VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2022-24070HigApr 12, 2022
    risk 0.49cvss 7.5epss 0.09

    Subversion's mod_dav_svn is vulnerable to memory corruption. While looking up path-based authorization rules, mod_dav_svn servers may attempt to use memory which has already been freed. Affected Subversion mod_dav_svn servers 1.10.0 through 1.14.1 (inclusive). Servers that do…

  • CVE-2022-27227HigMar 25, 2022
    risk 0.49cvss 7.5epss 0.05

    In PowerDNS Authoritative Server before 4.4.3, 4.5.x before 4.5.4, and 4.6.x before 4.6.1 and PowerDNS Recursor before 4.4.8, 4.5.x before 4.5.8, and 4.6.x before 4.6.1, insufficient validation of an IXFR end condition causes incomplete zone transfers to be handled as successful…

  • CVE-2022-27191HigMar 18, 2022
    risk 0.49cvss 7.5epss 0.04

    The golang.org/x/crypto/ssh package before 0.0.0-20220314234659-1baeb1ce4c0b for Go allows an attacker to crash a server in certain circumstances involving AddHostKey.

  • CVE-2022-0725HigMar 10, 2022
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in keepass. The vulnerability occurs due to logging the plain text passwords in system log and leads to an Information Exposure vulnerability. This flaw allows an attacker to interact and read sensitive passwords and logs.

  • CVE-2022-24464HigMar 9, 2022
    risk 0.49cvss 7.5epss 0.04

    .NET and Visual Studio Denial of Service Vulnerability

  • CVE-2021-25636HigFeb 24, 2022
    risk 0.49cvss 7.5epss 0.01

    LibreOffice supports digital signatures of ODF documents and macros within documents, presenting visual aids that no alteration of the document occurred since the last signing and that the signature is valid. An Improper Certificate Validation vulnerability in LibreOffice…

  • CVE-2021-20322HigFeb 18, 2022
    risk 0.49cvss 7.4epss 0.07

    A flaw in the processing of received ICMP errors (ICMP fragment needed and ICMP redirect) in the Linux kernel functionality was found to allow the ability to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypass the source port UDP…

  • CVE-2022-25271HigFeb 16, 2022
    risk 0.49cvss 7.5epss 0.01

    Drupal core's form API has a vulnerability where certain contributed or custom modules' forms may be vulnerable to improper input validation. This could allow an attacker to inject disallowed values or overwrite data. Affected forms are uncommon, but in certain cases an attacker…

  • CVE-2022-0391HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.08

    A flaw was found in Python, specifically within the urllib.parse module. This module helps break Uniform Resource Locator (URL) strings into components. The issue involves how the urlparse method does not sanitize input and allows characters like '\r' and '\n' in the URL path.…

  • CVE-2022-21986HigFeb 9, 2022
    risk 0.49cvss 7.5epss 0.04

    .NET Denial of Service Vulnerability

  • CVE-2021-46669HigFeb 1, 2022
    risk 0.49cvss 7.5epss 0.02

    MariaDB through 10.5.9 allows attackers to trigger a convert_const_to_int use-after-free when the BIGINT data type is used.

  • CVE-2022-23094HigJan 15, 2022
    risk 0.49cvss 7.5epss 0.03

    Libreswan 4.2 through 4.5 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted IKEv1 packet because pluto/ikev1.c wrongly expects that a state object exists. This is fixed in 4.6.

  • CVE-2021-41819HigJan 1, 2022
    risk 0.49cvss 7.5epss 0.03

    CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.

  • CVE-2021-4190HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Large loop in the Kafka dissector in Wireshark 3.6.0 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4185HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.04

    Infinite loop in the RTMPT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4184HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.04

    Infinite loop in the BitTorrent DHT dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4182HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.03

    Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-4181HigDec 30, 2021
    risk 0.49cvss 7.5epss 0.04

    Crash in the Sysdig Event dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file

  • CVE-2021-45290HigDec 21, 2021
    risk 0.49cvss 7.5epss 0.01

    A Denial of Service vulnerability exits in Binaryen 103 due to an assertion abort in wasm::handle_unreachable.

  • CVE-2021-45451HigDec 21, 2021
    risk 0.49cvss 7.5epss 0.01

    In Mbed TLS before 3.1.0, psa_aead_generate_nonce allows policy bypass or oracle-based decryption when the output buffer is at memory locations accessible to an untrusted application.

Page 81 of 268