VYPR

Fedora

by Fedoraproject

CVEs (5,359)

  • CVE-2021-30473CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    aom_image.c in libaom in AOMedia before 2021-04-07 frees memory that is not located on the heap.

  • CVE-2021-20204CriMay 6, 2021
    risk 0.64cvss 9.8epss 0.02

    A heap memory corruption problem (use after free) can be triggered in libgetdata v0.10.0 when processing maliciously crafted dirfile databases. This degrades the confidentiality, integrity and availability of third-party software that uses libgetdata as a library. This…

  • CVE-2021-20307CriApr 5, 2021
    risk 0.64cvss 9.8epss 0.02

    Format string vulnerability in panoFileOutputNamesCreate() in libpano13 2.9.20~rc2+dfsg-3 and earlier can lead to read and write arbitrary memory values.

  • CVE-2021-3466CriMar 25, 2021
    risk 0.64cvss 9.8epss 0.09

    A flaw was found in libmicrohttpd. A missing bounds check in the post_process_urlencoded function leads to a buffer overflow, allowing a remote attacker to write arbitrary data in an application that uses libmicrohttpd. The highest threat from this vulnerability is to data…

  • CVE-2020-1946CriMar 25, 2021
    risk 0.64cvss 9.8epss 0.06

    In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5, users should only use…

  • CVE-2021-20232CriMar 12, 2021
    risk 0.64cvss 9.8epss 0.03

    A flaw was found in gnutls. A use after free issue in client_send_params in lib/ext/pre_shared_key.c may lead to memory corruption and other potential consequences.

  • CVE-2021-3420CriMar 5, 2021
    risk 0.64cvss 9.8epss 0.02

    A flaw was found in newlib in versions prior to 4.0.0. Improper overflow validation in the memory allocation functions mEMALIGn, pvALLOc, nano_memalign, nano_valloc, nano_pvalloc could case an integer overflow, leading to an allocation of a small buffer and then to a heap-based…

  • CVE-2020-35628CriMar 4, 2021
    risk 0.64cvss 9.8epss 0.03

    A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->incident_sface. An attacker can provide malicious input to trigger this…

  • CVE-2020-28636CriMar 4, 2021
    risk 0.64cvss 9.8epss 0.03

    A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser::read_sloop() slh->twin() An attacker can provide malicious input to trigger this vulnerability.

  • CVE-2020-28601CriMar 4, 2021
    risk 0.64cvss 9.8epss 0.03

    A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this…

  • CVE-2021-3148CriFeb 27, 2021
    risk 0.64cvss 9.8epss 0.08

    An issue was discovered in SaltStack Salt before 3002.5. Sending crafted web requests to the Salt API can result in salt.utils.thin.gen_thin() command injection because of different handling of single versus double quotes. This is related to salt/utils/thin.py.

  • CVE-2021-3406CriFeb 25, 2021
    risk 0.64cvss 9.8epss 0.01

    A flaw was found in keylime 5.8.1 and older. The issue in the Keylime agent and registrar code invalidates the cryptographic chain of trust from the Endorsement Key certificate to agent attestations.

  • CVE-2020-13576CriFeb 10, 2021
    risk 0.64cvss 9.8epss 0.06

    A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.

  • CVE-2021-26937CriFeb 9, 2021
    risk 0.64cvss 9.8epss 0.09

    encoding.c in GNU Screen through 4.8.0 allows remote attackers to cause a denial of service (invalid write access and application crash) or possibly have unspecified other impact via a crafted UTF-8 character sequence.

  • CVE-2020-29600CriDec 7, 2020
    risk 0.64cvss 9.8epss 0.04

    In AWStats through 7.7, cgi-bin/awstats.pl?config= accepts an absolute pathname, even though it was intended to only read a file in the /etc/awstats/awstats.conf format. NOTE: this issue exists because of an incomplete fix for CVE-2017-1000501.

  • CVE-2020-0452CriNov 10, 2020
    risk 0.64cvss 9.8epss 0.03

    In exif_entry_get_value of exif-entry.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution if a third party app used this library to process remote image data with no additional execution privileges needed. User…

  • CVE-2020-28035CriNov 2, 2020
    risk 0.64cvss 9.8epss 0.04

    WordPress before 5.5.2 allows attackers to gain privileges via XML-RPC.

  • CVE-2020-17368CriAug 11, 2020
    risk 0.64cvss 9.8epss 0.04

    Firejail through 0.9.62 mishandles shell metacharacters during use of the --output or --output-stderr option, which may lead to command injection.

  • CVE-2020-17353CriAug 5, 2020
    risk 0.64cvss 9.8epss 0.02

    scm/define-stencil-commands.scm in LilyPond through 2.20.0, and 2.21.x through 2.21.4, when -dsafe is used, lacks restrictions on embedded-ps and embedded-svg, as demonstrated by including dangerous PostScript code.

  • CVE-2020-12460CriJul 27, 2020
    risk 0.64cvss 9.8epss 0.04

    OpenDMARC through 1.3.2 and 1.4.x through 1.4.0-Beta1 has improper null termination in the function opendmarc_xml_parse that can result in a one-byte heap overflow in opendmarc_xml when parsing a specially crafted DMARC aggregate report. This can cause remote memory corruption…

Page 9 of 268