VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2020-17367HigAug 11, 2020
    risk 0.51cvss 7.8epss 0.01

    Firejail through 0.9.62 does not honor the -- end-of-options indicator after the --output option, which may lead to command injection.

  • CVE-2020-6070HigAug 10, 2020
    risk 0.51cvss 7.8epss 0.02

    An exploitable code execution vulnerability exists in the file system checking functionality of fsck.f2fs 1.12.0. A specially crafted f2fs file can cause a logic flaw and out-of-bounds heap operations, resulting in code execution. An attacker can provide a malicious file to…

  • CVE-2020-6510HigJul 22, 2020
    risk 0.51cvss 7.8epss 0.02

    Heap buffer overflow in background fetch in Google Chrome prior to 84.0.4147.89 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

  • CVE-2020-15567HigJul 7, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing Intel guest OS users to gain privileges or cause a denial of service because of non-atomic modification of a live EPT PTE. When mapping guest EPT (nested paging) tables, Xen would in some circumstances use a series of…

  • CVE-2020-15396HigJun 30, 2020
    risk 0.51cvss 7.8epss 0.00

    In HylaFAX+ through 7.0.2 and HylaFAX Enterprise, the faxsetup utility calls chown on files in user-owned directories. By winning a race, a local attacker could use this to escalate his privileges to root.

  • CVE-2020-15395HigJun 30, 2020
    risk 0.51cvss 7.8epss 0.01

    In MediaInfoLib in MediaArea MediaInfo 20.03, there is a stack-based buffer over-read in Streams_Fill_PerStream in Multiple/File_MpegPs.cpp (aka an off-by-one during MpegPs parsing).

  • CVE-2020-10936HigMay 27, 2020
    risk 0.51cvss 7.8epss 0.01

    Sympa before 6.2.56 allows privilege escalation.

  • CVE-2020-6477HigMay 21, 2020
    risk 0.51cvss 7.8epss 0.00

    Inappropriate implementation in installer in Google Chrome on OS X prior to 83.0.4103.61 allowed a local attacker to perform privilege escalation via a crafted file.

  • CVE-2020-11866HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows a use-after-free.

  • CVE-2020-11865HigMay 11, 2020
    risk 0.51cvss 7.8epss 0.01

    libEMF (aka ECMA-234 Metafile Library) through 1.0.11 allows out-of-bounds memory access.

  • CVE-2020-0081HigApr 17, 2020
    risk 0.51cvss 7.8epss 0.00

    In finalize of AssetManager.java, there is possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0…

  • CVE-2020-11739HigApr 14, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Xen through 4.13.x, allowing guest OS users to cause a denial of service or possibly gain privileges because of missing memory barriers in read-write unlock paths. The read-write unlock paths don't contain a memory barrier. On Arm, this means a…

  • CVE-2019-20044HigFeb 24, 2020
    risk 0.51cvss 7.8epss 0.01

    In Zsh before 5.8, attackers able to execute commands can regain privileges dropped by the --no-PRIVILEGED option. Zsh fails to overwrite the saved uid, so the original privileges can be restored by executing MODULE_PATH=/dir/with/module zmodload with a module that calls…

  • CVE-2015-7747HigFeb 19, 2020
    risk 0.51cvss 8.8epss 0.09

    Buffer overflow in the afReadFrames function in audiofile (aka libaudiofile and Audio File Library) allows user-assisted remote attackers to cause a denial of service (program crash) or possibly execute arbitrary code via a crafted audio file, as demonstrated by…

  • CVE-2013-4161HigDec 31, 2019
    risk 0.51cvss 7.8epss 0.00

    gksu-polkit-0.0.3-6.fc18 was reported as fixing the issue in CVE-2012-5617 but the patch was improperly applied and it did not fixed the security issue.

  • CVE-2019-19918HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.02

    Lout 3.40 has a heap-based buffer overflow in the srcnext() function in z02.c.

  • CVE-2019-19917HigDec 20, 2019
    risk 0.51cvss 7.8epss 0.02

    Lout 3.40 has a buffer overflow in the StringQuotedWord() function in z39.c.

  • CVE-2019-3995HigDec 17, 2019
    risk 0.51cvss 7.5epss 0.29

    ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request.

  • CVE-2019-19787HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.01

    ATasm 1.06 has a stack-based buffer overflow in the get_signed_expression() function in setparse.c via a crafted .m65 file.

  • CVE-2019-19786HigDec 13, 2019
    risk 0.51cvss 7.8epss 0.01

    ATasm 1.06 has a stack-based buffer overflow in the parse_expr() function in setparse.c via a crafted .m65 file.

Page 71 of 268