VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2021-30465HigMay 27, 2021
    risk 0.49cvss 8.5epss 0.07

    runc before 1.0.0-rc95 allows a Container Filesystem Breakout via Directory Traversal. To exploit the vulnerability, an attacker must be able to create multiple containers with a fairly specific mount configuration. The problem occurs via a symlink-exchange attack that relies on…

  • CVE-2021-28651HigMay 27, 2021
    risk 0.49cvss 7.5epss 0.07

    An issue was discovered in Squid before 4.15 and 5.x before 5.0.6. Due to a buffer-management bug, it allows a denial of service. When resolving a request with the urn: scheme, the parser leaks a small amount of memory. However, there is an unspecified attack methodology that…

  • CVE-2021-25217HigMay 26, 2021
    risk 0.49cvss 7.4epss 0.06

    In ISC DHCP 4.1-ESV-R1 -> 4.1-ESV-R16, ISC DHCP 4.4.0 -> 4.4.2 (Other branches of ISC DHCP (i.e., releases in the 4.0.x series or lower and releases in the 4.3.x series) are beyond their End-of-Life (EOL) and no longer supported by ISC. From inspection it is clear that the…

  • CVE-2020-25672HigMay 25, 2021
    risk 0.49cvss 7.5epss 0.03

    A memory leak vulnerability was found in Linux kernel in llcp_sock_connect

  • CVE-2021-3480HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.02

    A flaw was found in slapi-nis in versions before 0.56.7. A NULL pointer dereference during the parsing of the Binding DN could allow an unauthenticated attacker to crash the 389-ds-base directory server. The highest threat from this vulnerability is to system availability.

  • CVE-2021-20718HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.03

    mod_auth_openidc 2.4.0 to 2.4.7 allows a remote attacker to cause a denial-of-service (DoS) condition via unspecified vectors.

  • CVE-2021-3445HigMay 19, 2021
    risk 0.49cvss 7.5epss 0.01

    A flaw was found in libdnf's signature verification functionality in versions before 0.60.1. This flaw allows an attacker to achieve code execution if they can alter the header information of an RPM package and then trick a user or system into installing it. The highest risk of…

  • CVE-2021-32920HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.02

    Prosody before 0.11.9 allows Uncontrolled CPU Consumption via a flood of SSL/TLS renegotiation requests.

  • CVE-2021-32919HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Prosody before 0.11.9. The undocumented dialback_without_dialback option in mod_dialback enables an experimental feature for server-to-server authentication. It does not correctly authenticate remote server certificates, allowing a remote server to…

  • CVE-2021-32918HigMay 13, 2021
    risk 0.49cvss 7.5epss 0.02

    An issue was discovered in Prosody before 0.11.9. Default settings are susceptible to remote unauthenticated denial-of-service (DoS) attacks via memory exhaustion when running under Lua 5.2 or Lua 5.3.

  • CVE-2020-27840HigMay 12, 2021
    risk 0.49cvss 7.5epss 0.04

    A flaw was found in samba. Spaces used in a string around a domain name (DN), while supposed to be ignored, can cause invalid DN strings with spaces to instead write a zero-byte into out-of-bounds memory, resulting in a crash. The highest threat from this vulnerability is to…

  • CVE-2021-29478HigMay 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis 6.2 before 6.2.3 could be exploited to corrupt the heap and potentially result with remote code execution. Redis 6.0 and…

  • CVE-2021-29477HigMay 4, 2021
    risk 0.49cvss 7.5epss 0.04

    Redis is an open source (BSD licensed), in-memory data structure store, used as a database, cache, and message broker. An integer overflow bug in Redis version 6.0 or newer could be exploited using the `STRALGO LCS` command to corrupt the heap and potentially result with remote…

  • CVE-2020-15078HigApr 26, 2021
    risk 0.49cvss 7.5epss 0.05

    OpenVPN 2.5.1 and earlier versions allows a remote attackers to bypass authentication and access control channel data on servers configured with deferred authentication, which can be used to potentially trigger further information leaks.

  • CVE-2021-29424HigApr 6, 2021
    risk 0.49cvss 7.5epss 0.02

    The Net::Netmask module before 2.0000 for Perl does not properly consider extraneous zero characters at the beginning of an IP address string, which (in some situations) allows attackers to bypass access control that is based on IP addresses.

  • CVE-2021-28831HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.03

    decompress_gunzip.c in BusyBox through 1.32.1 mishandles the error bit on the huft_build result pointer, with a resultant invalid free or segmentation fault, via malformed gzip data.

  • CVE-2021-28089HigMar 19, 2021
    risk 0.49cvss 7.5epss 0.02

    Tor before 0.4.5.7 allows a remote participant in the Tor directory protocol to exhaust CPU resources on a target, aka TROVE-2021-001.

  • CVE-2020-26797HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.04

    Mediainfo before version 20.08 has a heap buffer overflow vulnerability via MediaInfoLib::File_Gxf::ChooseParser_ChannelGrouping.

  • CVE-2020-27827HigMar 18, 2021
    risk 0.49cvss 7.5epss 0.03

    A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.

  • CVE-2020-27779HigMar 3, 2021
    risk 0.49cvss 7.5epss 0.00

    A flaw was found in grub2 in versions prior to 2.06. The cutmem command does not honor secure boot locking allowing an privileged attacker to remove address ranges from memory creating an opportunity to circumvent SecureBoot protections after proper triage about grub's memory…

Page 84 of 268