VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2024-2887HigMar 26, 2024
    risk 0.52cvss 7.7epss 0.18

    Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

  • CVE-2022-2625HigAug 18, 2022
    risk 0.52cvss 8.0epss 0.02

    A vulnerability was found in PostgreSQL. This attack requires permission to create non-temporary objects in at least one schema, the ability to lure or wait for an administrator to create or update an affected extension in that schema, and the ability to lure or wait for a…

  • CVE-2022-1996CriJun 8, 2022
    risk 0.52cvss 9.1epss 0.03

    Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

  • CVE-2022-1053CriMay 6, 2022
    risk 0.52cvss 9.1epss 0.01

    Keylime does not enforce that the agent registrar data is the same when the tenant uses it for validation of the EK and identity quote and the verifier for validating the integrity quote. This allows an attacker to use one AK, EK pair from a real TPM to pass EK validation and…

  • CVE-2022-24790CriMar 30, 2022
    risk 0.52cvss 9.1epss 0.02

    Puma is a simple, fast, multi-threaded, parallel HTTP 1.1 server for Ruby/Rack applications. When using Puma behind a proxy that does not properly validate that the incoming HTTP request matches the RFC7230 standard, Puma and the frontend proxy may disagree on where a request…

  • CVE-2022-24303CriMar 28, 2022
    risk 0.52cvss 9.1epss 0.03

    Pillow before 9.0.1 allows attackers to delete files because spaces in temporary pathnames are mishandled.

  • CVE-2021-4157HigMar 25, 2022
    risk 0.52cvss 8.0epss 0.02

    An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate…

  • CVE-2022-0860CriMar 11, 2022
    risk 0.52cvss 9.1epss 0.02

    Improper Authorization in GitHub repository cobbler/cobbler prior to 3.3.2.

  • CVE-2021-38000MedKEVNov 23, 2021
    risk 0.52cvss 6.1epss 0.05

    Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.

  • CVE-2021-21775HigJul 7, 2021
    risk 0.52cvss 8.0epss 0.01

    A use-after-free vulnerability exists in the way certain events are processed for ImageLoader objects of Webkit WebKitGTK 2.30.4. A specially crafted web page can lead to a potential information leak and further memory corruption. In order to trigger the vulnerability, a victim…

  • CVE-2021-34363CriJun 10, 2021
    risk 0.52cvss 9.1epss 0.02

    The thefuck (aka The Fuck) package before 3.31 for Python allows Path Traversal that leads to arbitrary file deletion via the "undo archive operation" feature.

  • CVE-2020-35452HigJun 10, 2021
    risk 0.52cvss 7.3epss 0.53

    Apache HTTP Server versions 2.4.0 to 2.4.46 A specially crafted Digest nonce can cause a stack overflow in mod_auth_digest. There is no report of this overflow being exploitable, nor the Apache HTTP Server team could create one, though some particular compiler and/or compilation…

  • CVE-2021-25288CriJun 2, 2021
    risk 0.52cvss 9.1epss 0.02

    An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_gray_i.

  • CVE-2021-25287CriJun 2, 2021
    risk 0.52cvss 9.1epss 0.03

    An issue was discovered in Pillow before 8.2.0. There is an out-of-bounds read in J2kDecode, in j2ku_graya_la.

  • CVE-2020-14352HigAug 30, 2020
    risk 0.52cvss 8.0epss 0.03

    A flaw was found in librepo in versions before 1.12.1. A directory traversal vulnerability was found where it failed to sanitize paths in remote repository metadata. An attacker controlling a remote repository may be able to copy files outside of the destination directory on the…

  • CVE-2020-10802HigMar 22, 2020
    risk 0.52cvss 8.0epss 0.02

    In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability has been discovered where certain parameters are not properly escaped when generating certain queries for search actions in libraries/classes/Controllers/Table/TableSearchController.php. An…

  • CVE-2020-10804HigMar 22, 2020
    risk 0.52cvss 8.0epss 0.02

    In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a…

  • CVE-2020-9402HigMar 5, 2020
    risk 0.52cvss 8.8epss 0.23

    Django 1.11 before 1.11.29, 2.2 before 2.2.11, and 3.0 before 3.0.4 allows SQL Injection if untrusted data is used as a tolerance parameter in GIS functions and aggregates on Oracle. By passing a suitably crafted tolerance to GIS functions and aggregates on Oracle, it was…

  • CVE-2020-7043CriFeb 27, 2020
    risk 0.52cvss 9.1epss 0.03

    An issue was discovered in openfortivpn 1.11.0 when used with OpenSSL before 1.0.2. tunnel.c mishandles certificate validation because hostname comparisons do not consider '\0' characters, as demonstrated by a good.example.com\x00evil.example.com attack.

  • CVE-2019-3993HigDec 17, 2019
    risk 0.52cvss 7.5epss 0.46

    ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP POST request.

Page 62 of 268