VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2021-3578HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in mbsync before v1.3.6 and v1.4.2, where an unchecked pointer cast allows a malicious or compromised server to write an arbitrary integer value past the end of a heap-allocated structure by issuing an unexpected APPENDUID response. This could be plausibly…

  • CVE-2022-23804HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadIJCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can…

  • CVE-2022-23803HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon ReadXYCoord coordinate parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can…

  • CVE-2021-3551HigFeb 16, 2022
    risk 0.51cvss 7.8epss 0.00

    A flaw was found in the PKI-server, where the spkispawn command, when run in debug mode, stores admin credentials in the installation log file. This flaw allows a local attacker to retrieve the file to obtain the admin password and gain admin privileges to the Dogtag CA manager.…

  • CVE-2021-45444HigFeb 14, 2022
    risk 0.51cvss 7.8epss 0.02

    In zsh before 5.8.1, an attacker can achieve code execution if they control a command output inside the prompt, as demonstrated by a %F argument. This occurs because of recursive PROMPT_SUBST expansion.

  • CVE-2022-23947HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.01

    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon DCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a…

  • CVE-2022-23946HigFeb 4, 2022
    risk 0.51cvss 7.8epss 0.02

    A stack-based buffer overflow vulnerability exists in the Gerber Viewer gerber and excellon GCodeNumber parsing functionality of KiCad EDA 6.0.1 and master commit de006fc010. A specially-crafted gerber or excellon file can lead to code execution. An attacker can provide a…

  • CVE-2022-23614HigFeb 4, 2022
    risk 0.51cvss 8.8epss 0.08

    Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to…

  • CVE-2022-23033HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.00

    arm: guest_physmap_remove_page not removing the p2m mappings The functions to remove one or more entries from a guest p2m pagetable on Arm (p2m_remove_mapping, guest_physmap_remove_page, and p2m_set_entry with mfn set to INVALID_MFN) do not actually clear the pagetable entry if…

  • CVE-2021-45342HigJan 25, 2022
    risk 0.51cvss 7.8epss 0.02

    A buffer overflow vulnerability in CDataList of the jwwlib component of LibreCAD 2.2.0-rc3 and older allows an attacker to achieve Remote Code Execution using a crafted JWW document.

  • CVE-2021-45417HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.00

    AIDE before 0.17.4 allows local users to obtain root privileges via crafted file metadata (such as XFS extended attributes or tmpfs ACLs), because of a heap-based buffer overflow.

  • CVE-2021-44537HigJan 15, 2022
    risk 0.51cvss 7.8epss 0.03

    ownCloud owncloud/client before 2.9.2 allows Resource Injection by a server into the desktop client via a URL, leading to remote code execution.

  • CVE-2021-4011HigDec 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SwapCreateRegister function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-4010HigDec 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcScreenSaverSuspend function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-4009HigDec 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcXFixesCreatePointerBarrier function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-4008HigDec 17, 2021
    risk 0.51cvss 7.8epss 0.01

    A flaw was found in xorg-x11-server in versions before 21.1.2 and before 1.20.14. An out-of-bounds access can occur in the SProcRenderCompositeGlyphs function. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

  • CVE-2021-45078HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    stab_xcoff_builtin_type in stabs.c in GNU Binutils through 2.37 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write. NOTE: this issue exists because of an incorrect fix…

  • CVE-2021-43518HigDec 15, 2021
    risk 0.51cvss 7.8epss 0.01

    Teeworlds up to and including 0.7.5 is vulnerable to Buffer Overflow. A map parser does not validate m_Channels value coming from a map file, leading to a buffer overflow. A malicious server may offer a specially crafted map that will overwrite client's stack causing denial of…

  • CVE-2020-16156HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.01

    CPAN 2.28 allows Signature Verification Bypass.

  • CVE-2020-16154HigDec 13, 2021
    risk 0.51cvss 7.8epss 0.01

    The App::cpanminus package 1.7044 for Perl allows Signature Verification Bypass.

Page 67 of 268