VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2023-50967HigMar 20, 2024
    risk 0.49cvss 7.5epss 0.01

    latchset jose through version 11 allows attackers to cause a denial of service (CPU consumption) via a large p2c (aka PBES2 Count) value.

  • CVE-2024-1931HigMar 7, 2024
    risk 0.49cvss 7.5epss 0.03

    NLnet Labs Unbound version 1.18.0 up to and including version 1.19.1 contain a vulnerability that can cause denial of service by a certain code path that can lead to an infinite loop. Unbound 1.18.0 introduced a feature that removes EDE records from responses with size higher…

  • CVE-2024-25713HigFeb 29, 2024
    risk 0.49cvss 8.6epss 0.02

    yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)

  • CVE-2024-27507HigFeb 27, 2024
    risk 0.49cvss 7.5epss 0.01

    libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.

  • CVE-2024-25711HigFeb 27, 2024
    risk 0.49cvss 7.5epss 0.01

    diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is trusted.

  • CVE-2024-1622HigFeb 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the peer too quickly after opening.

  • CVE-2023-3966HigFeb 22, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in Open vSwitch where multiple versions are vulnerable to crafted Geneve packets, which may result in a denial of service and invalid memory accesses. Triggering this issue requires that hardware offloading via the netlink path is enabled.

  • CVE-2023-5679HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    A bad interaction between DNS64 and serve-stale may cause `named` to crash with an assertion failure during recursive resolution, when both of these features are enabled. This issue affects BIND 9 versions 9.16.12 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19,…

  • CVE-2023-5517HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    A flaw in query-handling code can cause `named` to exit prematurely with an assertion failure when: - `nxdomain-redirect ;` is configured, and - the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN…

  • CVE-2023-4408HigFeb 13, 2024
    risk 0.49cvss 7.5epss 0.01

    The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw.…

  • CVE-2023-46838HigJan 29, 2024
    risk 0.49cvss 7.5epss 0.01

    Transmit requests in Xen's virtual network protocol can consist of multiple parts. While not really useful, except for the initial part any of them may be of zero length, i.e. carry no data at all. Besides a certain initial portion of the to be transferred data, these parts…

  • CVE-2024-0804HigJan 24, 2024
    risk 0.49cvss 7.5epss 0.00

    Insufficient policy enforcement in iOS Security UI in Google Chrome prior to 121.0.6167.85 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2024-0567HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    A vulnerability was found in GnuTLS, where a cockpit (which uses gnuTLS) rejects a certificate chain with distributed trust. This issue occurs when validating a certificate chain with cockpit-certificate-ensure. This flaw allows an unauthenticated, remote client or attacker to…

  • CVE-2024-0553HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.02

    A vulnerability was found in GnuTLS. The response times to malformed ciphertexts in RSA-PSK ClientKeyExchange differ from the response times of ciphertexts with correct PKCS#1 v1.5 padding. This issue may allow a remote attacker to perform a timing side-channel attack in the…

  • CVE-2023-46849HigNov 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Using the --fragment option in certain configuration setups OpenVPN version 2.6.0 to 2.6.6 allows an attacker to trigger a divide by zero behaviour which could cause an application crash, leading to a denial of service.

  • CVE-2023-39198HigNov 9, 2023
    risk 0.49cvss 7.5epss 0.00

    A race condition was found in the QXL driver in the Linux kernel. The qxl_mode_dumb_create() function dereferences the qobj returned by the qxl_gem_object_create_with_handle(), but the handle is the only one holding a reference to it. This flaw allows an attacker to guess the…

  • CVE-2023-31122HigOct 23, 2023
    risk 0.49cvss 7.5epss 0.03

    Out-of-bounds Read vulnerability in mod_macro of Apache HTTP Server.This issue affects Apache HTTP Server: through 2.4.57.

  • CVE-2023-38552HigOct 18, 2023
    risk 0.49cvss 7.5epss 0.01

    When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check. Impacts: This…

  • CVE-2023-39325HigOct 11, 2023
    risk 0.49cvss 7.5epss 0.04

    A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the…

  • CVE-2023-43615HigOct 7, 2023
    risk 0.49cvss 7.5epss 0.01

    Mbed TLS 2.x before 2.28.5 and 3.x before 3.5.0 has a Buffer Overflow.

Page 77 of 268