WebSQL in Google Chrome prior to 81.0.4044.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6454HigApr 13, 2020
    risk 0.57cvss 8.8epss 0.01

    Use after free in extensions in Google Chrome prior to 81.0.4044.92 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.

  • CVE-2020-6452HigApr 13, 2020
    risk 0.57cvss 8.8epss 0.02

    Heap buffer overflow in media in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6451HigApr 13, 2020
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebAudio in Google Chrome prior to 80.0.3987.162 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Page 46 of 268