VYPR

Fedora

by Fedoraproject

CVEs (5,358)

  • CVE-2020-5311CriJan 3, 2020
    risk 0.57cvss 9.8epss 0.04

    libImaging/SgiRleDecode.c in Pillow before 6.2.2 has an SGI buffer overflow.

  • CVE-2019-19578HigDec 11, 2019
    risk 0.57cvss 8.8epss 0.00

    An issue was discovered in Xen through 4.12.x allowing x86 PV guest OS users to cause a denial of service via degenerate chains of linear pagetables, because of an incorrect fix for CVE-2017-15595. "Linear pagetables" is a technique which involves either pointing a pagetable at…

  • CVE-2019-14889HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.03

    A flaw was found with the libssh API function ssh_scp_new() in versions before 0.9.3 and before 0.8.8. When the libssh SCP client connects to a server, the scp command, which includes a user-provided path, is executed on the server-side. In case the library is used in a way…

  • CVE-2019-13747HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Uninitialized data in rendering in Google Chrome on Android prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13741HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.

  • CVE-2019-13736HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Integer overflow in PDFium in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

  • CVE-2019-13735HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

  • CVE-2019-13732HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Use-after-free in WebAudio in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13730HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Type confusion in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13729HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Use-after-free in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13728HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Out of bounds write in JavaScript in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-13727HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.01

    Insufficient policy enforcement in WebSockets in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

  • CVE-2019-13726HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Buffer overflow in password manager in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2019-13725HigDec 10, 2019
    risk 0.57cvss 8.8epss 0.02

    Use-after-free in Bluetooth in Google Chrome prior to 79.0.3945.79 allowed a remote attacker to execute arbitrary code via a crafted HTML page.

  • CVE-2013-2166CriDec 10, 2019
    risk 0.57cvss 9.8epss 0.02

    python-keystoneclient version 0.2.3 to 0.2.5 has middleware memcache encryption bypass

  • CVE-2019-19334CriDec 6, 2019
    risk 0.57cvss 9.8epss 0.04

    In all versions of libyang before 1.0-r5, a stack-based buffer overflow was discovered in the way libyang parses YANG files with a leaf of type "identityref". An application that uses libyang to parse untrusted YANG files may be vulnerable to this flaw, which would allow an…

  • CVE-2019-18609CriDec 1, 2019
    risk 0.57cvss 9.8epss 0.03

    An issue was discovered in amqp_handle_input in amqp_connection.c in rabbitmq-c 0.9.0. There is an integer overflow that leads to heap memory corruption in the handling of CONNECTION_STATE_HEADER. A rogue server could return a malicious frame header that leads to a smaller…

  • CVE-2019-13723HigNov 25, 2019
    risk 0.57cvss 8.8epss 0.01

    Use after free in WebBluetooth in Google Chrome prior to 78.0.3904.108 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2019-18622CriNov 22, 2019
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.

  • CVE-2019-19010CriNov 16, 2019
    risk 0.57cvss 9.8epss 0.02

    Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.

Page 49 of 268