VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2020-6402HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.03

    Insufficient policy enforcement in downloads in Google Chrome on OS X prior to 80.0.3987.87 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

  • CVE-2020-6398HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Use of uninitialized data in PDFium in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2020-6390HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.03

    Out of bounds memory access in streams in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6385HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Insufficient policy enforcement in storage in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to bypass site isolation via a crafted HTML page.

  • CVE-2020-6382HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Type confusion in JavaScript in Google Chrome prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6381HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Integer overflow in JavaScript in Google Chrome on ChromeOS and Android prior to 80.0.3987.87 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6380HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in extensions in Google Chrome prior to 79.0.3945.130 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted Chrome Extension.

  • CVE-2020-6379HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.01

    Use after free in V8 in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-6378HigFeb 11, 2020
    risk 0.57cvss 8.8epss 0.01

    Use after free in speech in Google Chrome prior to 79.0.3945.130 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2015-8011CriJan 28, 2020
    risk 0.57cvss 9.8epss 0.05

    Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.

  • CVE-2014-4172CriJan 24, 2020
    risk 0.57cvss 9.8epss 0.06

    A URL parameter injection vulnerability was found in the back-channel ticket validation step of the CAS protocol in Jasig Java CAS Client before 3.3.2, .NET CAS Client before 1.0.2, and phpCAS before 1.3.3 that allow remote attackers to inject arbitrary web script or HTML via…

  • CVE-2020-6860HigJan 13, 2020
    risk 0.57cvss 8.8epss 0.02

    libmysofa 0.9.1 has a stack-based buffer overflow in readDataVar in hdf/dataobject.c during the reading of a header message attribute.

  • CVE-2020-6377HigJan 10, 2020
    risk 0.57cvss 8.8epss 0.01

    Use after free in audio in Google Chrome prior to 79.0.3945.117 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-5395HigJan 3, 2020
    risk 0.57cvss 8.8epss 0.02

    FontForge 20190801 has a use-after-free in SFD_GetFontMetaData in sfd.c.

  • CVE-2020-5312CriJan 3, 2020
    risk 0.57cvss 9.8epss 0.04

    libImaging/PcxDecode.c in Pillow before 6.2.2 has a PCX P mode buffer overflow.

  • CVE-2020-5311CriJan 3, 2020
    risk 0.57cvss 9.8epss 0.04

    libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.

  • CVE-2019-19578HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "Linear pagetables" is a technique which involves either pointing a pagetable at…

  • CVE-2019-14889HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.03

    A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way…

  • CVE-2019-13747HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13741HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.

Page 48 of 268